Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Possible addon security breach using nearby owner for man in middle attack #1098

Open
NikkiLacrima opened this issue Sep 13, 2024 · 1 comment

Comments

@NikkiLacrima
Copy link
Contributor

This is based on a report in OpenCollar group.
A user had an alt nearby and the alt had owner privileges to the collar.
The attacker knew about both the collar wearer and the alts owner status.

After a while the attacker had inserted himself as owner on the collar and changed restrictions.
No dialog popups were visible to the collar wearer, or so she thought.

So how can this possibly be done ? After seeing todays report on temp attachments I thought about the following:

Craft a remotecontrolled remotecontrol, or simply an addon man in the middle relay, Not to hard.

Make this object temp attach to the nearby collar owner ( the alt), as a furniture attached toy perhaps.

This remote controlled remote will now be owned by the collar owner and as such have owner privileges to the wearers collar, without any rlv or collar interaction happening.

Now the remotecontrolled remote can connet to the wearers collar and since its owned by the alt who is collar owner it gains owner status, and the attacker can gain control.

Is this possible and how can we prevent it ??

@mistressohm
Copy link

mistressohm commented Sep 13, 2024 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants