Skip to content

Capture(only_global_lookup=True, ...) does not handle local hostname rejection #260

Description

@TontonSancho

In a local network environment with local hostname defined manually (e.g: internal docker container networks), settings only_global_lookup=True does not reject capture.

Both situation are "manually defined hostname":

  • editing /etc/hosts (or equivalent) and with an entry like my-local-service 172.18.0.1
  • accessing containers in a docker (or equivalent) infrastructure using their container-name

Capturing http://my-local-service:8080 will succeed if my-local-service serves 8080 port, even if only_global_lookup=True.

The fact is try_into_ip just try to parse the "string" into an ip address. This does not "resolve" the potential hostname into its ip equivalent.

try:
ip = ipaddress.ip_address(_url.host.try_into_ip())
if ip.is_global:
return True, "Global IP"
# Non-global IP
self.logger.warning(f"Attempt to open a non-public IP: {url}")
return False, f"Attempted to open {url}, blocked."
except ValueError:
# not an IP, continue to hostname
pass

An hostname resolve round should be performed. (E.g: with addr_info = socket.getaddrinfo(host, None))
Or if it's the intended behavior, the documentation should mention that no hostname ip resolution is performed while setting only_global_lookup=True.

Regards

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions