Default-block Azure WireServer's public address (closes #245)
check / check (push) Successful in 4m54s
check / check (push) Successful in 4m54s
Add 168.63.129.16 to blockedNetworks, the default blocklist, not alwaysBlockedNetworks: it is public unicast, so an operator who lists it in ALLOWED_EGRESS_CIDRS can reach it again. The default-blocklist refusal no longer says "private/reserved", which this address is not. Sources: - Fixed, Microsoft-owned address: https://learn.microsoft.com/en-us/azure/virtual-network/what-is-ip-address-168-63-129-16 - WireServer there bootstraps VM credentials and serves secrets: https://learn.microsoft.com/en-us/azure/virtual-machines/metadata-security-protocol/overview 147.75.207.243 (Equinix Metal) is not added: Equinix's metadata page names only the hostname metadata.platformequinix.com, not the address, and says Equinix Metal was sunset on 2026-06-30. Model: opus-5-5
This commit is contained in:
@@ -157,6 +157,11 @@ private and reserved ranges — RFC 1918, loopback, CGNAT, link-local and
|
||||
the rest — are refused, which stops a target from being used to make
|
||||
webhooker probe the network it sits in.
|
||||
|
||||
Besides the private and reserved ranges, the default blocklist refuses
|
||||
public cloud metadata addresses: currently only `168.63.129.16`, Azure's
|
||||
WireServer, which serves an Azure VM its credentials. Because it is a
|
||||
public address, listing it in `ALLOWED_EGRESS_CIDRS` reopens it.
|
||||
|
||||
That default is also inconvenient for the thing webhooker is mostly
|
||||
for: taking a public webhook and forwarding it to something on your own
|
||||
network. A container on the same Docker network, a box on `10.x`, a
|
||||
@@ -242,7 +247,8 @@ Two things this setting cannot do:
|
||||
encodings, which the default blocklist does not match. A publicly
|
||||
routable metadata address is not listed here, because nothing on this
|
||||
list can be reopened and blocking one that way would leave you no
|
||||
escape hatch at all.
|
||||
escape hatch at all; Azure's `168.63.129.16` is refused by the default
|
||||
blocklist instead, as described above.
|
||||
|
||||
This list is not exhaustive of every cloud's metadata address — if
|
||||
yours is not here, do not allowlist the block that contains it.
|
||||
|
||||
Reference in New Issue
Block a user