Skip to content
This repository has been archived by the owner on Apr 26, 2024. It is now read-only.

default config: blacklist more internal ips #1198

Merged
merged 1 commit into from
Nov 7, 2016

Conversation

euank
Copy link
Contributor

@euank euank commented Nov 7, 2016

The server making requests to 169.254.169.254 is particularly scary because quite sensitive information can be stored there (e.g. the ec2 metadata service)

That being said, since none of those pages have a title, are html, or are media, the chance of it leading to any active information leak is pretty low, so I don't feel this is an actual vulnerability, just a more complete default setting.
For completeness I included another private ip range too that was missing

@matrixbot
Copy link
Member

Can one of the admins verify this patch?

4 similar comments
@matrixbot
Copy link
Member

Can one of the admins verify this patch?

@matrixbot
Copy link
Member

Can one of the admins verify this patch?

@matrixbot
Copy link
Member

Can one of the admins verify this patch?

@matrixbot
Copy link
Member

Can one of the admins verify this patch?

@euank
Copy link
Contributor Author

euank commented Nov 7, 2016

Thanks for doing your job so eagerly @matrixbot ❤️

@erikjohnston erikjohnston changed the base branch from master to develop November 7, 2016 09:37
@erikjohnston
Copy link
Member

Thanks!

@erikjohnston erikjohnston merged commit d24197b into matrix-org:develop Nov 7, 2016
@euank euank deleted the more-ip-blacklist branch November 7, 2016 09:59
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants