"Local network scan" can scan over the internet #2299
Labels
Bug
An error, flaw, misbehavior or failure in the Monkey or Monkey Island.
Complexity: Low
Impact: Critical
Describe the bug
The option to scan local networks in network configuration could allow Infection Monkey to scan and attempt to exploit machines over the public internet. This risk needs to be obvious to the user.
Determining whether or not a network interface is connected to the public internet is not trivial. There are some simple steps we can take, but there is no formal definition of "public interface". The closest thing would be to only scan addresses in IPv4 the private ranges, but this may or may not be the user's desired behavior.
To resolve this issue, we will take the following steps
Tasks
The text was updated successfully, but these errors were encountered: