mirror of
https://github.com/troglobit/finit.git
synced 2026-10-08 08:24:43 +07:00
Add protection against UDP inetd looping attacks
This patch adds protection against a common inetd attack vector wherein the reply port to UDP inetd services is forged to an internal inetd service port. Signed-off-by: Joachim Nilsson <troglobit@gmail.com>
This commit is contained in:
+5
-1
@@ -27,6 +27,7 @@
|
||||
|
||||
#include "../plugin.h"
|
||||
|
||||
#define NAME "chargen"
|
||||
#define PATTERN "!\"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}~ "
|
||||
|
||||
static char *generator(char *buf, size_t len)
|
||||
@@ -61,6 +62,9 @@ static int recv_peer(int sd, char *buf, ssize_t len, struct sockaddr *sa, sockle
|
||||
if (-1 == len)
|
||||
return -1; /* On error, close connection. */
|
||||
|
||||
if (inetd_check_loop(sa, *sa_len, NAME))
|
||||
return -1;
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -86,7 +90,7 @@ static int cb(int type)
|
||||
}
|
||||
|
||||
static plugin_t plugin = {
|
||||
.name = "chargen", /* Must match the inetd /etc/services entry */
|
||||
.name = NAME, /* Must match the inetd /etc/services entry */
|
||||
.inetd = {
|
||||
.cmd = cb
|
||||
},
|
||||
|
||||
+7
-1
@@ -28,6 +28,9 @@
|
||||
|
||||
#include "../plugin.h"
|
||||
|
||||
#define NAME "daytime"
|
||||
|
||||
|
||||
static char *daytime(char *buf, size_t len)
|
||||
{
|
||||
time_t t;
|
||||
@@ -48,6 +51,9 @@ static int recv_peer(int sd, char *buf, ssize_t len, struct sockaddr *sa, sockle
|
||||
if (-1 == len)
|
||||
return -1; /* On error, close connection. */
|
||||
|
||||
if (inetd_check_loop(sa, *sa_len, NAME))
|
||||
return -1;
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -72,7 +78,7 @@ static int cb(int type)
|
||||
}
|
||||
|
||||
static plugin_t plugin = {
|
||||
.name = "daytime", /* Must match the inetd /etc/services entry */
|
||||
.name = NAME, /* Must match the inetd /etc/services entry */
|
||||
.inetd = {
|
||||
.cmd = cb
|
||||
}
|
||||
|
||||
+16
-2
@@ -27,6 +27,20 @@
|
||||
|
||||
#include "../plugin.h"
|
||||
|
||||
#define NAME "echo"
|
||||
|
||||
static int recv_peer(int sd, char *buf, ssize_t len, struct sockaddr *sa, socklen_t *sa_len)
|
||||
{
|
||||
len = recvfrom(sd, buf, sizeof(buf), MSG_DONTWAIT, sa, sa_len);
|
||||
if (-1 == len)
|
||||
return -1; /* On error, close connection. */
|
||||
|
||||
if (inetd_check_loop(sa, *sa_len, NAME))
|
||||
return -1;
|
||||
|
||||
return len;
|
||||
}
|
||||
|
||||
static int cb(int type)
|
||||
{
|
||||
int sd = STDIN_FILENO;
|
||||
@@ -35,7 +49,7 @@ static int cb(int type)
|
||||
struct sockaddr_storage sa;
|
||||
socklen_t sa_len = sizeof(sa);
|
||||
|
||||
len = recvfrom(sd, buf, sizeof(buf), MSG_DONTWAIT, (struct sockaddr *)&sa, &sa_len);
|
||||
len = recv_peer(sd, buf, sizeof(buf), (struct sockaddr *)&sa, &sa_len);
|
||||
if (-1 == len)
|
||||
return -1; /* On error, close connection. */
|
||||
|
||||
@@ -43,7 +57,7 @@ static int cb(int type)
|
||||
}
|
||||
|
||||
static plugin_t plugin = {
|
||||
.name = "echo", /* Must match the inetd /etc/services entry */
|
||||
.name = NAME, /* Must match the inetd /etc/services entry */
|
||||
.inetd = {
|
||||
.cmd = cb
|
||||
},
|
||||
|
||||
+6
-1
@@ -28,6 +28,8 @@
|
||||
|
||||
#include "../plugin.h"
|
||||
|
||||
#define NAME "time"
|
||||
|
||||
/* UNIX epoch starts midnight, 1st Jan, 1970 */
|
||||
#define EPOCH_OFFSET 2208988800ULL
|
||||
|
||||
@@ -59,6 +61,9 @@ static int recv_peer(int sd, char *buf, ssize_t len, struct sockaddr *sa, sockle
|
||||
if (-1 == len)
|
||||
return -1; /* On error, close connection. */
|
||||
|
||||
if (inetd_check_loop(sa, *sa_len, NAME))
|
||||
return -1;
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -87,7 +92,7 @@ static int cb(int type)
|
||||
}
|
||||
|
||||
static plugin_t plugin = {
|
||||
.name = "time", /* Must match the inetd /etc/services entry */
|
||||
.name = NAME, /* Must match the inetd /etc/services entry */
|
||||
.inetd = {
|
||||
.cmd = cb
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user