blackbeard420

blackbeard420 / mmon luna audit

Last active 1 month ago

Like 0

blackbeard420 revised this gist 1 month ago · e77e83f

1 file changed, 70 insertions

audit.md (file created)
@@ -0,0 +1,70 @@
1 +
2 + ### High
3 +
4 + - Unauthenticated API exposed on all interfaces. --serve/--listen defaults to 0.0.0.0, and authentication is skipped when no token is configured. This exposes host, mounts, devices, sensors, GPU, and network data.
5 + Evidence: src/main.cpp:56, src/api.cpp:1347
6 +
7 + - Bearer tokens are sent over plaintext HTTP. HTTPS is explicitly rejected, while remote polling sends Authorization: Bearer ... over an unencrypted socket. Network observers can steal the token.
8 + Evidence: src/api.cpp:1045, src/api.cpp:1436
9 +
10 + - Unhandled SIGPIPE can terminate the process. POSIX send() is used without MSG_NOSIGNAL, and the application never ignores SIGPIPE. A peer closing during response transmission can kill mmon.
11 + Evidence: src/api.cpp:177, src/main.cpp:2108
12 +
13 + - Single-threaded HTTP server is vulnerable to slow-client denial of service. run() handles each connection synchronously. A client can hold the only server thread by slowly sending headers/body or refusing to read the response.
14 + Evidence: src/api.cpp:1234, src/api.cpp:1248
15 +
16 + - Encrypted push frames have no replay protection. crypto::open() accepts any previously valid envelope, and returned commands are executed without timestamps, counters, or freshness checks. A captured quit, serve, connect, or key
17 + command can be replayed.
18 + Evidence: src/crypto.cpp:401, src/api.cpp:1652
19 +
20 + - Unbounded decompression and response accumulation permit memory exhaustion. Gzip output has no maximum size, and close-delimited HTTP responses are accumulated without a limit.
21 + Evidence: src/api.cpp:333, /home/blackbeard/src/api.cpp:297
22 +
23 + - CPU topology detection changes the application’s CPU affinity. cpuidGroups() pins the calling thread to each CPU but never restores the original affinity. The main thread and subsequently created threads can remain restricted to the
24 + final CPU.
25 + Evidence: src/sys_metrics.cpp:145, src/sys_metrics.cpp:157
26 +
27 + - Windows build fetches an unpinned external dependency. build-win.sh clones PDCurses from the moving default branch, making builds non-reproducible and creating a supply-chain risk.
28 + Evidence: build-win.sh:12
29 +
30 + ### Medium
31 +
32 + - Generated token/config files are not protected. ofstream creates files using the process umask. Under a permissive umask, --write-config produced mode 0666, exposing authentication tokens to other users.
33 + Evidence: src/main.cpp:2067
34 +
35 + - Metric collection can block indefinitely. statvfs() on hung network mounts, zpool, nvidia-smi, and Windows WMI/PDH calls run synchronously in the main refresh path.
36 + Evidence: src/sys_metrics.cpp:393, src/sys_metrics.cpp:445
37 +
38 + - JSON parser accepts invalid/non-finite numbers and does not validate trailing input. Inputs such as NaN, Inf, oversized integers, malformed trailing data, or deeply nested structures can cause undefined conversions, bad display
39 + values, or crashes.
40 + Evidence: src/api.cpp:536, src/api.cpp:773
41 +
42 + - CPU counter decreases are not handled. Counter deltas use unsigned subtraction without validating each field. CPU hotplug/reset conditions can produce enormous percentages and undefined floating-to-integer conversions during
43 + rendering.
44 + Evidence: src/sys_metrics.cpp:947, src/main.cpp:412
45 +
46 + - Windows disk throughput likely remains zero/unavailable. A new PDH query is created on every update and only one sample is collected; rate counters generally require two samples.
47 + Evidence: src/sys_metrics_windows.cpp:243
48 +
49 + - GPU fallback order contradicts the documented order. The implementation selects DRM before trying nvidia-smi, contrary to the README/manual.
50 + Evidence: src/gpu_metrics.cpp:190
51 +
52 + - nvidia-smi reports N/A temperature/power as valid zero values. Temperature and power flags are set solely based on column count.
53 + Evidence: src/gpu_metrics.cpp:295
54 +
55 + - Selecting a named remote theme does not apply it. selectTheme() changes only the index; it does not call applyTheme().
56 + Evidence: src/theme.cpp:416, src/main.cpp:1360
57 +
58 + - The secondary Windows build script is broken from a clean checkout. It does not fetch PDCurses, while the CMake Windows target requires it. A clean configure reproduced No SOURCES given to target: pdcurses.
59 + Evidence: scripts/build-windows.sh:6, CMakeLists.txt:21
60 +
61 + - IPv6 is unsupported. Both server and client force AF_INET; IPv6-only hosts, bind addresses, and bracketed IPv6 URLs fail.
62 + Evidence: src/api.cpp:130, src/api.cpp:1162
63 +
64 + ### Low
65 +
66 + - Bar rendering ignores its bgPair argument, so custom themes can render incorrect bar-track backgrounds: src/ui.cpp:63
67 + - ZFS pools with only one child cannot be expanded because expansion requires more than one part: src/main.cpp:656
68 + - Mount paths from /proc/mounts are not unescaped (\040, \011), causing mounts containing spaces/tabs to be misread: src/sys_metrics.cpp:384
69 + - SERVER.md is referenced throughout the documentation but is absent and explicitly ignored by Git: .gitignore:10
70 + - There is no automated test suite for HTTP framing, authentication, replay, malformed JSON, resource limits, platform collectors, or UI behavior.