Commit 37bcc9f3 authored by George Kadianakis's avatar George Kadianakis Committed by Nick Mathewson
Browse files

hs-v3: Don't allow registration of an all-zeroes client auth key.

The client auth protocol allows attacker-controlled x25519 private keys being
passed around, which allows an attacker to potentially trigger the all-zeroes
assert for client_auth_sk in hs_descriptor.c:decrypt_descriptor_cookie().

We fixed that by making sure that an all-zeroes client auth key will not be
used.

There are no guidelines for validating x25519 private keys, and the assert was
there as a sanity check for code flow issues (we don't want to enter that
function with an unitialized key if client auth is being used). To avoid such
crashes in the future, we also changed the assert to a BUG-and-err.
parent e4727372
Loading
Loading
Loading
Loading

changes/bug33545

0 → 100644
+4 −0
Original line number Diff line number Diff line
  o Minor bugfixes (hidden services):
    - Block a client-side assert by disallowing the registration of an x25519
      client auth key that's all zeroes. Fixes bug 33545; bugfix on
      0.4.3.1-alpha. Patch based on patch from "cypherpunks".
 No newline at end of file
+8 −1
Original line number Diff line number Diff line
@@ -55,6 +55,13 @@ parse_private_key_from_control_port(const char *client_privkey_str,
    goto err;
  }

  if (fast_mem_is_zero((const char*)privkey->secret_key,
                       sizeof(privkey->secret_key))) {
    control_printf_endreply(conn, 553,
                            "Invalid private key \"%s\"", key_blob);
    goto err;
  }

  retval = 0;

 err:
+1 −1
Original line number Diff line number Diff line
@@ -45,7 +45,7 @@ typedef enum {
  REGISTER_SUCCESS_AND_DECRYPTED,
  /* We failed to register these credentials, because of a bad HS address. */
  REGISTER_FAIL_BAD_ADDRESS,
  /* We failed to register these credentials, because of a bad HS address. */
  /* We failed to store these credentials in a persistent file on disk. */
  REGISTER_FAIL_PERMANENT_STORAGE,
} hs_client_register_auth_status_t;

+14 −0
Original line number Diff line number Diff line
@@ -467,6 +467,20 @@ test_hs_control_bad_onion_client_auth_add(void *arg)
  cp1 = buf_get_contents(TO_CONN(&conn)->outbuf, &sz);
  tt_str_op(cp1, OP_EQ, "512 Failed to decode x25519 private key\r\n");

  tor_free(cp1);
  tor_free(args);

  /* Register with an all zero client key */
  args = tor_strdup("jt4grrjwzyz3pjkylwfau5xnjaj23vxmhskqaeyfhrfylelw4hvxcuyd "
                    "x25519:AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=");
  retval = handle_control_command(&conn, (uint32_t) strlen(args), args);
  tt_int_op(retval, OP_EQ, 0);

  /* Check contents */
  cp1 = buf_get_contents(TO_CONN(&conn)->outbuf, &sz);
  tt_str_op(cp1, OP_EQ, "553 Invalid private key \"AAAAAAAAAAAAAAAAAAAA"
                        "AAAAAAAAAAAAAAAAAAAAAAA=\"\r\n");

  client_auths = get_hs_client_auths_map();
  tt_assert(!client_auths);