Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Insecure connection could allow RCE #9

Open
ShaKabosh opened this issue May 5, 2023 · 3 comments
Open

Insecure connection could allow RCE #9

ShaKabosh opened this issue May 5, 2023 · 3 comments
Assignees
Labels
enhancement New feature or request

Comments

@ShaKabosh
Copy link

If the server is installed on Termux, then it seems as though anyone could, knowing your IP address, easily connect to the websocket unauthenticated and have RCE through Termux, which is especially bad if your phone is rooted.

@bajrangCoder
Copy link
Owner

Yes, but this is local server no one can access other than you, but if you will give your phone then it may be insecure.

Or if you have any suggestions for this , you can provide. i will happy to see.

@bajrangCoder bajrangCoder added enhancement New feature or request question Further information is requested labels May 5, 2023
@14725
Copy link

14725 commented Jun 3, 2023

If the server is on when we're surfing the web...

Then a evil (?) page surely knows your one of your IP as 127.0.0.1, and he cound connect to it easily by start a WebSocket and grab a shell of your phone...

Port could be scanned, too.

Some authentication is needed.

@bajrangCoder
Copy link
Owner

Ok , In next update I will add authentication system ♥️♥️

@bajrangCoder bajrangCoder closed this as not planned Won't fix, can't repro, duplicate, stale Aug 2, 2023
@bajrangCoder bajrangCoder reopened this Dec 2, 2023
@bajrangCoder bajrangCoder removed the question Further information is requested label Dec 2, 2023
@bajrangCoder bajrangCoder self-assigned this Dec 2, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

3 participants