[tor-bugs] #21509 [Core Tor/Tor]: Fuzz v3 hidden services

Tor Bug Tracker & Wiki blackhole at torproject.org
Thu Oct 26 15:34:09 UTC 2017


#21509: Fuzz v3 hidden services
-----------------------------------+------------------------------------
 Reporter:  teor                   |          Owner:  dgoulet
     Type:  task                   |         Status:  needs_review
 Priority:  Very High              |      Milestone:  Tor: 0.3.2.x-final
Component:  Core Tor/Tor           |        Version:
 Severity:  Normal                 |     Resolution:
 Keywords:  fuzz, prop224, tor-hs  |  Actual Points:
Parent ID:                         |         Points:  2
 Reviewer:                         |        Sponsor:  SponsorR-can
-----------------------------------+------------------------------------

Comment (by dgoulet):

 Replying to [comment:12 nickm]:
 > merging to 0.3.2 and forward.
 >
 > How hard would it be to get the decrypted part fuzzed too?

 A bit more work in mocking functions because lots of crypto checks are
 done (decrypt, MAC validation, signature...)

 And we would need to expose the inners like `desc_decrypt_all()` or
 `decrypt_desc_layer()`. A bit of work but not that crazy I think.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/21509#comment:13>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list