Analysis of Security in a P2P storage cloud
ID: 9bf7067d-8545-51cc-a5dc-417a236b9a1a
STIX ID: report--9bf7067d-8545-51cc-a5dc-417a236b9a1a
Feed Name: SensePost Blog
Threat Score
This report investigates security weaknesses in a P2P distributed storage service and demonstrates that the contribution/synchronization agent can be abused to (1) accept and serve arbitrary uploaded files by using a predictable fragment naming scheme, enabling covert content hosting and bandwidth/storage abuse, and (2) retrieve AES-256 folder encryption keys via the file-recovery/metadata API, allowing decryption of other users' fragments and exposure of confidential data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
