Add a test for potential DNS leaks via symbol interposition.
We build variants of kinit and test_acquire_cred that define their own symbols rk_dns_lookup, gethostbyname, gethostbyname2, and getaddrinfo to print a message and abort. For getaddrinfo, we abort only if the caller failed to specify AI_NUMERICHOST; otherwise we use dlsym(RTLD_NEXT, "getaddrinfo") instead. The new test tests/gss/check-nodns is like tests/gss/check-basic, but uses kinit_auditdns and test_acquire_cred_auditdns to verify that no DNS resolution happens. This test should work and be effective on ELF platforms where the getaddrinfo function is implemented by the symbol `getaddrinfo'. On non-ELF platforms it may not be effective -- and on platforms where the getaddrinfo function is implemented by another symbol (like `__getaddrinfo50') it may not work, but we can cross that bridge when we come to it. Verified manually that the test fails, with the expected error message and abort, without `block_dns = yes' in krb5-nodns.conf. No automatic test of the mechanism for now because it might not work on some platforms. XXX check-nodns.in is copypasta of check-basic.in, should factor out the common parts so they don't get out of sync.
This commit is contained in:

committed by
Nico Williams

parent
e2c0d98965
commit
ad23636db8
@@ -5,7 +5,8 @@ include $(top_srcdir)/Makefile.am.common
|
||||
WFLAGS += $(WFLAGS_LITE)
|
||||
|
||||
noinst_PROGRAMS = tcp_client tcp_server gssapi_server gssapi_client \
|
||||
uu_server uu_client nt_gss_server nt_gss_client http_client
|
||||
uu_server uu_client nt_gss_server nt_gss_client http_client \
|
||||
kinit_auditdns
|
||||
|
||||
tcp_client_SOURCES = tcp_client.c common.c test_locl.h
|
||||
|
||||
@@ -38,6 +39,25 @@ nt_gss_client_LDADD = $(gssapi_server_LDADD)
|
||||
|
||||
nt_gss_server_LDADD = $(nt_gss_client_LDADD)
|
||||
|
||||
kinit_auditdns_SOURCES = ../../kuser/kinit.c auditdns.c
|
||||
|
||||
kinit_auditdns_CPPFLAGS = $(AM_CPPFLAGS) -I$(srcdir)/../../lib/krb5
|
||||
|
||||
# sync with kinit_LDADD in kuser/Makefile.am
|
||||
if !NO_AFS
|
||||
afs_lib = $(LIB_kafs)
|
||||
endif
|
||||
kinit_auditdns_LDADD = \
|
||||
$(afs_lib) \
|
||||
$(top_builddir)/lib/krb5/libkrb5.la \
|
||||
$(top_builddir)/lib/gssapi/libgssapi.la \
|
||||
$(top_builddir)/lib/gss_preauth/libgss_preauth.la \
|
||||
$(top_builddir)/lib/ntlm/libheimntlm.la \
|
||||
$(LIB_hcrypto) \
|
||||
$(top_builddir)/lib/asn1/libasn1.la \
|
||||
$(LIB_libintl) \
|
||||
$(LIB_roken)
|
||||
|
||||
LDADD = $(top_builddir)/lib/krb5/libkrb5.la \
|
||||
$(LIB_hcrypto) \
|
||||
$(top_builddir)/lib/asn1/libasn1.la \
|
||||
|
96
appl/test/auditdns.c
Normal file
96
appl/test/auditdns.c
Normal file
@@ -0,0 +1,96 @@
|
||||
/*-
|
||||
* Copyright (c) 2024 Taylor R. Campbell
|
||||
* All rights reserved.
|
||||
*
|
||||
* Redistribution and use in source and binary forms, with or without
|
||||
* modification, are permitted provided that the following conditions
|
||||
* are met:
|
||||
* 1. Redistributions of source code must retain the above copyright
|
||||
* notice, this list of conditions and the following disclaimer.
|
||||
* 2. Redistributions in binary form must reproduce the above copyright
|
||||
* notice, this list of conditions and the following disclaimer in the
|
||||
* documentation and/or other materials provided with the distribution.
|
||||
*
|
||||
* THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
|
||||
* ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
||||
* IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
|
||||
* ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
|
||||
* FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
|
||||
* DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
|
||||
* OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
|
||||
* HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
|
||||
* LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
|
||||
* OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
|
||||
* SUCH DAMAGE.
|
||||
*/
|
||||
|
||||
#ifdef HAVE_CONFIG_H
|
||||
#include <config.h>
|
||||
#endif
|
||||
|
||||
#include <dlfcn.h>
|
||||
#include <netdb.h>
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
|
||||
#include "resolve.h"
|
||||
|
||||
struct rk_dns_reply *
|
||||
rk_dns_lookup(const char *domain, const char *type_name)
|
||||
{
|
||||
|
||||
fprintf(stderr, "DNS leak: %s %s (%s)\n", __func__, domain, type_name);
|
||||
abort();
|
||||
}
|
||||
|
||||
struct hostent *
|
||||
gethostbyname(const char *name)
|
||||
{
|
||||
|
||||
fprintf(stderr, "DNS leak: %s %s\n", __func__, name);
|
||||
abort();
|
||||
}
|
||||
|
||||
#ifdef HAVE_GETHOSTBYNAME2
|
||||
|
||||
struct hostent *
|
||||
gethostbyname2(const char *name, int af)
|
||||
{
|
||||
|
||||
fprintf(stderr, "DNS leak: %s %s\n", __func__, name);
|
||||
abort();
|
||||
}
|
||||
|
||||
#endif /* HAVE_GETHOSTBYNAME2 */
|
||||
|
||||
#ifdef HAVE_GETADDRINFO
|
||||
|
||||
typedef int getaddrinfo_fn_t(const char *, const char *,
|
||||
const struct addrinfo *restrict,
|
||||
struct addrinfo **restrict);
|
||||
getaddrinfo_fn_t getaddrinfo;
|
||||
int
|
||||
getaddrinfo(const char *hostname, const char *servname,
|
||||
const struct addrinfo *restrict hints,
|
||||
struct addrinfo **restrict res)
|
||||
{
|
||||
void *sym;
|
||||
|
||||
if (hints == NULL ||
|
||||
(hints->ai_flags & AI_NUMERICHOST) == 0 ||
|
||||
(hints->ai_flags & AI_CANONNAME) != 0) {
|
||||
fprintf(stderr, "DNS leak: %s %s:%s\n",
|
||||
__func__, hostname, servname);
|
||||
abort();
|
||||
}
|
||||
|
||||
if ((sym = dlsym(RTLD_NEXT, __func__)) == NULL) {
|
||||
fprintf(stderr, "dlsym(RTLD_NEXT, \"%s\") failed: %s\n",
|
||||
__func__, dlerror());
|
||||
return EAI_FAIL;
|
||||
}
|
||||
|
||||
return (*(getaddrinfo_fn_t *)sym)(hostname, servname, hints, res);
|
||||
}
|
||||
|
||||
#endif /* HAVE_GETADDRINFO */
|
Reference in New Issue
Block a user