shadowsocks / shadowsocks/shadowsocks-org
Redirect attack on Shadowsocks stream ciphers
Nobody has claimed this yet.
- Dominant language
- HTML
- Stars
- 1k
- Forks
- 694
- PR merge metrics
- No merged PRs in 30d
Description
Shadowsocks is a secure split proxy loosely based on SOCKS5. It’s widely used in china.
However, we found a vulnerability in shadowsocks protocol which break the confdentiality of
shadowsocks stream cipher. An attacker can easliy decrypt all the encrypted shadowsocks
packet using our redirect attack. As the vulnerability is obvious and easy to exploit. I think the
government has already know it. So, using shadowsocks in steam cipher cannot hide yourself
from surveillance.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the vulnerability report and the linked repository at github.com/edwardz246003/shadowsocks. The issue names no project files, tests, or concrete remediation; completion criteria must therefore be established before implementation can begin.
Written by the indexing model from the issue text.
Assessment
- Domain
- cryptography, networking, security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100