Warda-DNSDocs v0.6.4

Threats in the names and the answers

Protection → Protections, card Threats in the names (administrators; free, beta, each check on by default; internal/threats). The rule of the card: what leaves no doubt is blocked, the rest is told for a person to decide.

  • DNS rebinding (blocked): a name of Internet whose answer holds an address of the home, the loopback (127.0.0.0/8, ::1), a link-local address, or a private address (RFC 1918, ULA, 100.64.0.0/10) of a network of the interfaces of the box (read again every 10 minutes): a web page could drive the box, a camera or the NAS through the browser. The public addresses, even those of the home (its IPv6 prefix, which a dynamic DNS answers on purpose), the other private networks (a work network, a VPN) and 0.0.0.0 (the answer of a filtering upstream) are left alone, as the local names and zones, the names an administrator allowed, and the services that do it on purpose (plex.direct, nip.io, sslip.io, ts.net, synology.me… threats.SafeRebinding). Reason rebinding, origin rebinding:<address>; It is expected allows a domain and its names (at most 200): a homelab that publishes the names of its services with their local addresses (for a certificate) needs it, as with the protection against the rebinding of OpenWrt or pfSense.
  • Spyware (blocked): the servers of the commercial spyware, from the list stalkerware.txt of warda-lists (the network indicators of Echap, CC BY 4.0; read from the repository of Echap until warda-lists publishes it; refreshed every 6 hours, task stalkerware), for every device. Reason spyware. The alert goes to the administrators (the device) and to the person of the device (notice spyware.mine, GET /api/v1/me/spyware, each with blocked, shown on their dashboard and their page My account, with what to do and a helpline of their language), whoever the administrators are: the one who installs such an app is often a close person. The person is told even when the blocking is off or an administrator allowed the domain for himself (then "not blocked"; the administrators get no alert of their own).
  • Remote access tools (told): AnyDesk, TeamViewer, RustDesk, ScreenConnect, Splashtop, LogMeIn, Quick Assist, Chrome Remote Desktop… (threats.RemoteTools), used by the fake support scams: an alert the first time a device uses one (once a month by device and tool). To block them, block the service for a profile.
  • Beacons (told): a device that asks the same rare domain at a very regular interval (24 questions at least over 6 hours at least, the deviation of the intervals under 15 % of their mean, between one minute and two hours), a domain asked by that device only, neither a name protected against the look-alikes nor a known service (clouds, content networks), and young according to the online service (less than 180 days, so never with the second opinion off): a program driven from outside. Many connected objects talk to the servers of their maker that way, hence the age. At most 4096 device and domain pairs are followed; one alert a week by device and domain.
  • Quarantine: Put in quarantine (on an alert of spyware or of a beacon, or on Household → Devices) keeps a device away from Internet: it gets only the local names and the names that heal it (the updates of Windows, Apple, Android and Debian, the antivirus software, the time and the certificates, Warda: admin.Healing), until End the quarantine. It is a quarantine by the names: a program with its own resolver or addresses written in it goes around it; to cut a device off entirely, unplug it. Reason quarantine; kept at a restart (quarantine in the settings); audit device.quarantine.on/off.

Each alert (rebinding, spyware, remote, beacon) is shown with the others (see Alerts) and with the card. GET /api/v1/threats gives rebinding, rebinding_allowed, networks, spyware, spyware_domains, remote, beacons, found (the alerts of 30 days, each with name and extra: the address of a rebinding, the interval of a beacon) and quarantined (device ids); PUT /api/v1/threats takes rebinding, rebinding_allowed, spyware, remote and beacons (audit rebinding.on/off…, rebinding.allowed); PUT /api/v1/devices/{id}/quarantine {"on": true} (404 for a device not known, 400 for this box).