[prev in list] [next in list] [prev in thread] [next in thread] 

List:       dante-misc
Subject:    Re: [dante-misc] Understanding socks
From:       Michael Shuldman <michaels () inet ! no>
Date:       2016-01-29 16:19:26
Message-ID: 20160129161926.GA8133 () jensen ! inet ! no
[Download RAW message or body]

Leandro Garrido wrote,
> <p dir="ltr"><br>
> Hi Folks<br>
> I&#180;m trying to understant how does socks works regarding DNS reverse<br>
> resoluction. I have a dante socks proxy running over a linux server.In<br>
> the socks policy I define rules that permit conexions by matching<br>
> domain names.<br>
> Last week I found out an strange behaviour. I was trying to connect to a remote ftp \
> server pointing to its public IP address. This remote<br> server has not enabled \
> reverse dns resolution, so is not possible to<br> optain its domain-name from the \
> ip. The rare thing is that the socks<br> proxy permited the connexion even in the \
> policy was only permited the<br> domain name<br>
> Does anyone&#160; guess how can be this possible?</p>
> <p dir="ltr">Thanks<br>
> Leandro Garrido&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#1 \
> 60;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; \
> <br> </p>

Hi.  Please don't send html email, but send normal text instead. 

We have tried to reproduce this, but are unable to do thus so far.

Can you please start Dante with the "-d1" option and send us the
resulting sockd.log-file?  If there's private information there,
you can send it to the dante-bugs @ inet.no address instead.

With kind regards,




-- 
  _ // 
  \X/ -- Michael Shuldman 


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic