]> git.netwichtig.de Git - user/henk/code/inspircd.git/commitdiff
Fail invalid dns responses instead of drop
authorAdam <Adam@anope.org>
Mon, 20 Apr 2015 01:57:38 +0000 (21:57 -0400)
committerAttila Molnar <attilamolnar@hush.com>
Mon, 6 Jul 2015 15:53:21 +0000 (17:53 +0200)
include/modules/dns.h
src/coremods/core_dns.cpp

index a66e3c28e1efecb1bde708e92266da026b03ac6f..1ba54cc616375fcfed8d4d26b75b25607b617d77 100644 (file)
@@ -57,6 +57,7 @@ namespace DNS
                ERROR_UNKNOWN,
                ERROR_UNLOADED,
                ERROR_TIMEDOUT,
+               ERROR_MALFORMED,
                ERROR_NOT_AN_ANSWER,
                ERROR_NONSTANDARD_QUERY,
                ERROR_FORMAT_ERROR,
index 01e911efbe5bc177be398a57cb8c6215e7d30f26..da468af5fae273a4ace9e1c48f266d45aa5552a7 100644 (file)
@@ -497,6 +497,7 @@ class MyManager : public Manager, public Timer, public EventHandler
                        case ERROR_NOT_AN_ANSWER:
                        case ERROR_NONSTANDARD_QUERY:
                        case ERROR_FORMAT_ERROR:
+                       case ERROR_MALFORMED:
                                return "Malformed answer";
                        case ERROR_SERVER_FAILURE:
                        case ERROR_NOT_IMPLEMENTED:
@@ -539,17 +540,19 @@ class MyManager : public Manager, public Timer, public EventHandler
                }
 
                Packet recv_packet;
+               bool valid = false;
 
                try
                {
                        recv_packet.Fill(buffer, length);
+                       valid = true;
                }
                catch (Exception& ex)
                {
                        ServerInstance->Logs->Log(MODNAME, LOG_DEBUG, ex.GetReason());
-                       return;
                }
 
+               // recv_packet.id must be filled in here
                DNS::Request* request = this->requests[recv_packet.id];
                if (request == NULL)
                {
@@ -564,14 +567,20 @@ class MyManager : public Manager, public Timer, public EventHandler
                        return;
                }
 
-               if (recv_packet.flags & QUERYFLAGS_OPCODE)
+               if (!valid)
+               {
+                       ServerInstance->stats.DnsBad++;
+                       recv_packet.error = ERROR_MALFORMED;
+                       request->OnError(&recv_packet);
+               }
+               else if (recv_packet.flags & QUERYFLAGS_OPCODE)
                {
                        ServerInstance->Logs->Log(MODNAME, LOG_DEBUG, "Received a nonstandard query");
                        ServerInstance->stats.DnsBad++;
                        recv_packet.error = ERROR_NONSTANDARD_QUERY;
                        request->OnError(&recv_packet);
                }
-               else if (recv_packet.flags & QUERYFLAGS_RCODE)
+               else if (!(recv_packet.flags & QUERYFLAGS_QR) || (recv_packet.flags & QUERYFLAGS_RCODE))
                {
                        Error error = ERROR_UNKNOWN;