Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Option to drop traffic from unrecognized hostnames #3620

Open
ocdtrekkie opened this issue May 19, 2022 · 0 comments
Open

Option to drop traffic from unrecognized hostnames #3620

ocdtrekkie opened this issue May 19, 2022 · 0 comments
Labels
enhancement Feature requests security Security issues or improvements

Comments

@ocdtrekkie
Copy link
Collaborator

At present, if you navigate to my home IP address with the right port and protocol but without knowing my Sandstorm hostname, the error message Sandstorm offers for unrecognized hostnames appears, and helpfully tells you the Sandstorm server's actual URL.

This is useful for troubleshooting DNS issues. However, it also lets someone port scanning know not just that I run Sandstorm but what URL it is at, which may lead to more personal or identifying information.

The only legitimate users of my Sandstorm server would approach it by hostname, so there's really no good reason, troubleshooting aside, to offer that error page to someone navigating by IP. It's really just helping port scanners at some point.

I'm wondering if it would be possible to have a configuration option to drop traffic not using a valid hostname instead of displaying the error message.

@ocdtrekkie ocdtrekkie added enhancement Feature requests security Security issues or improvements labels May 19, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement Feature requests security Security issues or improvements
Projects
None yet
Development

No branches or pull requests

1 participant