Skip to content

GitLab

  • Menu
Projects Groups Snippets
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
    • Switch to GitLab Next
  • Sign in / Register
  • iterm2 iterm2
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
    • Locked Files
  • Issues 2,615
    • Issues 2,615
    • List
    • Boards
    • Service Desk
    • Milestones
    • Requirements
  • Deployments
    • Deployments
    • Releases
  • Monitor
    • Monitor
    • Incidents
  • Analytics
    • Analytics
    • Value stream
    • Insights
    • Issue
    • Repository
  • Wiki
    • Wiki
  • Activity
  • Graph
  • Create a new issue
  • Commits
  • Issue Boards
Collapse sidebar

GitLab 15.0 is launching on May 22! This version brings many exciting improvements, but also removes deprecated features and introduces breaking changes that may impact your workflow. To see what is being deprecated and removed, please visit Breaking changes in 15.0 and Deprecations.

  • George Nachman
  • iterm2iterm2
  • Issues
  • #5303
Closed
Open
Created Nov 02, 2016 by ewaher@ewaher

undesirable domain lookup behavior

Thanks for filing an issue! Please answer the questions below so I can help you.

  • iTerm2 version: Build 3.0.10
  • OS version: OS X 10.11.16

Detailed steps to reproduce the problem:

  1. Turn on Preferences->Pointer-> ⌘-Click Opens Filename/URL (Semantic History)
  2. launch an iterm window, type google.com
  3. Holding ⌘ key, highlight google.com text.

What happened: Once you hover over the url while holding ⌘ key, iterm issues a DNS query for that domain highlighted.

What should have happened:

Domains should not be queried through DNS to determine whether they are highlighted in iTerm. The current behavior can compromise a security analyst or incident responders investigation by querying a URL unintentionally while in iterm. Often hackers/attackers monitor their attacking infrastructure for such investigators and these types of queries coming from a targets network.

While the user experience will be less than ideal, attempting to follow a URL in iterm which does not resolve is no fault of iterm, and could even introduce unexplained behavior when a bad domain name does not become "clickable".

Thanks for considering this request.

Assignee
Assign to
Time tracking