View Issue Details

IDProjectCategoryView StatusLast Update
0001722unrealircdpublic2004-04-10 18:00
Reporteradeep83 Assigned To 
PrioritynormalSeverityminorReproducibilityalways
Status closedResolutionopen 
Product Version3.2-RC2 
Summary0001722: incorrect working with resolving
DescriptionMy domain ends with digit, for example:
host.domain2
in file s_user.c line 833-834
if block rewrites hostname with its ip address.
Steps To Reproduce1. change user domain to domain with digit at the end (userhost.domain3)
2. reconnect to server
3. do /whois user
Additional InformationNeed to rewrite check for incorrect dns reply
3rd party modules

Activities

codemastr

2004-04-10 12:06

reporter   ~0005808

Well a domain can not end with a number. There are no TLDs that end in a number. It's .com, not .com2

If that's not what you mean, then you'll need to be more specific.

adeep83

2004-04-10 12:17

reporter   ~0005809

Yes, there are no public domains with numbers at the end.
But I use unreald in local network and have domains such .lan0, .lan1 and other

codemastr

2004-04-10 12:59

reporter   ~0005811

Well, your lan domains are illegal. I mean if you wanted to include a _ in them, should Unreal be modified to allow that too? What about a Ç? Should it be modified to allow that? Unreal makes a request for an "internet domain name" the domain name you are returning to it is not an internet domain name, therefore it is illegal.

adeep83

2004-04-10 15:13

reporter   ~0005812

Internet domain can include numbers in it.
I mean that you should use more powerfull checking for ip-like dns reply.
In any case I can provide my solution.

codemastr

2004-04-10 15:16

reporter   ~0005813

Indeed it can, however, the last portion (the TLD) can not.

adeep83

2004-04-10 15:41

reporter   ~0005815

RFC 1101 - DNS encoding of network names and other types
"The current syntax for network names, as defined by [RFC 952] is an
   alphanumeric string of up to 24 characters, which begins with an
   alpha, and may include "." and "-" except as first and last
   characters."
RFC 952
A "name" (Net, Host, Gateway, or Domain name) is a text string up
   to 24 characters drawn from the alphabet (A-Z), digits (0-9), minus
   sign (-), and period (.).
<skip>
   The first character must be an alpha character. The last character must not be a minus sign or period. "

Nothing about that the last char can't contain number.

syzop

2004-04-10 15:58

administrator   ~0005816

Last edited: 2004-04-10 16:06

Well I don't intend to change this. Sounds like if it was up to you a host would even be allowed to be named '192.168.1.15' (eg: look exactly like an ip).

Well. yes, you could scan the whole domainname and analyze it and whatnot... anyway this sounds so sad/stupid, I at least am not going to do this :P.

edited on: 2004-04-10 16:06

adeep83

2004-04-10 16:14

reporter   ~0005818

"The first character must be an alpha character."
No, leading digits are not allowed. Thats mean name 192.168.1.15 is not alowed because it has '1' as first char.

codemastr

2004-04-10 16:15

reporter   ~0005819

RFC952 is a ~20 year old document. And if you read it, it is horribly out of date. 24 characters? Current is 63 + 1 + TLD length. Also says only capital letters are allowed in domains. Lastly, the DDN only maintains the MIL TLD, it has no authority over anything else.

RFC1101 is a ~15 year old document. And yet again it talks about 24 character length, completely outdated.

Furthermore, ICANN has clarified that the "label" referred to in those documents refers only to the domain name, not the TLD. I've yet to find anything that says numbers are allowed.

Furthermore, the de facto standard is that they do not.

adeep83

2004-04-10 17:50

reporter   ~0005820

Ok, this is senseless discussion.
I can provide more correct function for check dns replies, or You can do it yourself.
This is my offer.

syzop

2004-04-10 17:59

administrator   ~0005821

[late]Well, as on leading digits disallowed... 'http://3com.com' works fine here (w2k->Linux bind 9.*). Fun, isn't it?[/late]

Your offer has been rejected for security reasons and simply because I don't feel comfortable with doing that, not to mention that this thing only affects very few LANs with such "domainnames".

adeep83

2004-04-10 18:00

reporter   ~0005822

>Well. yes, you could scan the whole domainname and analyze it and whatnot...
>anyway this sounds so sad/stupid, I at least am not going to do this :P.

This is simple, You can check for first char only :)

For example (i changed line 835 in file src/s_user.c):
# diff s_user.c s_user_new.c
835c835
< || isdigit(*(tmpstr - 1)))
---
> || (isdigit(*(tmpstr - 1))&&isaplha(*(sptr->sockhost)))

Issue History

Date Modified Username Field Change
2004-04-10 09:57 adeep83 New Issue
2004-04-10 12:06 codemastr Note Added: 0005808
2004-04-10 12:17 adeep83 Note Added: 0005809
2004-04-10 12:59 codemastr Note Added: 0005811
2004-04-10 15:13 adeep83 Note Added: 0005812
2004-04-10 15:16 codemastr Note Added: 0005813
2004-04-10 15:41 adeep83 Note Added: 0005815
2004-04-10 15:58 syzop Note Added: 0005816
2004-04-10 16:06 syzop Note Edited: 0005816
2004-04-10 16:14 adeep83 Note Added: 0005818
2004-04-10 16:15 codemastr Note Added: 0005819
2004-04-10 17:50 adeep83 Note Added: 0005820
2004-04-10 17:59 syzop Status new => closed
2004-04-10 17:59 syzop Note Added: 0005821
2004-04-10 18:00 adeep83 Note Added: 0005822