[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
Re: [tor-bugs] #17674 [Tor]: circuit_handle_first_hop doesn't respect ExtendAllowPrivateAddresses
#17674: circuit_handle_first_hop doesn't respect ExtendAllowPrivateAddresses
-------------------------------------------------+-------------------------
Reporter: teor | Owner:
Type: defect | Status:
Priority: Very High | needs_review
Component: Tor | Milestone: Tor:
Severity: Major | 0.2.8.x-final
Keywords: dos tor-hs 027-backport | Version:
026-backport security | Resolution:
Parent ID: #17178 | Actual Points:
Sponsor: | Points:
-------------------------------------------------+-------------------------
Changes (by teor):
* status: new => needs_review
Comment:
Please see my branch first-hop-no-private at
https://github.com/teor2345/tor.git
It modifies circuit_handle_first_hop to refuse any connections to a
private address with a protocol error, unless ExtendAllowPrivateAddresses
is set.
This should catch this issue with relay extends, and hidden service / RSOS
rendezvous from badly behaved clients.
I can't test it on chutney, so I need help testing it on the live network.
(Ugh.)
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/17674#comment:4>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs