Re: IP Filtering Patch

dean blackketter <[email protected]> Wed, 19 Feb 2003 22:57:26 -0800
Newsgroups gmane.music.equipment.slimp3.dev
Message-ID <[email protected]>
--Apple-Mail-2-845053617
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=ISO-8859-1;
	format=flowed

I've checked in this patch (with some rewriting of the strings for=20
clarity.)

On my OS X machine, incoming connections from the same machine are=20
blocked unless I explicitly put in the IP address for that machine,=20
that is,  even if 127.0.0.1 is allowed, I need to add 10.0.1.204 to=20
make it work.  I'd love a fix for this.

-dean


On Wednesday, February 19, 2003, at 08:13  PM, Metzger, Michael wrote:

> Ok, sorry about that.=A0 I was working off the base release sources as I=
=20
> didn't have CVS installed previously.=A0 This is a diff direct off cvs=20
> from tonight.=A0 It seems to work nicely with the HTTP Authentication=20
> patch for a fair level of security.=A0
> =A0
> Let me know if there are any problems.
> =A0
> Thanks!
> =A0
> Mike
> =A0
> =A0
>
> -----Original Message-----
> From: dean blackketter [mailto:[email protected]]
> Sent: Wednesday, February 19, 2003 8:26 PM
> To: [email protected]
> Subject: Re: [slimp3-dev] IP Filtering Patch
>
> Hi Mike,
>
>
> It looks like the patch conflicts with the password protection patch=20
> that was just applied this morning.
>
>
> Could you update and fix and resubmit the patch?
>
>
> -dean
>
>
>
> On Wednesday, February 19, 2003, at 04:47 PM, Metzger, Michael wrote:
>
>
> Well, after=A0a bit of=A0hacking, I've added basic IP filtering options t=
o=20
> the server code.=A0 This will allow you to specify IP addresses,=20
> wildcard addresses, and ranges to connect to the HTTP and/or CLI=20
> interfaces.=A0 This check occurs immediately after connection by the=20
> client to either server.=A0 After obtaining the IP, the server will=20
> validate the IP against the ruleset (if filtering is enabled) and=20
> either allow the connection to continue or immediately kill it.
>
>
>
> Some further info taken from the field descriptions:
>
>
>
> For example:
>
> 10.1.2.2 will allow only 10.1.2.2 to connect
>
> 10.1.2.* will allow anything with an IP in the 10.1.2.x addresses.
>
> For ranges, you can do something like 10.1.2.2-50 which will allow=20
> 10.1.2.2 - 10.1.2.50 to connect.
>
> Finally, these can be combined like 10.1.2.2,172.16.1.*,192.168.1-255.*
>
> NOTE: 127.0.0.1 is always added to the list to allow the local server=20
> to connect.
>
>
>
> Thanks
>
>
>
> Mike Metzger
>
>
>
>
>
>
> <image.tiff>
>
>
>
> To unsubscribe from this group, send an email to:
>
> [email protected]
>
>
>
>
> Your use of Yahoo! Groups is subject to the Yahoo! Terms of=20
> Service.<ipfiltering.patch>
>
>
<image.tiff>
>
>
> To unsubscribe from this group, send an email to:
> [email protected]
>
>
>
> Your use of Yahoo! Groups is subject to the Yahoo! Terms of=20
> Service.<ipfilter-021903.diff>
--Apple-Mail-2-845053617
Content-Transfer-Encoding: quoted-printable
Content-Type: text/enriched;
	charset=ISO-8859-1

I've checked in this patch (with some rewriting of the strings for
clarity.)


On my OS X machine, incoming connections from the same machine are
blocked unless I explicitly put in the IP address for that machine,
that is,  even if 127.0.0.1 is allowed, I need to add 10.0.1.204 to
make it work.  I'd love a fix for this.


-dean



On Wednesday, February 19, 2003, at 08:13  PM, Metzger, Michael wrote:


=
<excerpt><fontfamily><param>Arial</param><color><param>0000,0000,FFFF</par=
am>Ok,
sorry about that.=A0 I was working off the base release sources as I
didn't have CVS installed previously.=A0 This is a diff direct off cvs
from tonight.=A0 It seems to work nicely with the HTTP Authentication
patch for a fair level of security.=A0</color></fontfamily>

=A0

<fontfamily><param>Arial</param><color><param>0000,0000,FFFF</param>Let
me know if there are any problems.</color></fontfamily>

=A0

=
<fontfamily><param>Arial</param><color><param>0000,0000,FFFF</param>Thanks=
!</color></fontfamily>

=A0

=
<fontfamily><param>Arial</param><color><param>0000,0000,FFFF</param>Mike</=
color></fontfamily>

=A0

=A0


<fontfamily><param>Tahoma</param>-----Original Message-----

<bold>From:</bold> dean blackketter [mailto:[email protected]]

<bold>Sent:</bold> Wednesday, February 19, 2003 8:26 PM

<bold>To:</bold> [email protected]

<bold>Subject:</bold> Re: [slimp3-dev] IP Filtering Patch


</fontfamily>Hi Mike,



It looks like the patch conflicts with the password protection patch
that was just applied this morning.



Could you update and fix and resubmit the patch?



-dean




On Wednesday, February 19, 2003, at 04:47 PM, Metzger, Michael wrote:



<fontfamily><param>Arial</param>Well, after=A0a bit of=A0hacking, I've
added basic IP filtering options to the server code.=A0 This will allow
you to specify IP addresses, wildcard addresses, and ranges to connect
to the HTTP and/or CLI interfaces.=A0 This check occurs immediately
after connection by the client to either server.=A0 After obtaining the
IP, the server will validate the IP against the ruleset (if filtering
is enabled) and either allow the connection to continue or immediately
kill it.</fontfamily>




<fontfamily><param>Arial</param>Some further info taken from the field
descriptions:</fontfamily>




For example:


10.1.2.2 will allow only 10.1.2.2 to connect


10.1.2.* will allow anything with an IP in the 10.1.2.x addresses.


For ranges, you can do something like 10.1.2.2-50 which will allow
10.1.2.2 - 10.1.2.50 to connect.


Finally, these can be combined like 10.1.2.2,172.16.1.*,192.168.1-255.*


NOTE: 127.0.0.1 is always added to the list to allow the local server
to connect.




<fontfamily><param>Arial</param>Thanks</fontfamily>




<fontfamily><param>Arial</param>Mike Metzger</fontfamily>







<<image.tiff>




To unsubscribe from this group, send an email to:


[email protected]





Your use of Yahoo! Groups is subject to the<underline>
<color><param>1919,1919,FFFF</param>Yahoo! Terms of
Service</color></underline>.<<ipfiltering.patch>



</excerpt><<image.tiff>

<excerpt>


To unsubscribe from this group, send an email to:

[email protected]




Your use of Yahoo! Groups is subject to the
<underline><color><param>1999,1999,FFFF</param>Yahoo! Terms of
Service</color></underline>.<<ipfilter-021903.diff></excerpt>=

--Apple-Mail-2-845053617--