question-mark
Stuck on an issue?

Lightrun Answers was designed to reduce the constant googling that comes with debugging 3rd party libraries. It collects links to all the places you might be looking at while hunting down a tough bug.

And, if you’re still stuck at the end, we’re happy to hop on a call to see how we can help out.

[hackerone] warn about possible DNS leaks when user is using a browser proxy

See original GitHub issue

see https://bravesoftware.slack.com/archives/C01K7EDB082/p1655669298310699 for details

we will need some kind of warning when the user enables the following settings, to tell them that DNS requests will not use their proxy settings:

Suggested text for IPFS: https://github.com/brave/brave-browser/issues/23552#issuecomment-1159804437

Suggested text for everything else: Warning: When you enable this setting and use a custom proxy, DNS requests may not go through the proxy.

For Aggressive mode adblocking, this text should only show up once the user selects aggressive mode, in both the global shield settings and shields panel.

https://hackerone.com/reports/1443500 https://hackerone.com/reports/1606202

Issue Analytics

  • State:closed
  • Created a year ago
  • Comments:6 (1 by maintainers)

github_iconTop GitHub Comments

2reactions
cypt4commented, Jun 22, 2022

Unstopable domanins\ENS are using browser network stack and they don’t bypass proxy. Also checked this is net-export logs.

1reaction
neeythanncommented, Jul 2, 2022
Read more comments on GitHub >

github_iconTop Results From Across the Web

Types of Weaknesses | HackerOne Platform Documentation
This describes any attack whereby an attacker places incorrect or harmful material in cache. The targeted cache can be an application's cache (e.g....
Read more >
HackerOne Employee Caught Stealing Vulnerability Reports ...
An employee of HackerOne bug bounty platform was caught improperly accessing vulnerability reports submitted by researchers for personal ...
Read more >
Brave privacy bug exposes Tor onion URLs to your DNS provider ...
Brave Browser is fixing a privacy issue that leaks the Tor onion URL addresses you visit to your locally configured DNS server, exposing...
Read more >
Attacking Private Networks from the Internet with DNS Rebinding
DNS rebinding allows a remote attacker to bypass a victim's network firewall and use their web browser as a proxy to communicate directly...
Read more >
[CVE-2018-7600] Remote Code Execution due to outdated ...
we can see that we have a Drupal with version 7.54, which was updated the ... "medium": "https://profile-photos.hackerone-user-content.com/variants/000/016/ ...
Read more >

github_iconTop Related Medium Post

No results found

github_iconTop Related StackOverflow Question

No results found

github_iconTroubleshoot Live Code

Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free

github_iconTop Related Reddit Thread

No results found

github_iconTop Related Hackernoon Post

No results found

github_iconTop Related Tweet

No results found

github_iconTop Related Dev.to Post

No results found

github_iconTop Related Hashnode Post

No results found