Index | Thread | Search

From:
Damien Miller <djm@mindrot.org>
Subject:
Re: [Patch] nc(1) strncmp in socks mode is using the wrong length
To:
spiros thanasoulas <dsp@2f30.org>
Cc:
tech@openbsd.org
Date:
Thu, 22 May 2025 16:41:08 +1000

Download raw body.

Thread
On Wed, 21 May 2025, spiros thanasoulas wrote:

> 
> Hello list!
> 
> *Sorry if someone got this twice but i had to relax my DMARC policy.*
> 
> I am attaching a patch that fixes the parsing of the HTTP response from 
> a socks proxy to properly match the HTTP 200 or HTTP 407 modes. As the
> strncmp call is right now it would match a response of (for example)
> HTTP/1.0 407123 as something that belongs to the code path of the 
> HTTP/1.0 407 case. However I do not believe that this has any impact.

Good catch - this bug existed since I added CONNECT support
~19 years ago...

I've committed your fix.

-d