[hackerone] warn about possible DNS leaks when user is using a browser proxy
See original GitHub issuesee https://bravesoftware.slack.com/archives/C01K7EDB082/p1655669298310699 for details
we will need some kind of warning when the user enables the following settings, to tell them that DNS requests will not use their proxy settings:
- IPFS with the local node setting (also covered in #23570)
- ENS
- Unstoppable Domains
- Probably DNSlink
- Aggressive mode adblocking https://github.com/brave/brave-browser/issues/23812
Suggested text for IPFS: https://github.com/brave/brave-browser/issues/23552#issuecomment-1159804437
Suggested text for everything else: Warning: When you enable this setting and use a custom proxy, DNS requests may not go through the proxy.
For Aggressive mode adblocking
, this text should only show up once the user selects aggressive mode, in both the global shield settings and shields panel.
https://hackerone.com/reports/1443500 https://hackerone.com/reports/1606202
Issue Analytics
- State:
- Created a year ago
- Comments:6 (1 by maintainers)
Top Results From Across the Web
Types of Weaknesses | HackerOne Platform Documentation
This describes any attack whereby an attacker places incorrect or harmful material in cache. The targeted cache can be an application's cache (e.g....
Read more >HackerOne Employee Caught Stealing Vulnerability Reports ...
An employee of HackerOne bug bounty platform was caught improperly accessing vulnerability reports submitted by researchers for personal ...
Read more >Brave privacy bug exposes Tor onion URLs to your DNS provider ...
Brave Browser is fixing a privacy issue that leaks the Tor onion URL addresses you visit to your locally configured DNS server, exposing...
Read more >Attacking Private Networks from the Internet with DNS Rebinding
DNS rebinding allows a remote attacker to bypass a victim's network firewall and use their web browser as a proxy to communicate directly...
Read more >[CVE-2018-7600] Remote Code Execution due to outdated ...
we can see that we have a Drupal with version 7.54, which was updated the ... "medium": "https://profile-photos.hackerone-user-content.com/variants/000/016/ ...
Read more >Top Related Medium Post
No results found
Top Related StackOverflow Question
No results found
Troubleshoot Live Code
Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start FreeTop Related Reddit Thread
No results found
Top Related Hackernoon Post
No results found
Top Related Tweet
No results found
Top Related Dev.to Post
No results found
Top Related Hashnode Post
No results found
Top GitHub Comments
Unstopable domanins\ENS are using browser network stack and they don’t bypass proxy. Also checked this is net-export logs.
@rebron @diracdeltas may you also close https://github.com/brave/brave-browser/issues/21034 ?