4 ms·
No, 127.0.0.1 should never appear on any network, and no network device should ever route it. The earliest documentation I was able to find is in RFC 1122 [1]
by phlo 8y ago
No, 127.0.0.1 should never appear on any network, and no network device should ever route it.
The earliest documentation I was able to find is in RFC 1122 [1] from 1989, but according to RFC 6890 [2], the principle dates back to 1981.
[1] https://tools.ietf.org/html/rfc1122#section-3.2.1.3 https://tools.ietf.org/html/rfc1122#section-3.2.1.3
[2] https://tools.ietf.org/html/rfc6890 https://tools.ietf.org/html/rfc6890 (table 4)
- justinclift 8y agoAhhh yeah. But that's how most OS's set things up by default, in order to meet the required specs. (bugs and implementations hiccups aside) Once the OS is up and running, manipulation of the routing tables at least _used_ to make this possible on Linux and Solaris. Not sure about FreeBSD, but that's just from memory fuzziness on my part. :)
- yebyen 8y ago> Traffic sent to 127.0.0.1 is guaranteed not to leave your machine This is definitely false, without any routing tables. Any unprivileged user can start an SSH tunnel listening on any localhost port above 1024, sending traffic out to wherever.
- j4cob 8y agoThe implicit threat model here is "no one outside your machine can do something to you to make 127.0.0.1 traffic route elsewhere." It's true that software running on your machine can make copies of things and send them elsewhere, but that's not the point of the sentence you quoted.
- gerdesj 8y agoSent to is not the same as sent from
- icebraining 8y agoYeah, but that would rather involve being on the other side of the airtight hatchway (having root).
- justinclift 8y agoGood point. :)