Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-84x2-2qv6-qg56

Опубликовано: 02 фев. 2024
Источник: github
Github: Прошло ревью

Описание

Nervos CKB P2P DoS Attacks

The P2P protocols lack of rate limit. For example, in relay protocol, when a node receives a broadcasted tx_hashes, it will mark it in memory to avoid duplicated requests. code → .

It is easy to establish a DoS attach by generating random tx hashes.

Impact

It affects all nodes connected to the P2P network.

Workarounds

Apply rate limit on the data sent to CKB P2P port.

Пакеты

Наименование

ckb

rust
Затронутые версииВерсия исправления

< 0.34.0

0.34.0