RPC test nodes may be on the Internet #4248
Labels
A-rpc-interface
Area: RPC interface
A-testing
Area: Tests and testing infrastructure
I-SECURITY
Problems and improvements related to security.
Milestone
Zcash's RPC tests spawn test nodes with configuration files like:
This results in them being potentially accessible from the Internet - if the system is on the Internet and incoming traffic is not filtered. Combined with the hard-coded RPC password above, this probably allows for at least confusing the tests, and possibly much worse.
I suggest that this be added:
The text was updated successfully, but these errors were encountered: