diff options
| author | srdusr <[email protected]> | 2026-05-27 01:04:00 +0200 |
|---|---|---|
| committer | srdusr <[email protected]> | 2026-05-27 01:04:00 +0200 |
| commit | 0122045b492f2bd41a74769b8e6a9cefc73f988b (patch) | |
| tree | 031f1f91a19694ae520507e8cef56d38a4806f1e /fuzz/fuzz_ipv4.cpp | |
| parent | c098f1742bb04fbe41fc6cf492cd334efef734eb (diff) | |
| download | packeteer-0122045b492f2bd41a74769b8e6a9cefc73f988b.tar.gz packeteer-0122045b492f2bd41a74769b8e6a9cefc73f988b.zip | |
Decode DNS answer records (A/AAAA/CNAME) - resolved addresses, not just ancount
Probably the single most-wanted thing a packet analyzer shows that
this one didn't yet: responses showed ancount=N but never what a
query actually resolved to. A, AAAA, and CNAME rdata now render into
readable text; every other type is still walked correctly
(name/type/ttl/rdlength read and bounds-checked) but not rendered.
Needed a second name reader alongside the existing question-only
read_dns_name(): real answer records almost always compress their
NAME field as a 2-byte pointer back to the question, which the
original reader deliberately rejects. read_dns_name_following_pointers()
actually follows them, bounded by a maximum jump count rather than a
backward-only check - a cycle across pointers pointing at each other
would still loop forever under "must point backward", but can't
survive a hard cap on jumps followed.
Fuzzed the new pointer-chasing logic specifically before trusting it
(fuzz_dns, fuzz_summarize, ~5.1M combined runs) - exactly the kind of
attacker-influenced-offset code this project's fuzzing exists for.
Clean, no crashes or timeouts.
Live-verified extensively on wlp1s0: a direct query to 8.8.8.8 for
example.com resolved two real A records; a query for www.github.com
showed a real CNAME chain; and organic background DNS traffic from
this machine's own browser sessions showed AAAA records (including an
8-address response, all correctly listed) and DNS RR type 65 (HTTPS
records) correctly producing no answers suffix.
Diffstat (limited to 'fuzz/fuzz_ipv4.cpp')
0 files changed, 0 insertions, 0 deletions