diff --git a/src/dns.rs b/src/dns.rs index 2ae1528..8aefd03 100644 --- a/src/dns.rs +++ b/src/dns.rs @@ -1,6 +1,9 @@ #![allow(dead_code)] -use std::{net::IpAddr, str::FromStr}; +use std::{ + net::{IpAddr, Ipv4Addr, SocketAddr}, + str::FromStr, +}; use trust_dns_proto::{ op::{Message, ResponseCode}, rr::{record_type::RecordType, Name, RData, Record}, @@ -90,3 +93,17 @@ pub fn parse_data_to_dns_message(data: &[u8], used_by_tcp: bool) -> Result bool { + fn is_benchmarking(addr: &Ipv4Addr) -> bool { + addr.octets()[0] == 198 && (addr.octets()[1] & 0xfe) == 18 + } + fn addr_v4_is_private(addr: &Ipv4Addr) -> bool { + is_benchmarking(addr) || addr.is_private() || addr.is_loopback() || addr.is_link_local() + } + match addr { + SocketAddr::V4(addr) => addr_v4_is_private(addr.ip()), + SocketAddr::V6(_) => false, + } +} diff --git a/src/tun2proxy.rs b/src/tun2proxy.rs index a537a3b..f4c0854 100644 --- a/src/tun2proxy.rs +++ b/src/tun2proxy.rs @@ -1,4 +1,4 @@ -use crate::{error::Error, error::Result, virtdevice::VirtualTunDevice, NetworkInterface, Options}; +use crate::{dns, error::Error, error::Result, virtdevice::VirtualTunDevice, NetworkInterface, Options}; use mio::{event::Event, net::TcpStream, net::UdpSocket, unix::SourceFd, Events, Interest, Poll, Token}; use smoltcp::{ iface::{Config, Interface, SocketHandle, SocketSet}, @@ -468,7 +468,15 @@ impl<'a> TunToProxy<'a> { let (info, _first_packet, payload_offset, payload_size) = result?; let origin_dst = SocketAddr::try_from(&info.dst)?; let connection_info = match &mut self.options.virtual_dns { - None => info, + None => { + let mut info = info; + let port = origin_dst.port(); + if port == 53 && info.protocol == IpProtocol::Udp && dns::addr_is_private(&origin_dst) { + let dns_addr: SocketAddr = "8.8.8.8:53".parse()?; // TODO: Configurable + info.dst = Address::from(dns_addr); + } + info + } Some(virtual_dns) => { let dst_ip = origin_dst.ip(); virtual_dns.touch_ip(&dst_ip); @@ -798,7 +806,7 @@ impl<'a> TunToProxy<'a> { Ok(read_result) => read_result, Err(error) => { if error.kind() != std::io::ErrorKind::WouldBlock { - log::error!("Read from proxy: {}", error); + log::error!("{} Read from proxy: {}", conn_info.dst, error); } vecbuf.len() }