Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

remove ipv4, ipv6 announce URL query parameters #4501

Closed
ckerr opened this issue Dec 31, 2022 · 0 comments · Fixed by #4502
Closed

remove ipv4, ipv6 announce URL query parameters #4501

ckerr opened this issue Dec 31, 2022 · 0 comments · Fixed by #4502

Comments

@ckerr
Copy link
Member

ckerr commented Dec 31, 2022

Xref: #1661, #1659, #3461

The current revision (as of 2022-12-31) of BEP 0007 reads:

IP announce parameters

An earlier version of this BEP specified new HTTP parameters to announce an additional address of a different address family than the source IP address of the tracker connection (&ipv4= and &ipv6=). These are discouraged, as they allow an attacker to announce a victim's IP address to launch a DDoS attack.

Notes: Followed BEP7 suggestion to remove ipv4 and ipv6 query parameters from tracker announcements.

@ckerr ckerr changed the title remove ip, ipv4, ipv6 announce URL parameters remove ip, ipv4, ipv6 announce URL query parameters Dec 31, 2022
@ckerr ckerr changed the title remove ip, ipv4, ipv6 announce URL query parameters remove ipv4, ipv6 announce URL query parameters Dec 31, 2022
@ckerr ckerr added this to the 4.0.0 milestone Dec 31, 2022
@ckerr ckerr self-assigned this Dec 31, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Development

Successfully merging a pull request may close this issue.

1 participant