Limit the number of IPs we use from each DNS seeder
A risk exists where a malicious DNS seeder eclipses a node by returning an enormous number of IP addresses. In this commit we mitigate this risk by limiting the number of IP addresses addrman learns to 256 per DNS seeder.
This commit is contained in:
parent
b225010a80
commit
46e7f800bd
1 changed files with 2 additions and 1 deletions
|
@ -1631,7 +1631,8 @@ void CConnman::ThreadDNSAddressSeed()
|
||||||
if (!resolveSource.SetInternal(host)) {
|
if (!resolveSource.SetInternal(host)) {
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
if (LookupHost(host.c_str(), vIPs, 0, true))
|
unsigned int nMaxIPs = 256; // Limits number of IPs learned from a DNS seed
|
||||||
|
if (LookupHost(host.c_str(), vIPs, nMaxIPs, true))
|
||||||
{
|
{
|
||||||
for (const CNetAddr& ip : vIPs)
|
for (const CNetAddr& ip : vIPs)
|
||||||
{
|
{
|
||||||
|
|
Loading…
Reference in a new issue