Skip to content

Commit 505e6a6

Browse files
committed
Fix onion-grater profile for Whonix
Wahay sends an IP of 0.0.0.0 to ADD_ONION, which needs to be translated on the Whonix-Gateway to the Workstation IP. (This also reduces attack surface a bit.)
1 parent 9299ae2 commit 505e6a6

File tree

1 file changed

+4
-1
lines changed

1 file changed

+4
-1
lines changed

packaging/tails/onion-grater-profile.yml

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,10 @@
55
- 'amnesia'
66
commands:
77
ADD_ONION:
8-
- '.*'
8+
# TODO: Make Wahay restrict the local port range it listens on.
9+
# Whonix will use 0.0.0.0; most other OS's will use 127.0.0.1.
10+
- pattern: 'NEW:(\S+) Port=8181,(?:127.0.0.1|0.0.0.0):(\S+) Port=64738,(?:127.0.0.1|0.0.0.0):(\S+)'
11+
replacement: 'NEW:{} Port=8181,{client-address}:{} Port=64738,{client-address}:{} Flags=DiscardPK'
912
DEL_ONION:
1013
- '.+'
1114
GETINFO:

0 commit comments

Comments
 (0)