Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | Stub DNS to return IPv4 addressdeterminstic_dns_specs | Thong Kuah | 2019-07-29 | 1 | -0/+6 |
| | | | | Otherwise certain machines return IPv6 first, which is non-deterministic | ||||
* | Add DNS rebinding protection settings | Oswaldo Ferreira | 2019-05-30 | 1 | -0/+32 |
| | |||||
* | Protect Gitlab::HTTP against DNS rebinding attack | Douwe Maan | 2019-05-30 | 1 | -0/+88 |
Gitlab::HTTP now resolves the hostname only once, verifies the IP is not blocked, and then uses the same IP to perform the actual request, while passing the original hostname in the `Host` header and SSL SNI field. |