Quellcode durchsuchen

changelog and spec changes for the .exit fix

Roger Dingledine vor 14 Jahren
Ursprung
Commit
b7e8a4631f
2 geänderte Dateien mit 10 neuen und 1 gelöschten Zeilen
  1. 6 0
      ChangeLog
  2. 4 1
      doc/spec/address-spec.txt

+ 6 - 0
ChangeLog

@@ -1,4 +1,10 @@
 Changes in version 0.2.2.1-alpha - 2009-08-26
+  o Security fixes:
+    - Start the process of disabling ".exit" address notation, since it
+      can be used for a variety of esoteric application-level attacks
+      on users. To reenable it, set "AllowDotExit 1" in your torrc. Fix
+      on 0.0.9rc5.
+
   o New directory authorities:
     - Set up urras (run by Jacob Appelbaum) as the seventh v3 directory
       authority.

+ 4 - 1
doc/spec/address-spec.txt

@@ -33,10 +33,13 @@
   "www.google.com.foo.exit=64.233.161.99.foo.exit" to speed subsequent
   lookups.
 
+  The .exit notation is disabled by default as of Tor 0.2.2.1-alpha, due
+  to potential application-level attacks.
+
   EXAMPLES:
      www.example.com.exampletornode.exit
 
-        Connect to www.example.com from the node called "exampletornode."
+        Connect to www.example.com from the node called "exampletornode".
 
      exampletornode.exit