https://bz.apache.org/bugzilla/show_bug.cgi?id=70263

            Bug ID: 70263
           Summary: mod_remoteip clears remote_host and triggers
                    unbracketed IPv6 forward DNS lookups (appending search
                    domain)
           Product: Apache httpd-2
           Version: 2.4-HEAD
          Hardware: PC
                OS: FreeBSD
            Status: NEW
          Severity: normal
          Priority: P2
         Component: mod_remoteip
          Assignee: [email protected]
          Reporter: [email protected]
  Target Milestone: ---

ENVIRONMENT:
- OS: FreeBSD (13/14)
- Web Server: Apache 2.4.x
- Active Modules: mod_remoteip, mod_log_config

OVERVIEW:
When mod_remoteip overrides the client IP structure (c->client_ip) with an
external IPv6 address pulled from an upstream proxy header (e.g.,
X-Forwarded-For), it resets the c->remote_host and c->remote_logname variables
to NULL. 

However, mod_remoteip updates the internal structure with the raw client IPv6
address WITHOUT appending standard network formatting brackets ("[...]"). 

When downstream components (such as mod_log_config processing %a, or access
control evaluations) subsequently encounter the NULL hostname and attempt a
fallback lookup, the unbracketed IPv6 string is passed directly to the
operating system's text-based system resolver (getaddrinfo). 

On FreeBSD, getaddrinfo fails to recognize the unbracketed IPv6 colon-delimited
string as a numeric address. It mistakenly treats it as an unqualified local
hostname and appends the network's search domain (from /etc/resolv.conf),
resulting in rogue outbound DNS queries on every incoming client request (e.g.,
"2001:db8:1234:5687::abcd.your-search-domain.com").

STEPS TO REPRODUCE:
1. Configure a FreeBSD Apache 2.4 server with an active search domain in
/etc/resolv.conf.
2. Enable mod_remoteip and trust an upstream proxy subnet via
RemoteIPInternalProxy.
3. Configure a LogFormat string using %a, or use basic IP evaluation
constraints.
4. Send an incoming IPv6 request through the trusted proxy containing an
X-Forwarded-For header.
5. Monitor network traffic or DNS logs; a forward "A" record query for
"[IPv6].[search-domain]" will fire on every request.

ACTUAL RESULTS:
The OS resolver is flooded with malformed text-string DNS queries attempting to
resolve the raw client IPv6 concatenated with the local network search suffix.

EXPECTED RESULTS:
mod_remoteip should ensure that when client structures are updated with IPv6
strings, they are sanitized or encapsulated cleanly so that downstream internal
or system hooks strictly handle them via AI_NUMERICHOST, or the structures
retain proper bracket isolation to prevent the system resolver from treating
them as text hostnames.

WORKAROUND USED:
Disabled mod_remoteip entirely and switched to manual text-logging using
%{X-Forwarded-For}i to keep the address variable out of the socket/connection
memory pools.

NOTE: I wouldn't have noticed it, however, my recursive DNS had lagging issues
and my websites slowed down drastically, but only when accessed via IPv6. IPv4
was fine, since there is no DNS query from mod_remoteip for IPv4 addresses
passed through.

-- 
You are receiving this mail because:
You are the assignee for the bug.
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to