Cryptodog / cryptodog

The Cryptodog client
https://crypto.dog
GNU Affero General Public License v3.0
35 stars 9 forks source link

Malformed ciphertext causes client DoS #34

Closed superp00t closed 7 years ago

superp00t commented 7 years ago

If you delete a logged in user from the ciphertext object, it causes the clients of others to stop functioning.

Here is the proof of concept.

ayyghost commented 7 years ago

I am actively working on this, just so you know. My fix seems to work, but I want to test it some more before I push anything.

Thanks for reporting.