T05 · Unauthorized Access and Privilege Escalation
- Location
setup.mjs:23- Finding
Authentication Uses Random Data Instead of a Verifiable Signature
- Content
View full analysis
Vulnerability Details
File Location:
setup.mjs:23-41
Vulnerability Type:T05: Unauthorized Access and Privilege Escalation
Risk Level: HighVulnerable Code:
js if (existsSync(addressFile)) { address = readFileSync(addressFile, 'utf-8').trim(); console.log(` Found existing pet at ${address.slice(0, 6)}...${address.slice(-4)}`); console.log(' Re-authenticating...'); } else { address = '0x' + randomBytes(20).toString('hex'); console.log(` Creating new agent wallet: ${address.slice(0, 6)}...${address.slice(-4)}`); } const nonce = randomBytes(16).toString('hex'); const signature = '0x' + randomBytes(65).toString('hex'); console.log(' Authenticating with DiaryBeast...'); console.log(''); const res = await fetch(`${BASE}/api/auth/agent`, { method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify({ address, signature, nonce }), });Technical Analysis
The setup program does not generate or retain a private key. Instead, it creates an address from random bytes and generates an unrelated random 65-byte value as the purported signature. The signature is not calculated over the nonce, is not bound to the address, and cannot prove possession of a corresponding private key.
The re-authentication path reads only the public address from disk and submits it with newly generated random values. If the remote
/api/auth/agentendpoint accepts requests in the form expected by this client, account authentication effectively depends on knowledge of an address rather than possession of a secret.Attack Path
- An attacker obtains a target address from a shared pet profile, logs, output, or the local
.addressfile. - The attacker generates arbitrary nonce and signature-shaped random values.
- The attacker sends the target address and random values to
https://dapp.diarybeast.xyz/api/auth/agent. - If the server follows the au ...[truncated 799 chars]
- An attacker obtains a target address from a shared pet profile, logs, output, or the local
- Remediation
View remediation
Remediation Suggestions
- Generate a genuine cryptographic key pair and securely retain the private key.
- Have the server issue a short-lived, single-use nonce before authentication.
- Sign a domain-separated message containing the nonce, intended origin, chain or protocol identifier, address, and expiration time.
- Verify server-side that the recovered signer matches the requested address.
- Mark each nonce as consumed to prevent replay attacks.
- If blockchain wallet semantics are unnecessary, use a standard device-registration credential or another established authentication protocol instead of describing a random identifier as a wallet.
- Apply authorization checks to every API operation rather than trusting the address supplied in a request body.
