Commit Graph

3433 Commits

Author SHA1 Message Date
DL6ER fa4c194045 Improve URI matching algorithm
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-26 17:46:11 +01:00
DL6ER e8e4c5f180 Move id, date_added, date_modified into extra database object
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-26 17:46:09 +01:00
DL6ER efd5951968 POST should not include the target to get pushed
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-24 16:07:27 +01:00
DL6ER 0358c3b861 Test compile regex before adding to the database (we may want to reject it)
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-23 08:31:21 +01:00
DL6ER f12aa58f3f Rename /api/adlists -> /api/lists
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-23 07:49:41 +01:00
DL6ER 5e616f4ac2 Fix a bug in CivetWeb server
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-23 07:11:38 +01:00
DL6ER 8b3df9f554 Implement /api/clients
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-22 15:25:49 +01:00
DL6ER 9a2a2cdf10 Actually reload gravity data on list add/edit/remove
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-22 11:58:36 +01:00
DL6ER 98e74256ae Send domains/clients/groups/adlists counts in a new ftl object
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-22 11:47:57 +01:00
DL6ER 45801543db Remove obsolete ping/pong test
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-22 11:20:12 +01:00
DL6ER 54e206a273 Shorten history JSON keys
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-22 10:28:27 +01:00
DL6ER f67becc3e1 Introduce new ftl_conn struct that makes it easier to share stuff across processing subroutines in the same thread.
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-21 16:24:16 +01:00
DL6ER 15ba45e50f Extract payload only once
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-21 13:52:31 +01:00
DL6ER 0d91fcd55d Rename /api/list -> /api/domains, /api/adlist -> /api/adlists, /api/group -> /api/groups, added /api/clients
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-21 08:28:37 +01:00
DL6ER 1fc05034ef Set table columns comment/description to NULL if empty
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-20 17:07:36 +01:00
DL6ER 5c3a2b509c Implement changing group assignments through the API
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-20 16:36:02 +01:00
DL6ER 7fa2dac90a Allow domains/groups/adlists to be removed from the database
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-20 12:33:16 +01:00
DL6ER b08954aec7 http_get_payload(): Extract body payload also for PUT and PATCH
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-20 11:51:23 +01:00
DL6ER 5e1c75fb84 Include system object in /api/stats/summary to need one AJAX call less
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-20 11:12:47 +01:00
DL6ER 24aa5537a0 Merge branch 'master' into new/http 2021-01-20 10:12:09 +01:00
DL6ER 3ecec151b6 Merge branch 'release/v5.5' v5.5.1 2021-01-19 15:56:18 +01:00
DL6ER d6b1fe9569 Fix incorrect "FATAL" error message during garbage collection
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-19 15:54:37 +01:00
DL6ER 7acaeb72c7 Merge branch 'development' into new/http
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-19 15:35:46 +01:00
DL6ER 4457a1ad29 Merge pull request #1035 from pi-hole/master
Update development
2021-01-19 14:15:06 +01:00
DL6ER fb9b2744b4 Merge pull request #1034 from pi-hole/release/v5.5
Pi-hole FTL v5.5
v5.5
2021-01-19 13:17:26 +01:00
Simon Kelley 1ecb3ff96e Update to new struct frec fields in conntrack code.
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-19 13:08:08 +01:00
Simon Kelley 8e84016f54 Fix warning message logic.
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-19 13:07:59 +01:00
DL6ER 845890fea1 Update dnsmasq version string
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-19 10:34:36 +01:00
DL6ER df2df56c51 Adapt for change in struct forward to forward->frec_src
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-19 10:34:36 +01:00
Simon Kelley fab1f64db1 Small cleanups in frec_src datastucture handling.
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-19 10:34:36 +01:00
Petr Menšík dad7959f2b Support hash function from nettle (only)
Unlike COPTS=-DHAVE_DNSSEC, allow usage of just sha256 function from
nettle, but keep DNSSEC disabled at build time. Skips use of internal
hash implementation without support for validation built-in.

Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-19 10:34:36 +01:00
Simon Kelley a4864cf5dd Handle caching with EDNS options better.
If we add the EDNS client subnet option, or the client's
MAC address, then the reply we get back may very depending on
that. Since the cache is ignorant of such things, it's not safe to
cache such replies. This patch determines when a dangerous EDNS
option is being added and disables caching.

Note that for much the same reason, we can't combine multiple
queries for the same question when dangerous EDNS options are
being added, and the code now handles that in the same way. This
query combining is required for security against cache poisoning,
so disabling the cache has a security function as well as a
correctness one.

Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-19 10:34:36 +01:00
Simon Kelley 3774edeba8 Handle multiple identical near simultaneous DNS queries better.
Previously, such queries would all be forwarded
independently. This is, in theory, inefficent but in practise
not a problem, _except_ that is means that an answer for any
of the forwarded queries will be accepted and cached.
An attacker can send a query multiple times, and for each repeat,
another {port, ID} becomes capable of accepting the answer he is
sending in the blind, to random IDs and ports. The chance of a
succesful attack is therefore multiplied by the number of repeats
of the query. The new behaviour detects repeated queries and
merely stores the clients sending repeats so that when the
first query completes, the answer can be sent to all the
clients who asked. Refer: CERT VU#434904.

Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-19 10:34:36 +01:00
Simon Kelley a5743a1643 Add missing check for NULL return from allocate_rfd().
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-19 10:34:36 +01:00
Simon Kelley 17cb5d4d81 Fix DNS reply when asking for DNSSEC and a validated CNAME is already cached.
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-19 10:34:36 +01:00
Simon Kelley 58c6b8d56e Optimse RR digest calculation in DNSSEC.
If an RR is of a type which doesn't need canonicalisation,
bypass the relatively slow canonicalisation code, and insert
it direct into the digest.

Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-19 10:34:36 +01:00
Simon Kelley afff889e82 Use SHA-256 to provide security against DNS cache poisoning.
Use the SHA-256 hash function to verify that DNS answers
received are for the questions originally asked. This replaces
the slightly insecure SHA-1 (when compiled with DNSSEC) or
the very insecure CRC32 (otherwise). Refer: CERT VU#434904.

Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-19 10:34:36 +01:00
Simon Kelley 9002e99cd8 Check destination of DNS UDP query replies.
At any time, dnsmasq will have a set of sockets open, bound to
random ports, on which it sends queries to upstream nameservers.
This patch fixes the existing problem that a reply for ANY in-flight
query would be accepted via ANY open port, which increases the
chances of an attacker flooding answers "in the blind" in an
attempt to poison the DNS cache. CERT VU#434904 refers.

Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-19 10:34:36 +01:00
Simon Kelley e68acd8e6c Fix remote buffer overflow CERT VU#434904
The problem is in the sort_rrset() function and allows a remote
attacker to overwrite memory. Any dnsmasq instance with DNSSEC
enabled is vulnerable.

Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-19 10:34:35 +01:00
Simon Kelley 5deb35b24f Use the values of --min-port and --max-port in TCP connections.
Rather that letting the kernel pick source ports, do it ourselves
so that the --min-port and --max-port parameters are be obeyed.

Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-19 10:34:35 +01:00
Miao Wang 76b610ee39 pxe: support pxe clients with custom vendor-class
According to UEFI[1] and PXE[2] specs, PXE clients are required to have
`PXEClient` identfier in the vendor-class field of DHCP requests, and
PXE servers should also include that identifier in their responses.
However, the firmware of servers from a few vendors[3] are customized to
include a different identifier. This patch adds an option named
`dhcp-pxe-vendor` to provide a list of such identifiers. The identifier
used in responses sent from dnsmasq is identical to that in the coresponding
request.

[1]: https://uefi.org/sites/default/files/resources/UEFI%20Spec%202.8B%20May%202020.pdf
[2]: http://www.pix.net/software/pxeboot/archive/pxespec.pdf
[3]: For instance, TaiShan servers from Huawei, which are Arm64-based,
       send `HW-Client` in PXE requests up to now.

Signed-off-by: Miao Wang <shankerwangmiao@gmail.com>
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-19 10:34:35 +01:00
DL6ER 96cb7fdeea Merge pull request #1033 from pi-hole/fix/maxdb_overflow
Config option MAXDBDAYS fixes and tweaks
2021-01-18 22:09:18 +01:00
DL6ER 4d83a5adec Merge pull request #1032 from pi-hole/fix/querylog_filtering
Fix for Query Log filtering and memory optimizations
2021-01-18 21:58:34 +01:00
DL6ER ca36f2de8d Add MAXDBDAYS=-1 to disable auto-cleaning and ensure overflow cannot happen (we just enforce the maximum in this case)
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-18 19:41:02 +01:00
DL6ER 471fbf7b62 Use blocked property in API code. Make query->upstreamID = -1 the new default to differentiate easily what was forwarded (ID will be >= 0) and what not (ID == -1). Store the upstream server also for other query types that were forwarded (like queries blocked during CNAME inspection).
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-18 15:19:50 +01:00
DL6ER c227fc1598 Store blocked property in query flags.
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-18 15:04:59 +01:00
DL6ER 50d182950a Statically assert struct sizes are what we expect. This prevents us from increasing the memory needs unintentionally (e.g. due to sub-optimal padding)
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-18 14:29:03 +01:00
DL6ER deae66ba58 Optimize datastructures using bitfields and item re-arrangement (to minimize padding). This reduces the size of query, client, and regex records by 8 bytes per item. Note that this optimization was done on x86_64 and may not apply for other architectures (32bit architectures already used less padding).
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-17 13:06:16 +01:00
DL6ER c0505d7729 Improve format of overTime replies.
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-16 16:07:26 +01:00
DL6ER b7f94c7850 Tests: No login needed when there is no password
Signed-off-by: DL6ER <dl6er@dl6er.de>
2021-01-16 12:39:34 +01:00