adblock-fast : adblock-fast force user expose remote rpcd by token ? how to disable it?
Nobody has claimed this yet.
- Dominant language
- Makefile
- Stars
- 4.6k
- Forks
- 4k
- Avg merge
- 3d 12h
- Merged PRs (30d)
- 134
Description
Package Name
adblock-fast
Maintainer
Stan Grishin stangri@melmac.ca
OpenWrt Version
25.12.5
OpenWrt Target/Subtarget
mediatek/filogic
Steps to Reproduce
The adblock-fast force user expose token rpcd ? how to disable it ? why it doesn't see any document about it.
This token can be vulnerable to Brute Force Attack ?
Actual Behaviour
It should have clearly document and clearly option in luci to allow user to disable it.
Good app should clearly tell user how they remote thing work. if not it just kind of backdoor.
Confirmation Checklist
- The package is maintained in this repository.
- I understand that issues related to the base OpenWrt repository or LuCI repository will be closed.
- I am reporting an issue for OpenWrt, not an unsupported fork.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by tracing the adblock-fast package's force-user and token-based rpcd behavior, then check how its LuCI-facing options are exposed; the issue names no file or test. Confirm whether the token can be disabled safely, and define documentation and a clear LuCI disable path as the completion criteria.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, frontend, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 45/100