ShadowDNS v0.2.2 ships with secure defaults after a full audit hotfix.
| Setting | Default | Why |
|---|---|---|
| Bind | 127.0.0.1 |
No open recursive DNS / open dashboard |
| HTTP port | 8089 |
Avoid collision with other local labs on 8088 |
| TLS verify | on (DoH/DoT/webhook) | Prevent MITM DNS hijack |
| API auth | optional --token / SD_API_TOKEN |
Required when exposed |
| DNS clients | loopback only | Use --allow-client CIDR or --open-resolver |
export SD_API_TOKEN="$(openssl rand -hex 16)"
./shadowdns --token "$SD_API_TOKEN" --dns-port 5353 --http-port 8089
# LAN expose (explicit):
./shadowdns --listen-all --token "$SD_API_TOKEN" --allow-client 192.168.0.0/16- Prefer
SD_TELEGRAM_TOKEN+--telegram-chatover--telegram TOKEN:CHAT(argv leak). - JSONL is created mode
0600. - Mutating APIs (
/api/block,/api/fluxtap) and intel APIs requireX-ShadowDNS-Token(or?token=) when--tokenis set. - CORS
*removed; CSP + security headers enabled. - HTTP concurrency capped at 64 threads (
429when busy); SSE auto-closes after 5 minutes. - Webhook SSRF: private/link-local destinations blocked; HTTPS required unless
--insecure-tls.
- Unauthenticated remote policy mutation / intel dump (when bound openly)
- Missing TLS peer verification on DoH/DoT/webhooks
snprintflength used asmemcpysize (over-read)- Unbounded unique-name table growth
- DNS labels > 63 accepted
- Static file symlink / size footguns
- Open recursive DNS by default