[package] dnsmasq: add and enable DNS rebind protections
[openwrt.git] / package / dnsmasq / files / dnsmasq.init
index 4cd941c..49291a5 100644 (file)
@@ -99,6 +99,29 @@ dnsmasq() {
 
        config_get hostsfile "$cfg" dhcphostsfile
        [ -e "$hostsfile" ] && append args "--dhcp-hostsfile=$hostsfile"
+
+       local rebind
+       config_get_bool rebind "$cfg" rebind_protection 1
+       [ $rebind -gt 0 ] && {
+               logger -t dnsmasq \
+                       "DNS rebinding protection is active," \
+                       "will discard upstream RFC1918 responses!"
+               append args "--stop-dns-rebind"
+
+               local rebind_localhost
+               config_get_bool rebind_localhost "$cfg" rebind_localhost 0
+               [ $rebind_localhost -gt 0 ] && {
+                       logger -t dnsmasq "Allowing 127.0.0.0/8 responses"
+                       append args "--rebind-localhost-ok"
+               }
+
+               append_rebind_domain() {
+                       logger -t dnsmasq "Allowing RFC1918 responses for domain $1"
+                       append args "--rebind-domain-ok=$1"
+               }
+
+               config_list_foreach "$cfg" rebind_domain append_rebind_domain
+       }
 }
 
 dhcp_subscrid_add() {
@@ -296,12 +319,37 @@ dhcp_domain_add() {
        local raddr="${4:+$4.$3.$2.$1.in-addr.arpa}"
 
        for name in $names; do
-               append args "-A /$name${DOMAIN:+.$DOMAIN}/$ip"
-               [ -n "$raddr" ] && \
-                       append args "--ptr-record=$raddr,$name${DOMAIN:+.$DOMAIN}"
+               local fqdn="$name"
+
+               [ "${fqdn%.*}" == "$fqdn" ] && \
+                       fqdn="$fqdn${DOMAIN:+.$DOMAIN}"
+
+               append args "-A /$fqdn/$ip"
+               
+               [ -n "$raddr" ] && {
+                       append args "--ptr-record=$raddr,$fqdn"
+                       raddr=""
+               }
        done
 }
 
+dhcp_srv_add() {
+       local cfg="$1"
+
+       config_get srv "$cfg" srv
+       [ -n "$srv" ] || return 0
+
+       config_get target "$cfg" target
+       [ -n "$target" ] || return 0
+
+       config_get port "$cfg" port
+
+       local service="$srv,$target"
+       [ -n "$port" ] && service="$service,$port"
+
+       append args "-W $service"
+}
+
 start() {
        include /lib/network
        scan_interfaces
@@ -318,6 +366,7 @@ start() {
        config_foreach dhcp_remoteid_add remoteid
        config_foreach dhcp_subscrid_add subscrid
        config_foreach dhcp_domain_add domain
+       config_foreach dhcp_srv_add srvhost
        config_foreach dhcp_add dhcp
 
        /usr/sbin/dnsmasq $args && {
This page took 0.023843 seconds and 4 git commands to generate.