Skip to content
This repository has been archived by the owner on Mar 1, 2024. It is now read-only.

Security updates for default turn server configuration. #196

Merged
merged 6 commits into from
Apr 13, 2023

Conversation

gingernaz
Copy link
Contributor

@gingernaz gingernaz commented Apr 13, 2023

Relevant components:

  • Signalling server
  • Frontend library
  • Frontend UI library
  • Matchmaker
  • Platform scripts
  • SFU

Problem statement:

The default turn server configuration has a serious security vulnerability allowing internal network traversal from an external entity.

Solution

This change introduces a set of configuration options in a config file that will close off traversal to certain subnets.

Documentation

NA

Test Plan and Compatibility

Running the existing with-turn or turn scripts on windows/linux/docker should now mention that it loaded a config file and dump out a list of the blocked subnets and whitelist local TURN ip.

Copy link
Contributor

@lukehb lukehb left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@lukehb lukehb merged commit aa1b0fa into EpicGames:master Apr 13, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants