Security, Governance and Platform · Principal
The agent's URL passed the allowlist. Why did its fetch reach an internal service?
The question
Interview question
An agent can fetch a public URL to research a customer issue. The tool validates the hostname and resolves it to a public IP before approving the call. The HTTP client later makes the request. The hostname now resolves to a private address, and the tool reaches an internal service. What did validation actually approve?
Take a few minutes to form your approach. Then open a worked answer and compare the decisions.
Reveal a worked answer
It approved one observation of DNS, not the connection that was made. The host can resolve differently between validation and use. A proxy, connection pool, redirect or HTTP library can also make its own resolution after your check. This is a time-of-check to time-of-use problem. OWASP's SSRF guidance calls out DNS rebinding and the need to validate target addresses. The exact guard has to live at the egress path that actually connects.
For a narrow product, I would prefer an explicit set of trusted destinations and a fetcher with no direct access to internal networks. For arbitrary public research URLs, parse and normalize the URL, permit only expected schemes and ports, resolve it, reject loopback, link-local, private, metadata and other disallowed addresses, and bind the actual connection to an approved address. Preserve the intended hostname for TLS certificate verification and HTTP authority. Do not disable TLS verification to make an IP-pinned connection work. Enforce network egress policy too, so a parsing mistake does not turn into access to instance metadata.
Redirects are a fresh destination decision. Proxies must apply the same rule at their connection point. Consider IPv6, numeric and encoded IP forms, CNAME chains, multiple A and AAAA answers and DNS answers that change between attempts. I would test a hostname that returns a public IP at validation and a private IP at connect, then verify that no private connection is attempted. A clean-looking URL in the agent transcript is insufficient evidence.
The interviewer may say the domain itself is allowlisted. That can be a useful authorization constraint if the operator controls it and the egress path is restricted. It still does not justify connecting to an arbitrary private IP returned by that domain. The tool URL was approved. May the agent follow its redirect to a new host? covers an approved URL redirecting to a different host. This failure can occur with the same hostname and no redirect at all.
Continue reading
Related questions
Read beyond the question
Explore more security, governance and platform
Follow another question in this area, or search the complete Question Library.
Browse this area →Browse Question Library →