[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

[tor-commits] [tor/master] Block multiple introductions on the same intro circuit.



commit a7eae4ddc52006a5d94a07435152c4dc5ab2ac0e
Author: George Kadianakis <desnacked@xxxxxxxxxx>
Date:   Wed Apr 1 14:33:09 2015 +0100

    Block multiple introductions on the same intro circuit.
---
 changes/bug15515 |    4 ++++
 src/or/or.h      |    3 +++
 src/or/rendmid.c |   13 +++++++++++++
 3 files changed, 20 insertions(+)

diff --git a/changes/bug15515 b/changes/bug15515
new file mode 100644
index 0000000..dda7c2f
--- /dev/null
+++ b/changes/bug15515
@@ -0,0 +1,4 @@
+  o Minor features (DoS-resistance):
+    - Make it harder for attackers to overwhelm hidden services with
+      introductions, by blocking multiple introduction requests on the
+      same circuit. Resolves ticket #15515.
diff --git a/src/or/or.h b/src/or/or.h
index 1609587..adf3cfa 100644
--- a/src/or/or.h
+++ b/src/or/or.h
@@ -3186,6 +3186,9 @@ typedef struct or_circuit_t {
    * to the specification? */
   unsigned int remaining_relay_early_cells : 4;
 
+  /* We have already received an INTRODUCE1 cell on this circuit. */
+  unsigned int already_received_introduce1 : 1;
+
   /** True iff this circuit was made with a CREATE_FAST cell. */
   unsigned int is_first_hop : 1;
 
diff --git a/src/or/rendmid.c b/src/or/rendmid.c
index d89cdf6..48bab19 100644
--- a/src/or/rendmid.c
+++ b/src/or/rendmid.c
@@ -149,6 +149,19 @@ rend_mid_introduce(or_circuit_t *circ, const uint8_t *request,
     goto err;
   }
 
+  /* We have already done an introduction on this circuit but we just
+     received a request for another one. We block it since this might
+     be an attempt to DoS a hidden service (#15515). */
+  if (circ->already_received_introduce1) {
+    log_fn(LOG_PROTOCOL_WARN, LD_REND,
+           "Blocking multiple introductions on the same circuit. "
+           "Someone might be trying to attack a hidden service through "
+           "this relay.");
+    goto err;
+  }
+
+  circ->already_received_introduce1 = 1;
+
   /* We could change this to MAX_HEX_NICKNAME_LEN now that 0.0.9.x is
    * obsolete; however, there isn't much reason to do so, and we're going
    * to revise this protocol anyway.



_______________________________________________
tor-commits mailing list
tor-commits@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-commits