Default-block Azure WireServer's public address (closes #245)
check / check (push) Successful in 4m54s
check / check (push) Successful in 4m54s
Add 168.63.129.16 to blockedNetworks, the default blocklist, not alwaysBlockedNetworks: it is public unicast, so an operator who lists it in ALLOWED_EGRESS_CIDRS can reach it again. The default-blocklist refusal no longer says "private/reserved", which this address is not. Sources: - Fixed, Microsoft-owned address: https://learn.microsoft.com/en-us/azure/virtual-network/what-is-ip-address-168-63-129-16 - WireServer there bootstraps VM credentials and serves secrets: https://learn.microsoft.com/en-us/azure/virtual-machines/metadata-security-protocol/overview 147.75.207.243 (Equinix Metal) is not added: Equinix's metadata page names only the hostname metadata.platformequinix.com, not the address, and says Equinix Metal was sunset on 2026-06-30. Model: opus-5-5
This commit is contained in:
@@ -26,7 +26,7 @@ var (
|
||||
"hostname resolved to no IP addresses",
|
||||
)
|
||||
errBlockedIP = errors.New(
|
||||
"blocked private/reserved IP range",
|
||||
"blocked private, reserved or cloud metadata address",
|
||||
)
|
||||
errBlockedMetadata = errors.New(
|
||||
"blocked link-local or cloud instance metadata " +
|
||||
@@ -37,9 +37,10 @@ var (
|
||||
)
|
||||
)
|
||||
|
||||
// blockedNetworks contains all private/reserved IP ranges
|
||||
// that should be blocked to prevent SSRF attacks. An operator
|
||||
// can permit specific blocks out of this set with
|
||||
// blockedNetworks is the default blocklist: the private and
|
||||
// reserved IP ranges, plus the public cloud metadata addresses,
|
||||
// that are blocked to prevent SSRF attacks. An operator can
|
||||
// permit specific blocks out of this set with
|
||||
// ALLOWED_EGRESS_CIDRS; see Guard.
|
||||
//
|
||||
//nolint:gochecknoglobals // package-level network list is appropriate here
|
||||
@@ -122,6 +123,8 @@ func init() {
|
||||
"::1/128",
|
||||
"fc00::/7",
|
||||
"fe80::/10",
|
||||
// Azure WireServer, a public address that serves VM credentials.
|
||||
"168.63.129.16/32",
|
||||
})
|
||||
|
||||
// Every entry is named. The set must not grow or shrink
|
||||
@@ -216,8 +219,8 @@ func matchesAny(networks []*net.IPNet, ip net.IP) bool {
|
||||
}
|
||||
|
||||
// isBlockedIP checks whether an IP address falls within
|
||||
// any blocked private/reserved network range, before any
|
||||
// operator allowlist is considered.
|
||||
// the default blocklist, before any operator allowlist is
|
||||
// considered.
|
||||
func isBlockedIP(ip net.IP) bool {
|
||||
return matchesAny(blockedNetworks, ip)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user