v1.7.0 - DNS Rebind Protection
🛡️ DNS Rebinding Protection
phantomd can now protect against DNS rebinding attacks by filtering private and special-use IP addresses from upstream responses. This prevents malicious domains from accessing internal network resources—a critical security feature for network‑level DNS filters.
✨ Added
- DNS rebinding protection – new
[security]configuration options:
dns_rebind_protectionanddns_rebind_action(striporblock).
When enabled, phantomd removes private IPs (192.168.x.x, 10.x.x.x, etc.) from DNS answers before returning them to clients.
Default: disabled (dns_rebind_protection = false). - New tests – 11 tests cover
_is_private_ip,_apply_rebind_protectionin both modes, disabled behaviour, and end‑to‑end forwarding with rebinding enabled. Total test suite: 104 tests.
🛠️ Changed
- Configuration template (
config/phantomd.conf) updated with commented‑out examples for the new rebinding‑protection settings.
📦 Upgrading
- Update:
./installer.sh --updatethensystemctl restart phantomd - Fresh install:
./installer.sh
Full Changelog: v1.6.0...v1.7.0