cybersecurity · intermediate · ~15 min · safe pentest lab
Return true only for loopback targets — a hard-coded defensive scope limit.
A safe local tool must refuse to touch anything but the loopback interface. Implement the scope guard:
int is_loopback_target(const char *host);
Return 1 iff host is a loopback target — "localhost", "::1", or a valid IPv4 in 127.0.0.0/8 (first octet 127) — and 0 for every non-loopback host.
A NUL-terminated host string.
1 for a loopback target, 0 otherwise.
The whole 127.0.0.0/8 block is loopback. A malformed IPv4 is not a loopback target (fail closed).
#include <stddef.h>
/* Defensive scope guard: return 1 iff host is a loopback target the tool is
allowed to probe - "localhost", "::1", or a valid IPv4 in 127.0.0.0/8
(first octet 127) - else 0. Never allow a non-loopback host. */
int is_loopback_target(const char *host){ (void)host; return 0; }
Only matching 127.0.0.1 exactly instead of the whole /8; failing open on a malformed address; forgetting localhost/::1.
"127.0.0.1", "localhost", "127.5.6.7", "::1"→1; "126.0.0.1", "8.8.8.8", "example.com", "127.0.0.256"→0.
Solve this exercise in the browser editor — compile and run against the test harness, no setup required.