Skip to content
create-bsv-app
5 / 9

Break it

A proof is useless to an attacker who copies it. Let's check.

This page builds the signed request by hand (instead of useSignedRequest()), so it can keep the proof and send it again.

Your task#

  1. Click Send. The note is accepted: 200.
  2. Click Replay it. Same proof, same body: 401. The proof's nonce is already in the server's nonce store, so it's refused.
  3. Click Change the body. Same proof, different text: 401. The body is part of what was signed, so the signature no longer matches.

Now take a defence away. Open server/src/bsv/nonceStore.ts and make consumeNonce always succeed:

ts
export function consumeNonce (nonce: string, expiresAt: Date): boolean {
  console.log('replay accepted: nonce check is off')
  return true
}

Send, then Replay it: the replay gets 200. Anyone who captured that request could now repeat it for two minutes, until the proof expires. Put the original back with Reset.

Your task

  • Get a replayed and a changed request refused (two 401s)
  • Switch off the nonce check and watch a replay get through