Skip to content

Possible Data Leak: "Route" feature is misbehaving #491

Description

@fluxoak

I upgraded Exclave on F-Droid recently, and found that Route is not working as intended:

Route's:

  • A: Outbound proxy is not hornored
  • B: Traffic not getting blocked

Settings > Route mode is set to rule.


A: Outbound proxy is not hornored

  1. In Configuration, create only 1 VLESS profile (name it "test"). There is just only this profile.
  2. In Route, create following rules in order:

Rule1:

Name: IPTV
Applications: 1 (IPTV software)
network: TCP
outbound: "Select profile" > "test"

Rule2:

Name: block-tcp
Port: 1-52,54-442,444-65535
network: TCP
outbound: Block

Rule3:

Name: block-udp
Port: 1-52,54-65535
network: UDP
outbound: Block
  1. Apply the config by restarting VPN and Start IPTV.

Result: IPTV cannot connect because it goes to below rule(2/3). Why it doens't route to test(because of Rule1)?


B: Traffic not getting blocked

  1. In Route, create following rules in order:

Rule2:

Name: block-tcp
Port: 1-52,54-442,444-65535
network: TCP
outbound: Block

Rule3:

Name: block-udp
Port: 1-52,54-65535
network: UDP
outbound: Block
  1. Observe the log.

Why Exclave didn't block 8.8.8.8:7 connection? It simply got accepted, Port 7 is 1-52 range so why not blocked?

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    lack infoNecessary infomation not provided

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions