linuxdcpp-team team mailing list archive
-
linuxdcpp-team team
-
Mailing list archive
-
Message #05894
[Bug 1030613] [NEW] Normal users can issue CMDs
*** This bug is a security vulnerability ***
Private security bug reported:
Any client may send a CMD (only B-type tested) to the hub, distributing
it to any user. If done in a bot, you can effectively send tens or
hundreds of these, and a receiving client will be forced to manage them,
thus potentially causing a DoS scenario.
Generate the following user command in DC++ to test yourself;
Command type: Raw
Context: Hub menu
Name: RogueCommand
Command: BCMD %[mySID] Security\stest,\sbe\safraid TTHINF\sNIfoobar\n CT2
Hub address: adc://
(Above command should obviously be followed by a new line.)
The hub should ignore any CMD originating from a user. Potentially allow
CMDs from trusted users.
** Affects: adchpp
Importance: Undecided
Status: New
--
You received this bug notification because you are a member of
Dcplusplus-team, which is subscribed to the bug report.
https://bugs.launchpad.net/bugs/1030613
Title:
Normal users can issue CMDs
Status in ADCH++:
New
Bug description:
Any client may send a CMD (only B-type tested) to the hub,
distributing it to any user. If done in a bot, you can effectively
send tens or hundreds of these, and a receiving client will be forced
to manage them, thus potentially causing a DoS scenario.
Generate the following user command in DC++ to test yourself;
Command type: Raw
Context: Hub menu
Name: RogueCommand
Command: BCMD %[mySID] Security\stest,\sbe\safraid TTHINF\sNIfoobar\n CT2
Hub address: adc://
(Above command should obviously be followed by a new line.)
The hub should ignore any CMD originating from a user. Potentially
allow CMDs from trusted users.
To manage notifications about this bug go to:
https://bugs.launchpad.net/adchpp/+bug/1030613/+subscriptions
Follow ups
-
[Bug 1030613] Re: Normal users can issue CMDs
From: poy, 2014-03-31
-
[Bug 1030613] Re: Normal users can issue CMDs
From: poy, 2014-03-30
-
[Bug 1030613] Re: Normal users can issue CMDs
From: Fredrik Ullner, 2013-11-30
-
[Bug 1030613] Re: Normal users can issue CMDs
From: Fredrik Ullner, 2013-11-30
-
[Bug 1030613] Re: Normal users can issue CMDs
From: poy, 2013-11-06
-
[Bug 1030613] Re: Normal users can issue CMDs
From: Fredrik Ullner, 2013-11-03
-
[Bug 1030613] Re: Normal users can issue CMDs
From: Fredrik Ullner, 2013-11-03
-
[Bug 1030613] Re: Normal users can issue CMDs
From: Fredrik Ullner, 2013-08-11
-
[Bug 1030613] Re: Normal users can issue CMDs
From: Fredrik Ullner, 2013-08-11
-
[Bug 1030613] Re: Normal users can issue CMDs
From: poy, 2013-07-23
-
[Bug 1030613] Re: Normal users can issue CMDs
From: Pirre, 2012-07-29
-
[Bug 1030613] Re: Normal users can issue CMDs
From: iceman50, 2012-07-29
-
[Bug 1030613] [NEW] Normal users can issue CMDs
From: Fredrik Ullner, 2012-07-29
References