Add a test for potential DNS leaks via symbol interposition.

We build variants of kinit and test_acquire_cred that define their
own symbols rk_dns_lookup, gethostbyname, gethostbyname2, and
getaddrinfo to print a message and abort.  For getaddrinfo, we abort
only if the caller failed to specify AI_NUMERICHOST; otherwise we use
dlsym(RTLD_NEXT, "getaddrinfo") instead.

The new test tests/gss/check-nodns is like tests/gss/check-basic, but
uses kinit_auditdns and test_acquire_cred_auditdns to verify that no
DNS resolution happens.

This test should work and be effective on ELF platforms where the
getaddrinfo function is implemented by the symbol `getaddrinfo'.  On
non-ELF platforms it may not be effective -- and on platforms where
the getaddrinfo function is implemented by another symbol (like
`__getaddrinfo50') it may not work, but we can cross that bridge when
we come to it.

Verified manually that the test fails, with the expected error
message and abort, without `block_dns = yes' in krb5-nodns.conf.  No
automatic test of the mechanism for now because it might not work on
some platforms.

XXX check-nodns.in is copypasta of check-basic.in, should factor out
the common parts so they don't get out of sync.
This commit is contained in:
Taylor R Campbell
2024-01-07 21:44:29 +00:00
committed by Nico Williams
parent e2c0d98965
commit ad23636db8
8 changed files with 411 additions and 4 deletions

View File

@@ -5,7 +5,8 @@ include $(top_srcdir)/Makefile.am.common
WFLAGS += $(WFLAGS_LITE)
noinst_PROGRAMS = tcp_client tcp_server gssapi_server gssapi_client \
uu_server uu_client nt_gss_server nt_gss_client http_client
uu_server uu_client nt_gss_server nt_gss_client http_client \
kinit_auditdns
tcp_client_SOURCES = tcp_client.c common.c test_locl.h
@@ -38,6 +39,25 @@ nt_gss_client_LDADD = $(gssapi_server_LDADD)
nt_gss_server_LDADD = $(nt_gss_client_LDADD)
kinit_auditdns_SOURCES = ../../kuser/kinit.c auditdns.c
kinit_auditdns_CPPFLAGS = $(AM_CPPFLAGS) -I$(srcdir)/../../lib/krb5
# sync with kinit_LDADD in kuser/Makefile.am
if !NO_AFS
afs_lib = $(LIB_kafs)
endif
kinit_auditdns_LDADD = \
$(afs_lib) \
$(top_builddir)/lib/krb5/libkrb5.la \
$(top_builddir)/lib/gssapi/libgssapi.la \
$(top_builddir)/lib/gss_preauth/libgss_preauth.la \
$(top_builddir)/lib/ntlm/libheimntlm.la \
$(LIB_hcrypto) \
$(top_builddir)/lib/asn1/libasn1.la \
$(LIB_libintl) \
$(LIB_roken)
LDADD = $(top_builddir)/lib/krb5/libkrb5.la \
$(LIB_hcrypto) \
$(top_builddir)/lib/asn1/libasn1.la \

96
appl/test/auditdns.c Normal file
View File

@@ -0,0 +1,96 @@
/*-
* Copyright (c) 2024 Taylor R. Campbell
* All rights reserved.
*
* Redistribution and use in source and binary forms, with or without
* modification, are permitted provided that the following conditions
* are met:
* 1. Redistributions of source code must retain the above copyright
* notice, this list of conditions and the following disclaimer.
* 2. Redistributions in binary form must reproduce the above copyright
* notice, this list of conditions and the following disclaimer in the
* documentation and/or other materials provided with the distribution.
*
* THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
* ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
* IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
* ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
* FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
* DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
* OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
* HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
* LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
* OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
* SUCH DAMAGE.
*/
#ifdef HAVE_CONFIG_H
#include <config.h>
#endif
#include <dlfcn.h>
#include <netdb.h>
#include <stdio.h>
#include <stdlib.h>
#include "resolve.h"
struct rk_dns_reply *
rk_dns_lookup(const char *domain, const char *type_name)
{
fprintf(stderr, "DNS leak: %s %s (%s)\n", __func__, domain, type_name);
abort();
}
struct hostent *
gethostbyname(const char *name)
{
fprintf(stderr, "DNS leak: %s %s\n", __func__, name);
abort();
}
#ifdef HAVE_GETHOSTBYNAME2
struct hostent *
gethostbyname2(const char *name, int af)
{
fprintf(stderr, "DNS leak: %s %s\n", __func__, name);
abort();
}
#endif /* HAVE_GETHOSTBYNAME2 */
#ifdef HAVE_GETADDRINFO
typedef int getaddrinfo_fn_t(const char *, const char *,
const struct addrinfo *restrict,
struct addrinfo **restrict);
getaddrinfo_fn_t getaddrinfo;
int
getaddrinfo(const char *hostname, const char *servname,
const struct addrinfo *restrict hints,
struct addrinfo **restrict res)
{
void *sym;
if (hints == NULL ||
(hints->ai_flags & AI_NUMERICHOST) == 0 ||
(hints->ai_flags & AI_CANONNAME) != 0) {
fprintf(stderr, "DNS leak: %s %s:%s\n",
__func__, hostname, servname);
abort();
}
if ((sym = dlsym(RTLD_NEXT, __func__)) == NULL) {
fprintf(stderr, "dlsym(RTLD_NEXT, \"%s\") failed: %s\n",
__func__, dlerror());
return EAI_FAIL;
}
return (*(getaddrinfo_fn_t *)sym)(hostname, servname, hints, res);
}
#endif /* HAVE_GETADDRINFO */