HelloZeroNet / HelloZeroNet/ZeroNet

Security problem on ZeroMail (and all zeromail clones) need to be allowed nickname@cryptoid.bit: (the auth address), malicious user can read, delete, send messages have full access to your mailbox!

Đang mở
#2,833 3 bình luận 0 reaction 0 người được giao Xem trên GitHub
Ngôn ngữ chính
JavaScript
Star
18.8k
Fork
2.3k
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Mô tả

Cloned user have full access to the original user mailbox. If have a originaluser@cryptoid.bit and someone else are registering another originaluser@cryptoid.bit have full access to the original user mailbox! On any name service if the user can change in the .json file his name, or the name service can manipulated like ZeroID anyone's emails can be easily accessed.

If multiple user are registered in cryptoid.bit with the same nickname.

-1. Not possible to filter nickname@cryptoid.bit: (the auth address) Like this: user@idprovider.bit:De86hbTrEftznbTRFVcDemj7Zhgvfdsx
-2. The system can not detected before the secondary registration one user with the same nickname already registered.
-3. On nickname@cryptoid.bit the system is not sure from who to send the letter to. And send both the users with the same nickname. Both user are accessing the same mailbox and can send, delete, read messages have full access to the original user mailbox.
-4. A hacker can manipulate the system so that someone else to receive the letter.

Affected mail services ZeroMail, ZeroMailX, ZeroVerse services and any ZeroMail Clones. Need to use the public key hash and nickname combination to identify the user. Like this: user@idprovider.bit:De86hbTrEftznbTRFVcDemj7Zhgvfdsx

Centralized ID providers like ZeroID they are completely untrusted. It is very easy to hack the system.

Hướng dẫn đóng góp

Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này

Hướng nghiên cứu

No files or tests are identified. Start by tracing the ZeroMail registration flow, the nickname@cryptoid.bit auth address, and mailbox recipient resolution; confirm how duplicate nicknames are handled. Done means duplicate registrations cannot access or redirect another user's mailbox, with delivery tied to the stated identity data.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Lĩnh vực
authentication, security
Loại issue
Lỗi
Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức độ hoạt động
Đình trệ
Độ rõ ràng
Cần làm rõ
Mức phù hợp với người mới
20/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.