Skip to content

v1.7.0 - DNS Rebind Protection

Choose a tag to compare

@33xception 33xception released this 25 Apr 18:37
· 16 commits to master since this release

🛡️ DNS Rebinding Protection

phantomd can now protect against DNS rebinding attacks by filtering private and special-use IP addresses from upstream responses. This prevents malicious domains from accessing internal network resources—a critical security feature for network‑level DNS filters.


✨ Added

  • DNS rebinding protection – new [security] configuration options:
    dns_rebind_protection and dns_rebind_action (strip or block).
    When enabled, phantomd removes private IPs (192.168.x.x, 10.x.x.x, etc.) from DNS answers before returning them to clients.
    Default: disabled (dns_rebind_protection = false).
  • New tests – 11 tests cover _is_private_ip, _apply_rebind_protection in both modes, disabled behaviour, and end‑to‑end forwarding with rebinding enabled. Total test suite: 104 tests.

🛠️ Changed

  • Configuration template (config/phantomd.conf) updated with commented‑out examples for the new rebinding‑protection settings.

📦 Upgrading

  • Update: ./installer.sh --update then systemctl restart phantomd
  • Fresh install: ./installer.sh

Full Changelog: v1.6.0...v1.7.0