Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

0-conf possible attack using large transactions #33

Open
cmaves opened this issue Jan 23, 2018 · 5 comments
Open

0-conf possible attack using large transactions #33

cmaves opened this issue Jan 23, 2018 · 5 comments
Assignees
Labels

Comments

@cmaves
Copy link

cmaves commented Jan 23, 2018

By making a very simple modification to the monero-wallet-rpc, one can generate a valid low priority transaction that is small enough to be relayed, but large enough to never be confirmed by the network. After looking through the code. I looked through the code and I didn't see a protection against this kind of attack.

After 24 hours this transaction will drop from the mempool and the sender will be able to use the Monero again.

@emesik
Copy link

emesik commented Jan 25, 2018

This could be a mempool spam attack against the daemon itself. Don't you think it's worth reporting upstream, with some more details on how to perform it?

@amiuhle
Copy link
Owner

amiuhle commented Jan 26, 2018

I agree, transactions like this shouldn't be propagated through the network.

@cmaves
Copy link
Author

cmaves commented Jan 26, 2018

I made an issue on the monero repo.
monero-project/monero#3189

@cmaves
Copy link
Author

cmaves commented Jan 26, 2018

I'll leave this issue open until it is either fixed on the upstream or fixed in kasisto itself

@anonimal
Copy link

@cmaves In the future, please respect responsible disclosure by using using Monero's Vulnerability Response Process regardless of whether this issue is a confirmed vulnerability or not. Thank you.

@amiuhle amiuhle self-assigned this Jan 28, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

4 participants