Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ignore local/lan-only hosts (and invalid domains). #184

Open
jtagcat opened this issue May 26, 2021 · 0 comments
Open

Ignore local/lan-only hosts (and invalid domains). #184

jtagcat opened this issue May 26, 2021 · 0 comments

Comments

@jtagcat
Copy link

jtagcat commented May 26, 2021

  • By default ignore all localhost, localhost-ip6, 127.0.0.1, 192.168.5.25, 10.13.37.96, etc; disable the filter with either removing them from the global ignores, or perhaps a flag --no-ignore-lan (possible attacks, data leaks)
  • Probably not by default? Get a list of valid TLDs, and ignore everything else. (knock knock, it's your ISP's DNS)

req to localhost
hmmm

time for explot-a-crawler ctf, where entity dislikes scraper scraper, but scraper go brrr; scraped content goes upload, entity goes time-for-court, and once you in american courts, you have already lost

@jtagcat jtagcat changed the title Ignore all local hosts and invalid domains. Ignore local/lan-only hosts (and invalid domains). May 26, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant