Skip to content

Hosts resolving to a reserved address range should be blocked by the API #339

@argl

Description

@argl

What information was incorrect, unhelpful, or incomplete?

The API allows scanning of reserved ip addresses if these are resolved by DNS.

What did you expect to see?

Those scan requests should be blocked. Look into a lookup hook function for a request to mitigate races (DNS chnages resolved ip between lookup check and actual request)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions