पाठ 14 / 25

Network Egress Allowlists

बाहर जाने वाला traffic सिर्फ़ उन hosts तक allow करें जिनकी काम को ज़रूरत है और metadata endpoints रोकें।

डेटा कहाँ जा सकता है, यह नियंत्रित करें

Injected निर्देश को आम तौर पर डेटा बाहर भेजना (हमलावर के server को) या कोड भीतर लाना होता है। Agent सिर्फ़ छोटी hosts सूची, जैसे आपका package registry और Git host, तक पहुँच सके तो दोनों कठिन हो जाते हैं। सटीक hostname मिलाएँ (substring नहीं: pypi.org.evil.com, pypi.org नहीं है), निजी और link-local पते, जैसे cloud metadata service (169.254.169.254), रोकें, और नियम को सिर्फ़ agent में नहीं बल्कि sandbox या proxy में लागू करें।

Host जाँच, चलाकर

मैंने यह चलाया। मिलता-जुलता domain और metadata IP रोके जाते हैं; सटीक allowed hosts पास होते हैं। असली deployment इसे network परत पर लागू करता है।

from urllib.parse import urlparse
ALLOW = {"pypi.org", "files.pythonhosted.org", "registry.npmjs.org", "github.com"}

def egress_ok(url):
    return (urlparse(url).hostname or "") in ALLOW

for u in ("https://pypi.org/simple/x", "https://pypi.org.evil.com/x",
          "http://169.254.169.254/latest/meta-data", "https://github.com/a/b"):
    print(egress_ok(u), u)

Output:

True https://pypi.org/simple/x
False https://pypi.org.evil.com/x
False http://169.254.169.254/latest/meta-data
True https://github.com/a/b

डिफ़ॉल्ट रूप से network नहीं

कई agent कामों (कोड बदलना, पहले से install tests चलाना) को network की बिल्कुल ज़रूरत नहीं। शून्य से शुरू करें, और ख़ास hosts तभी जोड़ें जब कोई काम साबित करे कि उसे चाहिए।

त्वरित जाँच: सटीक hostname क्यों मिलाएँ, "contains pypi.org" क्यों नहीं?

  • कोई फ़र्क़ नहीं पड़ता
  • Hostnames सिर्फ़ case-insensitive होते हैं
  • Substring जाँच तेज़ है
  • pypi.org.evil.com जैसे मिलते-जुलते domains पास हो जाएँगे
Answer

pypi.org.evil.com जैसे मिलते-जुलते domains पास हो जाएँगे — हमलावर भरोसेमंद नाम वाले domains पंजीकृत करते हैं, इसलिए सिर्फ़ सटीक मेल सुरक्षित है।