Re: [IPv6] [Last-Call] Artart last call review of draft-ietf-6man-rfc6874bis-02

David Farmer <[email protected]>
Newsgroups gmane.ietf.apps-discuss,gmane.ietf.ipv6
Message-ID <CAN-Dau1-sfBTXew1u=qGuWrO3FGBPTNDXk=ByTx324Xy_XyDig@mail.gmail.com>
On Mon, Mar 27, 2023 at 15:10 Brian E Carpenter <[email protected]>
wrote:

> Roy,
> On 28-Mar-23 07:26, Roy T. Fielding wrote:
> > On Mar 26, 2023, at 7:33 PM, Brian E Carpenter <
> [email protected]> wrote:
> >> On 27-Mar-23 14:37, Rob Sayre wrote:
> >>> On Sun, Mar 26, 2023 at 6:31 PM Brian E Carpenter <
> [email protected] <mailto:[email protected]>> wrote:
> >>>     I 100% fail to understand what you mean.
> >>>     http://[fe80::abcd-eth0] won't parse today any better than http://[fe80::abcd%eth0].
> Neither of them respects the current grammar. Whatever we do here extends
> the grammar.
> >
> > The difference is that % is only allowed within a pct-encoding and that
> > is heavily enforced at all layers, including those that don't parse the
> URI,
> > because it can be used for vulnerability probing/exploitation.
>
> Let me see if I can paraphrase that. It seems that you are saying that
> even if the strict ABNF grammar permits a bare % all (or at least many)
> implementations will still not allow it?


So, RFC 3986, section 2.4, paragraph 3, basically says “%” can only be use
for percent-encoding, although it doesn’t use the word “only”, which would
make the statement much more unequivocal. Also, I agree the ABNF is fuzzy
about bare “%” or anything other than two hex digits following percent sign.

I'm at a loss to understand the vunerability, though. The proposal is that
> exactly one bare % is allowed but only within the [ ] pair. There is no
> requirement for percent-encoding within the [ ] pair otherwise. If
> percent-encoding was supported there, something like http://[fe80::abc%64]
> would work today. But percent-encoding is not supported there, because no
> version of the syntax says it is.


The only security discussion of percent-encodings is in section 7.3 of RFC
3986, where it clearly warns about %00 or (NUL) and the need for special
handling. So, I also would like to better understand the venerability
claims.

Thanks
-- 
===============================================
David Farmer               Email:[email protected]
Networking & Telecommunication Services
Office of Information Technology
University of Minnesota
2218 University Ave SE        Phone: 612-626-0815
Minneapolis, MN 55414-3029   Cell: 612-812-9952
===============================================

_______________________________________________
art mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/art
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.