daemon: don't ignore dnssec validation result in start_mining
What changed, and why it matters
This patch fixes a bug in the Monero daemon's 'start_mining' command. Previously, when a user started mining to a human-readable address (like a domain name), the code asked for a DNSSEC-validated lookup but then ignored whether DNSSEC actually succeeded. That could let an attacker on the network tamper with the DNS response and redirect mining rewards to their own wallet. The patch now rejects the command if DNSSEC validation fails.
Operators running mining daemons should upgrade to a release containing this commit. Until patched, avoid using human-readable/OpenAlias addresses with the start_mining command; use raw Monero addresses instead. Review logs for any prior unexpected mining reward destinations if DNSSEC failures were possible on the network.
Security signals we found
DNSSEC validation result was previously ignored
Network-supplied address could be accepted without cryptographic proof of origin
Mining rewards could be redirected to an attacker-controlled address
Fix adds explicit rejection on dnssec_valid == false
Fix also guards empty address list to prevent out-of-bounds access
Evidence from the diff
In src/daemon/command_parser_executor.cpp::start_mining(), the code called tools::dns_utils::get_account_address_as_str_from_url() with a callback that returned addresses[0] regardless of the dnssec_valid flag. The caller also did not inspect dnssec_valid. Consequently, a DNSSEC failure (e.g., missing signatures, spoofed records) was silently ignored and the first returned address was parsed and used. The patch changes the callback to return an empty string when dnssec_valid is false or no addresses are returned, and the caller now checks dnssec_valid and aborts with an error message. This is a validation/logic fix in a command-line/admin RPC code path.
Changed components
src/daemon/command_parser_executor.cppdaemon start_mining commandDNS-based OpenAlias / human-readable address resolutionInspect captured patch +10 / −1
diff --git a/src/daemon/command_parser_executor.cpp b/src/daemon/command_parser_executor.cpp
index 1a1dada..eefb6dc 100644
--- a/src/daemon/command_parser_executor.cpp
+++ b/src/daemon/command_parser_executor.cpp
@@ -384,7 +384,16 @@ bool t_command_parser_executor::start_mining(const std::vector<std::string>& arg
{
bool dnssec_valid;
std::string address_str = tools::dns_utils::get_account_address_as_str_from_url(args.front(), dnssec_valid,
- [](const std::string &url, const std::vector<std::string> &addresses, bool dnssec_valid){return addresses[0];});
+ [](const std::string &url, const std::vector<std::string> &addresses, bool dnssec_valid) -> std::string {
+ if (!dnssec_valid) return {};
+ if (addresses.empty()) return {};
+ return addresses[0];
+ });
+ if(!dnssec_valid)
+ {
+ std::cout << "Invalid syntax: Invalid DNSSEC for " << args.front() << std::endl;
+ return true;
+ }
if(!cryptonote::get_account_address_from_str(info, cryptonote::MAINNET, address_str))
{
if(!cryptonote::get_account_address_from_str(info, cryptonote::TESTNET, address_str))
Why this scored 48/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.