All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Ming-Ching Tiew" <mingching.tiew@redtone.com>
To: <netfilter-devel@vger.kernel.org>, <tproxy@lists.balabit.hu>
Subject: Tproxy4, fwmark and netfilter route_me_harder
Date: Thu, 17 Jan 2008 10:28:18 +0800	[thread overview]
Message-ID: <007001c858b0$9f570db0$8119fea9@MingChing> (raw)
In-Reply-To: 478F724F.8010900@redtone.com


KOVACS Krisztian wrote:
> Hi,
>
> On szo, jan 12, 2008 at 11:47:44 +0800, Ming-Ching Tiew wrote:
>   
>> 2 ) IP FREEBIND packets spoofed with foreign source address will not 
>> leave the system when there is a FWMARK in the mangle table OUTPUT 
>> chain. This patch is created by me based on the information given by 
>> Kovacs, code quality is highly questionable as I barely understood 
>> what's it is all about, but it seems to work.
>>
>> --- linux-2.6.22-org/net/ipv4/netfilter.c       2007-12-13 
>> 20:55:45.000000000 +0800
>> +++ linux-2.6.22-new/net/ipv4/netfilter.c       2007-12-13 
>> 20:55:03.000000000 +0800
>> @@ -24,7 +24,7 @@
>>         /* some non-standard hacks like ipt_REJECT.c:send_reset() can cause
>>          * packets with foreign saddr to appear on the NF_IP_LOCAL_OUT hook.
>>          */
>> -       if (addr_type == RTN_LOCAL) {
>> +//     if (addr_type == RTN_LOCAL) {
>>                 fl.nl_u.ip4_u.daddr = iph->daddr;
>>                 if (type == RTN_LOCAL)
>>                         fl.nl_u.ip4_u.saddr = iph->saddr;
>> @@ -37,10 +37,10 @@
>>                 /* Drop old route. */
>>                 dst_release((*pskb)->dst);
>>                 (*pskb)->dst = &rt->u.dst;
>> -       } else {
>> +//     } else {
>>                 /* non-local src, find valid iif to satisfy
>>                  * rp-filter when calling ip_route_input. */
>> -               fl.nl_u.ip4_u.daddr = iph->saddr;
>> +/*             fl.nl_u.ip4_u.daddr = iph->saddr;
>>                 if (ip_route_output_key(&rt, &fl) != 0)
>>                         return -1;
>>
>> @@ -53,7 +53,7 @@
>>                 dst_release(&rt->u.dst);
>>                 dst_release(odst);
>>         }
>> -
>> +*/
>>         if ((*pskb)->dst->error)
>>                 return -1;
>>     
>
> We should probably first ask on netfilter-devel@ why this whole route
> lookup thing is necessary...
>
>    

I  sort of just forward this to netfilter-devel.
 
For those who in netfilter-devel but not in tproxy mail list, a little 
background here :-
 
I discovered after applying the tproxy4 patch which allows one to spoof 
originating traffic with a foreign IP address ( for the purpose of doing 
transparent proxy ) that after doing it, traffics with foreign IP will 
not leave the system if there is a FWMARK in the mangle table OUTPUT 
chain. Any MARK will screw up the routing.
 
And the patch above seems to be able to get the packets out of the machine
again.

So the motivation here perhaps someone here could throw some light as to 
how this situation is best handled.
 
Regards.


       reply	other threads:[~2008-01-17  2:41 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <2eda2a0a0801101228h230e9d56pd850df9e86a03546@mail.gmail.com>
     [not found] ` <47878108.50108@redtone.com>
     [not found]   ` <2eda2a0a0801101928l650804aclbdfd101779f45295@mail.gmail.com>
     [not found]     ` <007901c85403$6f690dd0$8119fea9@MingChing>
     [not found]       ` <47873A67.2010406@balabit.hu>
     [not found]         ` <47878F45.4040201@redtone.com>
     [not found]           ` <47879DC5.3050605@balabit.hu>
     [not found]             ` <47883860.8040303@redtone.com>
     [not found]               ` <20080115114237.GA7265@sch.bme.hu>
     [not found]                 ` <478F724F.8010900@redtone.com>
2008-01-17  2:28                   ` Ming-Ching Tiew [this message]
2008-01-20 15:31                     ` Tproxy4, fwmark and netfilter route_me_harder Patrick McHardy

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to='007001c858b0$9f570db0$8119fea9@MingChing' \
    --to=mingching.tiew@redtone.com \
    --cc=netfilter-devel@vger.kernel.org \
    --cc=tproxy@lists.balabit.hu \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.