[tor-bugs] #10839 [Firefox Patch Issues]: Block 127.0.0.0/8, RFC1918, and others ranges (for Non-Tor SOCKS proxies) (was: Revert #10419 and fix it by another way)

Tor Bug Tracker & Wiki blackhole at torproject.org
Tue Feb 11 02:21:33 UTC 2014


#10839: Block 127.0.0.0/8, RFC1918, and others ranges (for Non-Tor SOCKS proxies)
--------------------------------------+-----------------------
     Reporter:  cypherpunks           |      Owner:  mikeperry
         Type:  defect                |     Status:  new
     Priority:  normal                |  Milestone:
    Component:  Firefox Patch Issues  |    Version:
   Resolution:                        |   Keywords:
Actual Points:                        |  Parent ID:
       Points:                        |
--------------------------------------+-----------------------
Changes (by mikeperry):

 * keywords:  tbb-fingerprinting, tbb-pref, MikePerry201401R =>
 * priority:  blocker => normal


Old description:

> #10419 is not fixed, fix for #10419 creates security hole.

New description:

 The fix for #10419 was Tor specific. We rely on Tor blocking localhost,
 RFC1918, and other non-routable addresses to prevent these requests from
 going anywhere.

 This creates problems for people who want to use Tor Browser with non-Tor
 SOCKS proxies. The browser will now try to proxy localhost, and it will
 still continue to proxy RFC1918 addresses, as it did before.

 This is not a development priority for us, but we will accept a patch that
 prevents localhsot, RFC1918, and other internal address space from being
 proxied in the first place.

--

Comment:

 I agree this is an issue, but it is not a high development priority for
 us.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/10839#comment:7>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list