Curl those funny IPv4 addresses
daniel.haxx.se
daniel.haxx.se
ping 1.1
(1.0.0.1 - cloudflare dns server) use 10.1 10.2 10.3 as IP addresses in my home network
(10.0.0.1/24)off-topic: thanks @Daniel Stenberg for curl and for rockbox back in the day when it first showed me the wonders of open-source.
Also I see rockbox is still active. Nice
Like the article mention, supporting obscure features just makes it more likely that they can be exploited for nefarious purposes. It's not worth saving typing 4-5 characters from times to times.
Before reading the article, I would have assumed for example that 127.1 would be 127.1.0.0, not 127.0.0.1.
There is a point when the only interface to that program is via text. You still have to convert the 32-bit value to text, but there's a difference between that and converting it to IPv4's dot notation. The former is simpler.
> It's not worth saving typing 4-5 characters from times to times.
I don't think the main users of the feature are people manually typing those addresses.
> Before reading the article, I would have assumed for example that 127.1 would be 127.1.0.0, not 127.0.0.1.
But then it wouldn't be a valid IP.
> But then it wouldn't be a valid IP.
127.1.0.0 is a perfectly valid IP address. The loopback range is a /8.
It hints that certificate validation fails in some cases, but that seems even more niche. What applications are using certs with IP-in-CN anyway in 2021? Shouldn't any IPs be in the "typed" SAN extension?
Commit is here: https://github.com/curl/curl/commit/56a037cc0ad1b2a770d0c08d...
I odo ccasionally use the (already-mentioned)
$ ping 1.1
$ 10.1
variants, but I use "these obscure formats" more frequently when dealing with 4-byte ASNs (cf. [0], for example).--
But, I'm also happy for having curl be more consistent with itself, so that it has the same behaviour on developer workstation and in production, since I'd imagine most pen-testing happens by developers locally.
Quite nifty I'd say.
I often wanted hexadecimal IP4 addresses because the standard format is hard to type and some octets in decimal expand to three digits. However seeing it in action and requiring the "0x…" prefix has made me less enthused:
ping 0x0a000101
ping 0x0a.0x00.0x01.0x01
Frankly that sucks, no wonder it never caught on. Something shorter with a fixed length like the below would have made me happier, though the ship sailed decades ago: ping 0a00.0101Have not seen many other programs adopt this. It's useful. Less to type.
At least IPv6 made this practice non-ambiguous by requiring a double colon (::) and mandating that at most one :: can exist in a valid address.
It doesn't just mean "fill in zeros".
I would fully expect support for these "weird" formats to be a (enabled by default) build-time option, but it's a good thing that curl maintainer is not just cutting it off right away.
When I was in middle school, I needed to research a paper in the school library computers. Their stupid computers were always messed up; first the proxy settings weren't configured in half the machines (I fixed that, and got scolded), then the anti-virus wasn't working (fixed that, got scolded). Then the proxies wouldn't let me search for my paper.
I was a budding hacker, so I figured out the numbering trick mentioned in this article, and was able to bypass the proxy and do my research for my paper. This was a long time ago but I bet the same situation is just as relevant today. (Doubtful that you'd use curl in this scenario, but nice to know they are preserving useful functionality rather than throwing it out)
The only way I can think of this possibly helping you is by changing the Host header and that somehow fooling the proxy into allowing your connection through. However some random testing with both a modern browser and a really old version of firefox I have installed shows that it seems to convert the 'weird number format' into a proper IP address, even when using a proxy. In other words, I cannot see how using these weird IPs ever could make a difference from the proxy's perspective.
But do "npm"? Is "npm" any safer?
> inb4 sudo