Skip to content

Block the IPv6 rebinding targets the DNS blacklist already blocks over IPv4 - #15050

Open
arpitjain099 wants to merge 1 commit into
trailofbits:mainfrom
arpitjain099:fix/dns-blacklist-ipv6
Open

arpitjain099 wants to merge 1 commit into
trailofbits:mainfrom
arpitjain099:fix/dns-blacklist-ipv6

Conversation

@arpitjain099

Copy link
Copy Markdown

roles/dns/templates/ip-blacklist.txt.j2 is the DNS rebinding guard that ships as /etc/dnscrypt-proxy/ip-blacklist.txt. It blocks every RFC 1918 range, 0.0.0.0, 127.* and 169.254.*, then repeats all of them in ::ffff: form, and finishes with fd00::* and fe80::*. Three IPv6 addresses that have an IPv4 twin in the list are not there:

  • ::1, while 127.* is blocked
  • ::, while 0.0.0.0 is blocked
  • the VPN client networks, which for IPv4 fall under the 10.* entry that covers both strongswan_network 10.48.0.0/16 and wireguard_network_ipv4 10.49.0.0/16, but strongswan_network_ipv6 2001:db8:4160::/48 and wireguard_network_ipv6 2001:db8:a160::/48 have nothing covering them

Both defaults sit under 2001:db8::/32, the documentation prefix, which should never be the answer to a real lookup, so I blocked that rather than templating the two variables into wildcards.

Added a case to tests/unit/test_template_rendering.py that renders the template and checks the three entries are present. It fails on master listing all three. pytest tests/unit/ gives 116 passed against 115 before, with the same 4 pre-existing failures from boto3 and openssl version checks in my environment.

I have not put this in front of a live dnscrypt-proxy, so if any of the three patterns is not accepted by the matcher I would want to know.

…r IPv4

Signed-off-by: Arpit Jain <arpitjain099@gmail.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant