openwrt / openwrt/packages

adblock-fast : adblock-fast force user expose remote rpcd by token ? how to disable it?

Open
#30,150 7 comments 2 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug release/25.12
Dominant language
Makefile
Stars
4.6k
Forks
4k
Avg merge
3d 12h
Merged PRs (30d)
134

Description

Package Name

adblock-fast

Maintainer

Stan Grishin stangri@melmac.ca

OpenWrt Version

25.12.5

OpenWrt Target/Subtarget

mediatek/filogic

Steps to Reproduce

The adblock-fast force user expose token rpcd ? how to disable it ? why it doesn't see any document about it.
This token can be vulnerable to Brute Force Attack ?

Actual Behaviour

It should have clearly document and clearly option in luci to allow user to disable it.
Good app should clearly tell user how they remote thing work. if not it just kind of backdoor.

Confirmation Checklist

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by tracing the adblock-fast package's force-user and token-based rpcd behavior, then check how its LuCI-facing options are exposed; the issue names no file or test. Confirm whether the token can be disabled safely, and define documentation and a clear LuCI disable path as the completion criteria.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, frontend, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.