पाठ 14 / 25
Network Egress Allowlists
बाहर जाने वाला traffic सिर्फ़ उन hosts तक allow करें जिनकी काम को ज़रूरत है और metadata endpoints रोकें।
डेटा कहाँ जा सकता है, यह नियंत्रित करें
Injected निर्देश को आम तौर पर डेटा बाहर भेजना (हमलावर के server को) या कोड भीतर लाना होता है। Agent सिर्फ़ छोटी hosts सूची, जैसे आपका package registry और Git host, तक पहुँच सके तो दोनों कठिन हो जाते हैं। सटीक hostname मिलाएँ (substring नहीं: pypi.org.evil.com, pypi.org नहीं है), निजी और link-local पते, जैसे cloud metadata service (169.254.169.254), रोकें, और नियम को सिर्फ़ agent में नहीं बल्कि sandbox या proxy में लागू करें।
Host जाँच, चलाकर
मैंने यह चलाया। मिलता-जुलता domain और metadata IP रोके जाते हैं; सटीक allowed hosts पास होते हैं। असली deployment इसे network परत पर लागू करता है।
from urllib.parse import urlparse
ALLOW = {"pypi.org", "files.pythonhosted.org", "registry.npmjs.org", "github.com"}
def egress_ok(url):
return (urlparse(url).hostname or "") in ALLOW
for u in ("https://pypi.org/simple/x", "https://pypi.org.evil.com/x",
"http://169.254.169.254/latest/meta-data", "https://github.com/a/b"):
print(egress_ok(u), u)
Output:
True https://pypi.org/simple/x False https://pypi.org.evil.com/x False http://169.254.169.254/latest/meta-data True https://github.com/a/b
डिफ़ॉल्ट रूप से network नहीं
कई agent कामों (कोड बदलना, पहले से install tests चलाना) को network की बिल्कुल ज़रूरत नहीं। शून्य से शुरू करें, और ख़ास hosts तभी जोड़ें जब कोई काम साबित करे कि उसे चाहिए।
त्वरित जाँच: सटीक hostname क्यों मिलाएँ, "contains pypi.org" क्यों नहीं?
- कोई फ़र्क़ नहीं पड़ता
- Hostnames सिर्फ़ case-insensitive होते हैं
- Substring जाँच तेज़ है
- pypi.org.evil.com जैसे मिलते-जुलते domains पास हो जाएँगे
Answer
pypi.org.evil.com जैसे मिलते-जुलते domains पास हो जाएँगे — हमलावर भरोसेमंद नाम वाले domains पंजीकृत करते हैं, इसलिए सिर्फ़ सटीक मेल सुरक्षित है।