Re: [DNSOP] Status of "let localhost be localhost"?

"Peter van Dijk" <peter.van.dijk@powerdns.com> Thu, 10 August 2017 11:45 UTC

Return-Path: <peter.van.dijk@powerdns.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 61AF3132699 for <dnsop@ietfa.amsl.com>; Thu, 10 Aug 2017 04:45:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id oc9cBCPlrtzB for <dnsop@ietfa.amsl.com>; Thu, 10 Aug 2017 04:45:51 -0700 (PDT)
Received: from shannon.7bits.nl (shannon.7bits.nl [IPv6:2a01:1b0:202:40::1]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6876812741D for <dnsop@ietf.org>; Thu, 10 Aug 2017 04:45:51 -0700 (PDT)
Received: from [10.242.2.31] (095-096-086-198.static.chello.nl [95.96.86.198]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) (Authenticated sender: peter) by shannon.7bits.nl (Postfix) with ESMTPSA id 75FF31C7D5; Thu, 10 Aug 2017 13:45:48 +0200 (CEST)
From: Peter van Dijk <peter.van.dijk@powerdns.com>
To: dnsop <dnsop@ietf.org>
Date: Thu, 10 Aug 2017 13:45:47 +0200
Message-ID: <15B4EE8E-CE83-42F4-9FC5-2E6FB58C2AA9@powerdns.com>
In-Reply-To: <20170802233921.BEDA280D9BB0@rock.dv.isc.org>
References: <05e469cf-1325-89fc-4a81-661f8647e869@eff.org> <CAKXHy=ctB=LZkX9j=8-Jy0NkTAs2tAesa4gmFhfp94O5=9U4TA@mail.gmail.com> <1dbb47a4-c6e2-97d2-a1d7-ce6c65a4042a@eff.org> <20170802012345.2CE2680BCC5E@rock.dv.isc.org> <121adcc6-55c5-4f90-2797-999f3f1f1ef8@eff.org> <CAAiTEH9=RNDrUmSOs8Rg2Ea4+as9pg=j5jnU6Y=nc8A4Z1aPog@mail.gmail.com> <2ef550a8-3e55-7fa0-9e00-fdf07093b25e@eff.org> <20170802233921.BEDA280D9BB0@rock.dv.isc.org>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: quoted-printable
X-Mailer: MailMate (1.9.6r5347)
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/Dlb8tGb7GVWSP2fcab-oxZpBVq8>
Subject: Re: [DNSOP] Status of "let localhost be localhost"?
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 10 Aug 2017 11:45:53 -0000

Hello Mark,

On 3 Aug 2017, at 1:39, Mark Andrews wrote:

> Most OS's don't treat localhost specially.  It is just a entry in
> /etc/hosts and/or a zone in the local recursive server and/or
> localhost.<zone> in a zone on the search list.  The last of these
> is how localhost is actually resolved on my machine (MacOS 10.12.6)
> as the resolver doesn't treat "localhost" as special.  It's processed
> the same way as any other single label name.

localhost entries in zones are dangerous and should (MUST?) be removed. 
Having them present allows exploits like 
https://googleprojectzero.blogspot.nl/2015/06/owning-internet-printing-case-study-in.html 
to reach beyond the vulnerable software, into the context of your 
domain.

On a sidenote, my Mac does not send out queries for localhost. I’m 
unsure if this is due to /etc/hosts or due to special casing in the 
stub.

Kind regards,
-- 
Peter van Dijk
PowerDNS.COM BV - https://www.powerdns.com/