daimajia / daimajia/droidwall

In white list mode all apps bypass blocking if openvpn is active

Open
#230 0 comments 0 reactions 0 assignees View on GitHub
auto-migrated Priority-Medium Type-Defect
Dominant language
No language data
Stars
0
Forks
0
PR merge metrics
No merged PRs in 30d

Description

```
What steps will reproduce the problem?

1. Set white list mode
2. Allow either openvpn-settings or vpn networking ( if using cyanogen mod
openvpn option under Settings -> Wireles and network -> VPN settings ) and root
apps if the former is used.
3. Test any blocked apps, e.g., the Browser, before connecting your openvpn.
4. create your vpn tunnel
5. Test the previously chosen blocked apps again. Although it uses your vpn to
connect to the internet, it is not blocked anymore.

What is the expected output? What do you see instead?

In Droidwall you can see that the usually blocked thus logged applications do
appear there anymore, obviously because they are not blocked.

What version of the product are you using? On what operating system?

Droidwall 1.5.7 on a standard Samsung Galaxy S2 ( Tested 1.5.3 as well )
Tested with Hyperdroid v5.2.21 ( Non-AOSP ROM )
Cyanogen Mod 7.1, Cyanogen Mod 7 Nightly #116, Cyanogen Mod 7 repo version
2012-01-08

openvpn 2.1.1 from openvpn-installer
openvpn 2.1.1 from cyanogen mod

Please provide any additional information below.

Like I said, the apps can only freely use the openvpn tunnel in the Droidwall
white list mode.
I am not very familiar with iptables and openvpn binaries yet so I didn't
create a custom configuration solve this issue yet.
Whether the owner matches don't work with RETURN as the target as desired of
something else is missing, I have not found out so far.
```

Original issue reported on code.google.com by `ueakx...@gmail.com` on 13 Jan 2012 at 9:16

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reproducing the whitelist-mode behavior with OpenVPN active on the reported Android configurations, then inspect Droidwall's iptables rule generation and handling of VPN networking. Compare the rules before and after the tunnel is created, and consider the issue done when blocked applications remain blocked and their traffic is still logged while OpenVPN is active.

Written by the indexing model from the issue text.

Assessment

Tech stack
android
Domain
networking, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
28/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.