Repository navigation
Warn on potentially insecure inspector options (--inspect=0.0.0.0) #23444
Copy link
Copy link
Closed
Labels
docIssues and PRs related to Node.js documentation.Issues and PRs related to Node.js documentation.help wantedIssues that need assistance from volunteers or PRs that need help to proceed.Issues that need assistance from volunteers or PRs that need help to proceed.inspectorIssues and PRs related to the V8 inspector protocol.Issues and PRs related to the V8 inspector protocol.securityIssues and PRs related to security.Issues and PRs related to security.
Description
Activity
- addedsecurityIssues and PRs related to security.Issues and PRs related to security.inspectorIssues and PRs related to the V8 inspector protocol.Issues and PRs related to the V8 inspector protocol.docIssues and PRs related to Node.js documentation.Issues and PRs related to Node.js documentation.
on Oct 12, 2018 can I work on this one ?
@nik72619c Sure!
Documentation change is in #23640, the warning part is free to be taken atm.
I was thinking about:
- Making a function to determine if the specified IPv4 is either (1) loopback, (2) private, or (3) public.
- If the user specifies a host, it's resolved to an address.
- Once we have the address, pass it through the function from part 1. Loopback (1) does not need any warning, and the private (2) and public (3) addresses probably need slightly different warnings, with a link to the doc from doc: inspector security warning for changing host to a public IP #23640 (once that lands).
Loopback: 127.0.0.0 — 127.255.255.255.
Private: 10.0.0.0 – 10.255.255.255, 172.16.0.0 – 172.31.255.255, 192.168.0.0 – 192.168.255.255
Public: everything else, mostly.There are more special address blocks, but those are unlikely to be observed, so just falling back to «public» and printing a corresponding warning should be fine imo.
I can mentor that.
@nik72619c are you still working on this? If not I'm happy to take over.
- added a commit that references this issue
on Nov 6, 2018 - added a commit that references this issue
on Nov 6, 2018 - added a commit that references this issue
on Nov 29, 2018 - added 2 commits that reference this issue
on Nov 29, 2018 1 remaining item
- added a commit that references this issue
on Mar 21, 2025 - added a commit that references this issue
on Mar 23, 2025 - added 2 commits that reference this issue
on Apr 16, 2025 - added 2 commits that reference this issue
on May 1, 2025
Metadata
Metadata
Assignees
Labels
docIssues and PRs related to Node.js documentation.Issues and PRs related to Node.js documentation.help wantedIssues that need assistance from volunteers or PRs that need help to proceed.Issues that need assistance from volunteers or PRs that need help to proceed.inspectorIssues and PRs related to the V8 inspector protocol.Issues and PRs related to the V8 inspector protocol.securityIssues and PRs related to security.Issues and PRs related to security.
Extracted from #21774.
Inspector by default is bound to 127.0.0.1, but suggestion to launch it with
--inspect=0.0.0.0is highly copy-pasted without proper understanding what it does. I've observed that personally in chats, also see google.Binding inspector to 0.0.0.0 (in fact, to anything but the loopback interface ip) allows RCE, which could be catastrophic in cases where the IP is public. The users should be informed of that.
A warning printed to the console (with corresponding documentation change) should at least somewhat mitigate this.
Note: the doc change and the c++ change can come separately.