Gnutella Forums  

Go Back   Gnutella Forums > Current Gnutella Client Forums > Phex (Cross-platform) > General Discussion
Register FAQ The Twelve Commandments Members List Calendar Arcade Find the Best VPN Today's Posts

General Discussion For anything which doesn't fit somewhere else (for PHEX users)


Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old March 5th, 2006
Novicius
 
Join Date: March 5th, 2006
Posts: 4
f00bar is flying high
Default phex security rules not working?

I've been trying to configure phex to communicate only with a certain list of IP addresses. That is, I'm trying to get phex to only work with a whitelist of IPs.

I tried the following security rules:

DENY network mask 0.0.0.0/255.255.255.255
ALLOW network range x.x.0.0-x.x.255.255

However, after applying these rules, I'm still able to connect to servers outside the allowed IP range, and I'm also to download from hosts outside of the range.

Could someone please tell me what I'm doing wrong?

Thanks.
Reply With Quote
  #2 (permalink)  
Old March 6th, 2006
Novicius
 
Join Date: March 5th, 2006
Posts: 4
f00bar is flying high
Default

I've also tried setting the blocked range to 0.0.0.0-255.255.255.255 and my client still connects to anything.
Reply With Quote
  #3 (permalink)  
Old March 6th, 2006
Phex Developer
 
Join Date: May 8th, 2001
Location: Stuttgart, Germany
Posts: 988
GregorK is flying high
Default

I will check this...

it might be that the rules are only checked when collecting IPs... meaning when they first enter Phex from any network source.
...but already collected and cached IPs might not be checked again before a connection attempt is made...
__________________
Reply With Quote
  #4 (permalink)  
Old March 6th, 2006
Novicius
 
Join Date: March 5th, 2006
Posts: 4
f00bar is flying high
Default

Quote:
Originally posted by GregorK
I will check this...

it might be that the rules are only checked when collecting IPs... meaning when they first enter Phex from any network source.
...but already collected and cached IPs might not be checked again before a connection attempt is made...
I just built the latest version from CVS to test this issue. I deleted all the files in my phex configuration directory (~/.phex) and and created a new security.xml with a rule as follows:

Code:
        <ip-access-rule>
            <description>Deny all.</description>
            <isDenyingRule>true</isDenyingRule>
            <isDisabled>false</isDisabled>
            <triggerCount>0</triggerCount>
            <expiryDate>9223372036854775807</expiryDate>
            <isDeletedOnExpiry>false</isDeletedOnExpiry>
            <addressType>3</addressType>
            <ip>00000000</ip>
            <compareIP>FFFFFFFF</compareIP>
        </ip-access-rule>
Starting phex results in no connections. However, if I activate Ultrapeer mode, the security rule is bypassed and all connections are allowed.
Reply With Quote
  #5 (permalink)  
Old March 6th, 2006
Novicius
 
Join Date: March 5th, 2006
Posts: 4
f00bar is flying high
Default

I spoke too soon. Even after clearing the host cache, it appears that some hosts are able to connect.
Reply With Quote
  #6 (permalink)  
Old March 6th, 2006
Phex Developer
 
Join Date: May 8th, 2001
Location: Stuttgart, Germany
Posts: 988
GregorK is flying high
Default

It looks like the host creep in through the UDP host cache code. It is fairly new and I not yet had a chance to review it deeply.

I filed this bug report in case you like to monitor it.
http://sourceforge.net/tracker/index...21&atid=388892

I do my best to have it fixed for the next release.

Thanks for this nice observation, testing and reporting.

Gregor
__________________
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Outpost Firewall - Phex Rules? moloch88 Help & Support 3 December 31st, 2006 10:36 AM
Phex security e@t@r00t General Discussion 0 July 10th, 2005 01:13 AM
Security Rules? rjpear General Discussion 12 February 20th, 2005 01:23 PM
Send your ideas for a new Phex Security Concept GregorK General Discussion 0 November 21st, 2002 01:52 AM
phex not working well ken481 General Discussion 0 March 30th, 2002 05:23 AM


All times are GMT -7. The time now is 01:04 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 ©2011, Crawlability, Inc.

Copyright © 2020 Gnutella Forums.
All Rights Reserved.