secubox-openwrt/package/secubox/luci-app-dns-provider
CyberMind-FR e58f479cd4 feat(waf): Update WAF scenarios with 2024-2025 CVEs and OWASP threats
Add detection patterns for latest actively exploited vulnerabilities:
- CVE-2025-55182 (React2Shell, CVSS 10.0)
- CVE-2025-8110 (Gogs RCE), CVE-2025-53770 (SharePoint)
- CVE-2025-52691 (SmarterMail), CVE-2025-40551 (SolarWinds)
- CVE-2024-47575 (FortiManager), CVE-2024-21887 (Ivanti)
- CVE-2024-3400, CVE-2024-0012, CVE-2024-9474 (PAN-OS)

New attack categories based on OWASP Top 10 2025:
- HTTP Request Smuggling (TE.CL/CL.TE conflicts)
- AI/LLM Prompt Injection (ChatML, instruction markers)
- WAF Bypass techniques (Unicode normalization, double encoding)
- Supply Chain attacks (CI/CD poisoning, dependency confusion)
- Extended SSTI (Jinja2, Freemarker, Velocity, Thymeleaf)
- API Abuse (BOLA/IDOR, mass assignment)

CrowdSec scenarios split into 11 separate files for reliability.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-02-12 05:02:57 +01:00
..
htdocs/luci-static/resources/view/dns-provider feat(waf): Update WAF scenarios with 2024-2025 CVEs and OWASP threats 2026-02-12 05:02:57 +01:00
root/usr fix(rpcd): Wrap call handlers in function for BusyBox ash local keyword compatibility 2026-02-04 16:39:50 +01:00
Makefile feat: Add device-intel and dns-provider packages 2026-02-04 15:47:20 +01:00
README.md feat: Add device-intel and dns-provider packages 2026-02-04 15:47:20 +01:00

luci-app-dns-provider

LuCI web interface for the SecuBox DNS Provider Manager.

Overview

Provides a web UI for managing DNS records via provider APIs (OVH, Gandi, Cloudflare). Two views: Records management and Settings configuration.

Views

Records (dns-provider/records)

  • Status bar: provider, zone, enabled state
  • Action buttons: Add Record, Sync HAProxy Vhosts, ACME DNS-01, Refresh
  • Zone records display (raw provider API output)
  • Add Record modal: type, subdomain, target, TTL
  • DNS propagation checker (1.1.1.1, 8.8.8.8, 9.9.9.9)

Settings (dns-provider/settings)

  • General: enable, provider select, zone
  • OVH: endpoint, app_key, app_secret, consumer_key
  • Gandi: API key / PAT
  • Cloudflare: API token, zone_id
  • Test Credentials button

RPCD Methods

Method Params Description
get_config Config with masked secrets
list_records Fetch zone records from provider
add_record type, subdomain, target, ttl Create DNS record
remove_record type, subdomain Delete DNS record
sync_records Sync HAProxy vhosts to DNS
verify_record fqdn Check propagation
test_credentials Validate API credentials
acme_dns01 domain Issue cert via DNS-01

Files

root/usr/libexec/rpcd/luci.dns-provider              RPCD handler
root/usr/share/luci/menu.d/luci-app-dns-provider.json Menu entry
root/usr/share/rpcd/acl.d/luci-app-dns-provider.json  ACL permissions
htdocs/.../view/dns-provider/records.js               Records view
htdocs/.../view/dns-provider/settings.js              Settings view

Dependencies

  • luci-base
  • secubox-app-dns-provider