Block the IPv6 rebinding targets the DNS blacklist already blocks over IPv4 - #15050
Open
arpitjain099 wants to merge 1 commit into
Open
arpitjain099 wants to merge 1 commit into
arpitjain099 wants to merge 1 commit into
Conversation
…r IPv4 Signed-off-by: Arpit Jain <arpitjain099@gmail.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
roles/dns/templates/ip-blacklist.txt.j2is the DNS rebinding guard that ships as/etc/dnscrypt-proxy/ip-blacklist.txt. It blocks every RFC 1918 range,0.0.0.0,127.*and169.254.*, then repeats all of them in::ffff:form, and finishes withfd00::*andfe80::*. Three IPv6 addresses that have an IPv4 twin in the list are not there:::1, while127.*is blocked::, while0.0.0.0is blocked10.*entry that covers bothstrongswan_network10.48.0.0/16 andwireguard_network_ipv410.49.0.0/16, butstrongswan_network_ipv62001:db8:4160::/48 andwireguard_network_ipv62001:db8:a160::/48 have nothing covering themBoth defaults sit under 2001:db8::/32, the documentation prefix, which should never be the answer to a real lookup, so I blocked that rather than templating the two variables into wildcards.
Added a case to
tests/unit/test_template_rendering.pythat renders the template and checks the three entries are present. It fails on master listing all three.pytest tests/unit/gives 116 passed against 115 before, with the same 4 pre-existing failures from boto3 and openssl version checks in my environment.I have not put this in front of a live dnscrypt-proxy, so if any of the three patterns is not accepted by the matcher I would want to know.