RNS Logo

rns.recipes

◈ 9ce92808be498e9e05590ff27cbfdfe4
NomadNet 1.4.0 released with experimental image support https://pypi.org/project/nomadnet/

Reporting a vuln?

Discussion

Started by KenAKAFrosty ·

#1

I've bumped into a vulnerability in the reference impl (confirmed 1.3.7, human-reviewed lol, not just hallucinated nonsense) that can DoS announce propagation.

Blast radius is limited and there's no RCE or anything like that, but it's trivial to perform. And this doesn't seem like a tradeoff for some other benefit; it looks like it's just a small oversight, with a pretty straightforward path to fixing it.

Where's the best place to privately report the details now?

Anonymous
#2

If you mean the fact you can just spam announces, there's a ratelimit system but it isn't on by default.

If you don't, contacting Mark over LXMF is probably best, and checking if he's online in the rrc hub general room and pinging him there might also work.

#3

Anonymous wrote:

If you mean the fact you can just spam announces, there's a ratelimit system but it isn't on by default.

If you don't, contacting Mark over LXMF is probably best, and checking if he's online in the rrc hub general room and pinging him there might also work.

Thanks, and yeah I definitely don't mean just spamming announces, this would have to be specifically malicious in a certain way

Mark 8dd57a7382268096...
#4

You can send me the details over LXMF or email, and I'll have a look at it immediately.

#5

Mark wrote:

You can send me the details over LXMF or email, and I'll have a look at it immediately.

Thanks, Mark!! Just emailed you (a light bump in urgency since first discovery)

Post a Reply

Supports Markdown: **bold**, *italic*, `code`, ```code blocks```, [links](url)

Log in to upload images

Quote
Copied to clipboard