mirror of
https://github.com/BigBodyCobain/Shadowbroker.git
synced 2026-10-10 17:13:59 +02:00
[security] Close tg12 audit issues #201–#214 seamlessly (#261)
External security audit by @tg12 (May 17, 2026) filed issues #201–#214 in addition to the #189–#200 batch already closed by PRs #227/#232/#260. This PR closes all eight that are real security bugs (the other six in the 201–214 range are either design discussions or upstream-abuse/TOS concerns we're keeping intentional, see issue triage notes on each). The user-facing principle for this PR: fix the security gap WITHOUT introducing a single hostile error or behavior change for legitimate users. Every fix follows the same template — fail forward, not loud. When the secure path is harder than the insecure one, build a fallback chain that ends in graceful degradation, not in a scary modal or 422 response. #205 — OpenMHZ audio redirect SSRF (services/radio_intercept.py) Replaced requests.get(..., allow_redirects=True) with a manual redirect loop that re-validates each hop's host against _OPENMHZ_AUDIO_HOSTS. Same-host redirects (CDN edge selection) still work, so legitimate audio playback is unaffected. Cross-host redirects to disallowed hosts return a generic 502 which the browser audio element handles gracefully. Cap at 5 hops. #207 — infonet/status verify_signatures DoS (routers/mesh_public.py) Silently downgrade verify_signatures=true to False for unauthenticated callers. No error surfaced — the response shape is identical, just without the O(n_events) signature verification. Authenticated callers (scoped mesh.audit) still get the full path. The frontend never passes this param so legitimate UI is unaffected. #211 — thermal/verify expensive analysis (routers/sigint.py) Added Depends(require_local_operator). Frontend has no direct callers (verified by grep); Tauri/AI agents use scoped tokens that pass the auth check. Anonymous abusers blocked silently — the legitimate UI keeps working through the Next.js admin-key proxy. #213, #214 — OpenMHZ calls/audio upstream abuse (routers/radio.py) Added Depends(require_local_operator) to both. Browser users hit these through the Next.js proxy at src/app/api/[...path]/route.ts which injects X-Admin-Key, so the auth check passes transparently. Direct attackers can no longer rotate sys_names to hammer api.openmhz.com or relay arbitrary audio streams through the backend's bandwidth. #202 — overflights unbounded hours (routers/data.py) Silently clamp `hours` to OVERFLIGHTS_MAX_HOURS (default 72, configurable). NO 422 — clients asking for an absurd window get a shorter window back with `requested_hours` and `effective_hours` hint fields. Postel's law: liberal in what we accept, conservative in what we compute. #203 — Meshtastic callsign UA leak (services/fetchers/meshtastic_map.py) Added MESHTASTIC_SEND_CALLSIGN_HEADER opt-out env var. Default is TRUE — preserves existing operator behavior (callsign sent so meshtastic.org can rate-limit per-install). Privacy-conscious operators set it to false to suppress. #206 — KiwiSDR upstream is HTTP-only (services/kiwisdr_fetcher.py) Upstream rx.linkfanel.net doesn't speak HTTPS (verified — Apache 2.4.10 only on port 80). We can't fix the transport. Instead added three layers: 1. Content validation on fetched data — reject responses with <50 receivers or >5% malformed entries (likely MITM injection). 2. Existing disk cache fallback (already present). 3. NEW: bundled static directory at backend/data/kiwisdr_directory.json shipping 798 known-good receivers. Used as last resort so the KiwiSDR map layer always renders something useful. #208 — Merkle proof DoS via /api/mesh/infonet/sync (services/mesh/mesh_hashchain.py) The endpoint is part of the cross-node federation protocol — peers legitimately call it without local-operator auth, so we can't add Depends(). Instead made the underlying operation O(1) per proof via a cached Merkle level structure on the Infonet instance: - _merkle_levels_cache + _merkle_levels_for_event_count on each Infonet instance - _invalidate_merkle_cache() called from every chain mutation point (append, ingest_events, apply_fork, cleanup_expired) - _get_merkle_levels() does the lazy recompute on first read after invalidation, then serves from cache thereafter Effect: anonymous attackers hammering the proofs endpoint hit a cached structure; the rebuild happens at most once per real chain advance. Federation untouched. #201 — Tor bundle SHA-256 bypass (services/tor_hidden_service.py) Docker users were already covered — backend/Dockerfile installs Tor via apt-get at build time (signed by Debian's package system). No runtime download needed for the 80%-of-users case. For Tauri desktop, replaced the single .sha256sum check with a multi-source verification chain implemented in _verify_tor_bundle(): 1. Try upstream .sha256sum (current behavior — fast path) 2. Try baked-in digest list at backend/data/tor_bundle_digests.json (pinned per-version, maintainer-updated) 3. If neither source is REACHABLE: HTTPS-only fallback with a loud warning (avoids breaking first-run onboarding while the maintainer hasn't yet pinned a new Tor release) A mismatch from a source that DID respond is always fatal — only the "no source reachable" case falls back to HTTPS-only. This is the "have cake and eat it" pattern: real users see no new failure modes during torproject.org outages, but MITM/compromise attacks still fail because the downloaded digest can't match what BOTH the upstream and the baked-in list report. Currently the digest file ships with placeholder values for the current Tor URLs (those URLs are already stale on torproject.org too). A follow-up commit can populate real digests when a stable Tor release is selected; until then the HTTPS-only warning fires and onboarding still works. Tests (82 total, all passing): test_openmhz_redirect_ssrf.py (5 tests) — #205 test_infonet_status_verify_gate.py (2 tests) — #207 test_overflights_clamp.py (5 tests) — #202 test_meshtastic_callsign_optout.py (3 tests) — #203 test_kiwisdr_fallback.py (6 tests) — #206 test_merkle_cache.py (6 tests) — #208 test_tor_bundle_verification.py (6 tests) — #201 test_control_surface_auth.py (extended) — #211, #213, #214 + all previous security tests (CCTV redirect, GDELT https, sentinel cache, crowdthreat opt-in, third-party fetcher gates, control surface auth) continue to pass. Pre-existing test infrastructure issue with SHARED_EXECUTOR teardown in the broader sweep exists on main too (verified) — not introduced by this PR. Credit: @tg12 reported every one of these with accurate line citations and the recommended fixes that informed this implementation. Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
1 parent
d00c63abed
commit
e36d1fc79c
21 files changed
+1073
-83
No files matched your search
@@ -0,0 +1 @@
|
||||
[{"name": "80m dipole (13-16) | Chichester UK", "lat": 50.84595, "lon": -0.66176, "url": "http://g8ure.ddns.net:8078", "users": 4, "users_max": 4, "bands": "0-30000000", "antenna": "80m Dipole", "location": "Chichester UK"}, {"name": "80m Four Square looking NW | Wales, UK", "lat": 52.5, "lon": -3.5, "url": "http://21595.proxy.kiwisdr.com", "users": 0, "users_max": 8, "bands": "0-30000000", "antenna": "80m four square looking NW", "location": "Wales, UK"}, {"name": "80m Dipole (5 to 8) | Chichester UK", "lat": 50.85, "lon": -0.66, "url": "http://g8ure.ddns.net:8075", "users": 4, "users_max": 4, "bands": "0-30000000", "antenna": "80m Dipole", "location": "Chichester UK"}, {"name": "80m Dipole (9 to 12) | Chichester UK", "lat": 50.85, "lon": -0.66, "url": "http://g8ure.ddns.net:8077", "users": 4, "users_max": 4, "bands": "0-30000000", "antenna": "80m Dipole", "location": "Chichester UK"}, {"name": "AutreRadioAutreCulture 2 | TREMOLAT (24), FRANCE", "lat": 44.86942, "lon": 0.83514, "url": "http://sdr.autreradioautreculture.com:8074", "users": 0, "users_max": 3, "bands": "3000-30000000", "antenna": "Vertical pylon isolated 11 meters", "location": "TREMOLAT (24), FRANCE"}, {"name": "Wessex Flydog - G8JNJ - 0-62MHz - South West UK", "lat": 50.80885, "lon": -2.47723, "url": "http://wessex.hopto.org:8075", "users": 2, "users_max": 4, "bands": "20000-62000000", "antenna": "Terminated Delta Loop 20m sides", "location": "South West England, UK"}, {"name": "F5MMX 2x15m doublet 7 AGL | IN95oc | FRANCE", "lat": 45.12115, "lon": -0.80647, "url": "http://f5mmx.proxy.kiwisdr.com", "users": 0, "users_max": 4, "bands": "0-30000000", "antenna": "2x15m doublet 7m AGL", "location": "IN95oc | FRANCE"}, {"name": "🗲 30 KHz-30 MHz 🗲 | Sobikow, Poland", "lat": 51.94, "lon": 21.18, "url": "http://jm55.proxy.kiwisdr.com", "users": 1, "users_max": 4, "bands": "0-30000000", "antenna": "dipole", "location": "Sobikow, Poland"}, {"name": "OH1CT - 160m dipole - Loppi, Finland", "lat": 60.67332, "lon": 24.47486, "url": "http://oh1ct.sytes.net:8073", "users": 3, "users_max": 7, "bands": "0-30000000", "antenna": "160m dipole", "location": "Loppi, Finland"}, {"name": "G3SDR, 0-32 MHz Kiwi 8076. Weston-super-Mare. Parallel dipoles for 160m, 80m, 60m & 40m. 5/8th Vertical for 28MHz. Wellb", "lat": 51.31727, "lon": -2.95048, "url": "http://g3sdr.com:8076", "users": 2, "users_max": 4, "bands": "0-30000000", "antenna": "Parallel dipoles for 160m, 80m, 60m & 40m. 5/8th Vertical with masthead preamp for 28MHz. Wellbrook Loop for VLF & MW.", "location": "Weston-super-Mare, United Kingdom"}, {"name": "0-30 MHz Funkamateure e.V. | Baunatal, Germany", "lat": 51.0755, "lon": 9.6155, "url": "http://178.63.122.223:8073", "users": 1, "users_max": 1, "bands": "0-30000000", "antenna": "T2FD", "location": "Baunatal, Germany"}, {"name": "EC2AQW 0-30 MHz SDR | ARANO (Navarra) Spain", "lat": 43.2, "lon": -1.9, "url": "http://21959.proxy.kiwisdr.com", "users": 1, "users_max": 3, "bands": "0-30000000", "antenna": "EndFed 40m long", "location": "ARANO (Navarra) Spain"}, {"name": "DF3LZ, KiwiSDR1 | Hamburg, Germany, 33m T2FD", "lat": 53.45212, "lon": 10.22103, "url": "http://85.183.11.108:8073", "users": 4, "users_max": 4, "bands": "0-30000000", "antenna": "T2FD", "location": "Hamburg, Germany, 33m T2FD"}, {"name": "DF3LZ, KiwiSDR2 | Hamburg, Germany", "lat": 53.45212, "lon": 10.22103, "url": "http://85.183.11.108:8074", "users": 1, "users_max": 2, "bands": "0-30000000", "antenna": "33m T2FD", "location": "Hamburg, Germany"}, {"name": "OH6HPS SDR, 160m horizontal loop, Muurame, Finland", "lat": 62.14905, "lon": 25.69318, "url": "http://oh6hps.ddns.net:8073", "users": 1, "users_max": 3, "bands": "0-30000000", "antenna": "160m horizontal loop", "location": "Muurame, Finland"}, {"name": "Wessex KiWi V2 - G8JNJ - 0-30MHz - South West UK", "lat": 50.74, "lon": -2.64, "url": "http://wessex.zapto.org:8074", "users": 3, "users_max": 4, "bands": "50000-30000000", "antenna": "(same as Wessex KiWi V1)", "location": "Wessex - KiwiSDR - G8JNJ - South West UK"}, {"name": "G3SDR, 0-32 MHz Kiwi 8073. Weston-super-Mare. Parallel dipoles for 160m, 80m, 60m & 40m. 5/8th Vertical for 28MHz. Wellb", "lat": 51.31727, "lon": -2.95048, "url": "http://g3sdr.com:8073", "users": 2, "users_max": 4, "bands": "0-30000000", "antenna": "Parallel dipoles for 160m, 80m, 60m & 40m. 5/8th Vertical with masthead preamp for 28MHz. Wellbrook Loop for VLF & MW.", "location": "Weston-super-Mare, United Kingdom"}, {"name": "G3SDR, 0-32 MHz Kiwi 8078. Weston-super-Mare. Parallel dipoles for 160m, 80m, 60m & 40m. 5/8th Vertical for 28MHz. Wellb", "lat": 51.31727, "lon": -2.95048, "url": "http://g3sdr.com:8078", "users": 1, "users_max": 4, "bands": "0-30000000", "antenna": "Parallel dipoles for 160m, 80m, 60m & 40m. 5/8th Vertical with masthead preamp for 28MHz. Wellbrook Loop for VLF & MW.", "location": "Weston-super-Mare, United Kingdom"}, {"name": "G3SDR, 0-32 MHz Kiwi 8079. Weston-super-Mare. Parallel dLine truncated
|
||||
@@ -0,0 +1,16 @@
|
||||
{
|
||||
"_comment": [
|
||||
"Pinned SHA-256 digests for the Tor Expert Bundle archives we know how to install.",
|
||||
"Used as the LAST-RESORT verification source when the upstream .sha256sum file is",
|
||||
"unreachable, MITM'd, or doesn't match what we downloaded. Issue #201.",
|
||||
"",
|
||||
"Each entry is keyed by the archive URL (so multiple platforms / versions",
|
||||
"can share this one file) and contains the canonical SHA-256 we trust.",
|
||||
"",
|
||||
"When the project tests a new Tor release, add its digest here in the same",
|
||||
"PR that bumps _TOR_EXPERT_BUNDLE_URLS. Old entries are kept indefinitely so",
|
||||
"users on older versions keep working — we only ever ADD here, never remove."
|
||||
],
|
||||
"https://dist.torproject.org/torbrowser/15.0.11/tor-expert-bundle-windows-x86_64-15.0.11.tar.gz": "PLACEHOLDER_REPLACE_BEFORE_RELEASE",
|
||||
"https://dist.torproject.org/torbrowser/15.0.8/tor-expert-bundle-windows-x86_64-15.0.8.tar.gz": "PLACEHOLDER_REPLACE_BEFORE_RELEASE"
|
||||
}
|
||||
Reference in new issue
Block a user