From 0c75e59b772419301ac7fd63e394cb7f8391d67e Mon Sep 17 00:00:00 2001 From: Lennart Eriksson Date: Thu, 14 Dec 2017 10:34:07 +0100 Subject: [PATCH] Drop UDP packets from unwanted interfaces Previously UDP packets were never dropped and if a request came from a not valid interface inetd got stuck in an inifinite loop looking at the same packet every time and not dropping it. Signed-off-by: Lennart Eriksson --- src/inetd.c | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/src/inetd.c b/src/inetd.c index e3c0dd31..c6dc36dd 100644 --- a/src/inetd.c +++ b/src/inetd.c @@ -70,6 +70,22 @@ static int inetd_dgram_peek(int sd, char *ifname) return -1; } +/* Peek into SOCK_DGRAM socket to figure out where an inbound packet comes from. */ +static void inetd_dgram_drop(int sd, const char *ifname) +{ + char pkt_interface[17]; + char buf[BUFSIZ]; + + do { + inetd_dgram_peek(sd, pkt_interface); + if(string_compare(pkt_interface, ifname)) { + recv(sd, buf, sizeof(buf), 0); + continue; + } + + } while (0); +} + /* Peek into SOCK_STREAM on accepted client socket to figure out inbound interface */ static int inetd_stream_peek(int sd, char *ifname) { @@ -129,6 +145,8 @@ static int get_stdin(svc_t *svc) logit(LOG_INFO, "Service %s on %s:%d is not allowed", svc->inetd.name, ifname, svc->inetd.port); if (svc->inetd.type == SOCK_STREAM) close(stdin); + else + inetd_dgram_drop(stdin, ifname); return -1; }