HelloZeroNet / HelloZeroNet/ZeroNet
Security problem on ZeroMail (and all zeromail clones) need to be allowed nickname@cryptoid.bit: (the auth address), malicious user can read, delete, send messages have full access to your mailbox!
- 主要语言
- JavaScript
- 星标
- 18.8k
- 派生
- 2.3k
- PR 合并指标
- 30 天内没有已合并 PR
描述
Cloned user have full access to the original user mailbox. If have a originaluser@cryptoid.bit and someone else are registering another originaluser@cryptoid.bit have full access to the original user mailbox! On any name service if the user can change in the .json file his name, or the name service can manipulated like ZeroID anyone's emails can be easily accessed.
If multiple user are registered in cryptoid.bit with the same nickname.
-1. Not possible to filter nickname@cryptoid.bit: (the auth address) Like this: user@idprovider.bit:De86hbTrEftznbTRFVcDemj7Zhgvfdsx
-2. The system can not detected before the secondary registration one user with the same nickname already registered.
-3. On nickname@cryptoid.bit the system is not sure from who to send the letter to. And send both the users with the same nickname. Both user are accessing the same mailbox and can send, delete, read messages have full access to the original user mailbox.
-4. A hacker can manipulate the system so that someone else to receive the letter.
Affected mail services ZeroMail, ZeroMailX, ZeroVerse services and any ZeroMail Clones. Need to use the public key hash and nickname combination to identify the user. Like this: user@idprovider.bit:De86hbTrEftznbTRFVcDemj7Zhgvfdsx
Centralized ID providers like ZeroID they are completely untrusted. It is very easy to hack the system.
贡献指南
这个仓库没有索引到贡献指南
调研方向
未识别出文件或测试。首先跟踪 ZeroMail 注册流程、nickname@cryptoid.bit 身份验证地址以及邮箱收件人解析;确认重复 nickname 的处理方式。完成标准是:重复注册无法访问或重定向到其他用户的邮箱,并且投递与所声明的身份数据绑定。
由索引模型根据 Issue 内容生成。
评估
- 领域
- authentication, security
- Issue 类型
- 缺陷
- 难度
- 5/5
- 预计耗时
- 一周以上
- 活跃度
- 停滞
- 描述清晰度
- 需要澄清
- 新手友好度
- 20/100