p2p: add low port check in dialer

We already have a check like this for UDP ports, add a similar one in
the dialer. This prevents dials to port zero and it's also an extra
layer of protection against spamming HTTP servers.
This commit is contained in:
Felix Lange 2020-04-30 12:24:04 +02:00
parent 2337aa64eb
commit 6204fc33f0

View file

@ -78,6 +78,7 @@ var (
errAlreadyConnected = errors.New("already connected") errAlreadyConnected = errors.New("already connected")
errRecentlyDialed = errors.New("recently dialed") errRecentlyDialed = errors.New("recently dialed")
errNotWhitelisted = errors.New("not contained in netrestrict whitelist") errNotWhitelisted = errors.New("not contained in netrestrict whitelist")
errLowPort = errors.New("TCP port too low")
) )
// dialer creates outbound connections and submits them into Server. // dialer creates outbound connections and submits them into Server.
@ -388,6 +389,9 @@ func (d *dialScheduler) checkDial(n *enode.Node) error {
if n.ID() == d.self { if n.ID() == d.self {
return errSelf return errSelf
} }
if n.IP() != nil && n.TCP() < 1024 {
return errLowPort
}
if _, ok := d.dialing[n.ID()]; ok { if _, ok := d.dialing[n.ID()]; ok {
return errAlreadyDialing return errAlreadyDialing
} }
@ -474,15 +478,13 @@ type dialError struct {
} }
func (t *dialTask) run(d *dialScheduler) { func (t *dialTask) run(d *dialScheduler) {
if t.dest.Incomplete() { if t.needResolve() && !t.resolve(d) {
if !t.resolve(d) {
return return
} }
}
err := t.dial(d, t.dest) err := t.dial(d, t.dest)
if err != nil { if err != nil {
// Try resolving the ID of static nodes if dialing failed. // For static nodes, resolve one more time if dialing fails.
if _, ok := err.(*dialError); ok && t.flags&staticDialedConn != 0 { if _, ok := err.(*dialError); ok && t.flags&staticDialedConn != 0 {
if t.resolve(d) { if t.resolve(d) {
t.dial(d, t.dest) t.dial(d, t.dest)
@ -491,6 +493,10 @@ func (t *dialTask) run(d *dialScheduler) {
} }
} }
func (t *dialTask) needResolve() bool {
return t.flags&staticDialedConn != 0 && t.dest.IP() == nil
}
// resolve attempts to find the current endpoint for the destination // resolve attempts to find the current endpoint for the destination
// using discovery. // using discovery.
// //