Add protection against UDP inetd looping attacks

This patch adds protection against a common inetd attack vector wherein
the reply port to UDP inetd services is forged to an internal inetd
service port.

Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This commit is contained in:
Joachim Nilsson
2016-07-18 17:27:37 +02:00
parent 5723b2e75b
commit 7dfdc2395b
8 changed files with 70 additions and 6 deletions
+5 -1
View File
@@ -27,6 +27,7 @@
#include "../plugin.h"
#define NAME "chargen"
#define PATTERN "!\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~ "
static char *generator(char *buf, size_t len)
@@ -61,6 +62,9 @@ static int recv_peer(int sd, char *buf, ssize_t len, struct sockaddr *sa, sockle
if (-1 == len)
return -1; /* On error, close connection. */
if (inetd_check_loop(sa, *sa_len, NAME))
return -1;
return 0;
}
@@ -86,7 +90,7 @@ static int cb(int type)
}
static plugin_t plugin = {
.name = "chargen", /* Must match the inetd /etc/services entry */
.name = NAME, /* Must match the inetd /etc/services entry */
.inetd = {
.cmd = cb
},
+7 -1
View File
@@ -28,6 +28,9 @@
#include "../plugin.h"
#define NAME "daytime"
static char *daytime(char *buf, size_t len)
{
time_t t;
@@ -48,6 +51,9 @@ static int recv_peer(int sd, char *buf, ssize_t len, struct sockaddr *sa, sockle
if (-1 == len)
return -1; /* On error, close connection. */
if (inetd_check_loop(sa, *sa_len, NAME))
return -1;
return 0;
}
@@ -72,7 +78,7 @@ static int cb(int type)
}
static plugin_t plugin = {
.name = "daytime", /* Must match the inetd /etc/services entry */
.name = NAME, /* Must match the inetd /etc/services entry */
.inetd = {
.cmd = cb
}
+16 -2
View File
@@ -27,6 +27,20 @@
#include "../plugin.h"
#define NAME "echo"
static int recv_peer(int sd, char *buf, ssize_t len, struct sockaddr *sa, socklen_t *sa_len)
{
len = recvfrom(sd, buf, sizeof(buf), MSG_DONTWAIT, sa, sa_len);
if (-1 == len)
return -1; /* On error, close connection. */
if (inetd_check_loop(sa, *sa_len, NAME))
return -1;
return len;
}
static int cb(int type)
{
int sd = STDIN_FILENO;
@@ -35,7 +49,7 @@ static int cb(int type)
struct sockaddr_storage sa;
socklen_t sa_len = sizeof(sa);
len = recvfrom(sd, buf, sizeof(buf), MSG_DONTWAIT, (struct sockaddr *)&sa, &sa_len);
len = recv_peer(sd, buf, sizeof(buf), (struct sockaddr *)&sa, &sa_len);
if (-1 == len)
return -1; /* On error, close connection. */
@@ -43,7 +57,7 @@ static int cb(int type)
}
static plugin_t plugin = {
.name = "echo", /* Must match the inetd /etc/services entry */
.name = NAME, /* Must match the inetd /etc/services entry */
.inetd = {
.cmd = cb
},
+6 -1
View File
@@ -28,6 +28,8 @@
#include "../plugin.h"
#define NAME "time"
/* UNIX epoch starts midnight, 1st Jan, 1970 */
#define EPOCH_OFFSET 2208988800ULL
@@ -59,6 +61,9 @@ static int recv_peer(int sd, char *buf, ssize_t len, struct sockaddr *sa, sockle
if (-1 == len)
return -1; /* On error, close connection. */
if (inetd_check_loop(sa, *sa_len, NAME))
return -1;
return 0;
}
@@ -87,7 +92,7 @@ static int cb(int type)
}
static plugin_t plugin = {
.name = "time", /* Must match the inetd /etc/services entry */
.name = NAME, /* Must match the inetd /etc/services entry */
.inetd = {
.cmd = cb
}