mirror of
https://github.com/3proxy/3proxy.git
synced 2026-10-07 20:45:48 +08:00
Fix: invalid hostname ACL handling in UDPASSOC
Some checks failed
C/C++ CI Linux / ${{ matrix.target }} (ubuntu-24.04-arm) (push) Has been cancelled
C/C++ CI Linux / ${{ matrix.target }} (ubuntu-latest) (push) Has been cancelled
C/C++ CI MacOS / ${{ matrix.target }} (macos-15) (push) Has been cancelled
C/C++ CI Windows / ${{ matrix.target }} (windows-2022) (push) Has been cancelled
C/C++ CI cmake / ${{ matrix.target }} (macos-15) (push) Has been cancelled
C/C++ CI cmake / ${{ matrix.target }} (ubuntu-24.04-arm) (push) Has been cancelled
C/C++ CI cmake / ${{ matrix.target }} (ubuntu-latest) (push) Has been cancelled
C/C++ CI cmake / ${{ matrix.target }} (windows-2022) (push) Has been cancelled
C/C++ CI cmake / ubuntu-latest (wolfSSL) (push) Has been cancelled
Some checks failed
C/C++ CI Linux / ${{ matrix.target }} (ubuntu-24.04-arm) (push) Has been cancelled
C/C++ CI Linux / ${{ matrix.target }} (ubuntu-latest) (push) Has been cancelled
C/C++ CI MacOS / ${{ matrix.target }} (macos-15) (push) Has been cancelled
C/C++ CI Windows / ${{ matrix.target }} (windows-2022) (push) Has been cancelled
C/C++ CI cmake / ${{ matrix.target }} (macos-15) (push) Has been cancelled
C/C++ CI cmake / ${{ matrix.target }} (ubuntu-24.04-arm) (push) Has been cancelled
C/C++ CI cmake / ${{ matrix.target }} (ubuntu-latest) (push) Has been cancelled
C/C++ CI cmake / ${{ matrix.target }} (windows-2022) (push) Has been cancelled
C/C++ CI cmake / ubuntu-latest (wolfSSL) (push) Has been cancelled
This commit is contained in:
parent
ffa1a05009
commit
f52dc0f0b9
@ -288,6 +288,12 @@ int udpsockmap(struct clientparam *param, int timeo)
|
|||||||
}
|
}
|
||||||
default: return 997;
|
default: return 997;
|
||||||
}
|
}
|
||||||
|
/* As for TCP requests, a literal address is the host name,
|
||||||
|
otherwise an ACL with host names only matches any address */
|
||||||
|
if (!dstname) {
|
||||||
|
myinet_ntop(*SAFAMILY(&dst), SAADDR(&dst), dstnamebuf, sizeof(dstnamebuf));
|
||||||
|
dstname = dstnamebuf;
|
||||||
|
}
|
||||||
memcpy(SAPORT(&dst), base + i, 2);
|
memcpy(SAPORT(&dst), base + i, 2);
|
||||||
i += 2;
|
i += 2;
|
||||||
|
|
||||||
|
|||||||
@ -5,6 +5,8 @@ def run(t):
|
|||||||
srv = t.free_port()
|
srv = t.free_port()
|
||||||
sks = t.free_port()
|
sks = t.free_port()
|
||||||
sauth = t.free_port()
|
sauth = t.free_port()
|
||||||
|
sdeny = t.free_port()
|
||||||
|
sallow = t.free_port()
|
||||||
|
|
||||||
t.start("socks", f"""
|
t.start("socks", f"""
|
||||||
log
|
log
|
||||||
@ -24,7 +26,18 @@ def run(t):
|
|||||||
users alice:CL:secret
|
users alice:CL:secret
|
||||||
allow alice
|
allow alice
|
||||||
socks -p{sauth}
|
socks -p{sauth}
|
||||||
""", ports=[srv, sks, sauth])
|
|
||||||
|
flush
|
||||||
|
auth iponly
|
||||||
|
deny * * *.example.com
|
||||||
|
allow *
|
||||||
|
socks -p{sdeny}
|
||||||
|
|
||||||
|
flush
|
||||||
|
auth iponly
|
||||||
|
allow * * *.example.com
|
||||||
|
socks -p{sallow}
|
||||||
|
""", ports=[srv, sks, sauth, sdeny, sallow])
|
||||||
|
|
||||||
origin = f"http://127.0.0.1:{srv}"
|
origin = f"http://127.0.0.1:{srv}"
|
||||||
plain = f"127.0.0.1:{sks}"
|
plain = f"127.0.0.1:{sks}"
|
||||||
@ -62,6 +75,16 @@ def run(t):
|
|||||||
_, second = t.socks_udp(plain, "127.0.0.1", echo, b"two")
|
_, second = t.socks_udp(plain, "127.0.0.1", echo, b"two")
|
||||||
t.ne(first, second, "a second association binds its own port")
|
t.ne(first, second, "a second association binds its own port")
|
||||||
|
|
||||||
|
# A datagram names its destination by address. A rule listing host names
|
||||||
|
# only has to judge it by that address as text, the way CONNECT is judged,
|
||||||
|
# rather than match whatever the address is.
|
||||||
|
reply, _ = t.socks_udp(f"127.0.0.1:{sdeny}", "127.0.0.1", echo, b"ip")
|
||||||
|
t.eq(b"echo:ip", reply,
|
||||||
|
"a deny by host name leaves datagrams to an address alone")
|
||||||
|
reply, _ = t.socks_udp(f"127.0.0.1:{sallow}", "127.0.0.1", echo, b"ip")
|
||||||
|
t.eq(None, reply,
|
||||||
|
"an allow by host name does not let datagrams to an address through")
|
||||||
|
|
||||||
# --- authentication ----------------------------------------------------
|
# --- authentication ----------------------------------------------------
|
||||||
t.eq(200, t.socks_http(guarded, origin + "/echo",
|
t.eq(200, t.socks_http(guarded, origin + "/echo",
|
||||||
auth=("alice", "secret")).status,
|
auth=("alice", "secret")).status,
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user