cybersecurity · intermediate · ~15 min · safe pentest lab

Enforce a loopback-only scope

Return true only for loopback targets — a hard-coded defensive scope limit.

Challenge

A safe local tool must refuse to touch anything but the loopback interface. Implement the scope guard:

int is_loopback_target(const char *host);

Return 1 iff host is a loopback target — "localhost", "::1", or a valid IPv4 in 127.0.0.0/8 (first octet 127) — and 0 for every non-loopback host.

Input format

A NUL-terminated host string.

Output format

1 for a loopback target, 0 otherwise.

Constraints

The whole 127.0.0.0/8 block is loopback. A malformed IPv4 is not a loopback target (fail closed).

Starter code

#include <stddef.h>
/* Defensive scope guard: return 1 iff host is a loopback target the tool is
   allowed to probe - "localhost", "::1", or a valid IPv4 in 127.0.0.0/8
   (first octet 127) - else 0. Never allow a non-loopback host. */
int is_loopback_target(const char *host){ (void)host; return 0; }

Common mistakes

Only matching 127.0.0.1 exactly instead of the whole /8; failing open on a malformed address; forgetting localhost/::1.

Edge cases to handle

"127.0.0.1", "localhost", "127.5.6.7", "::1"→1; "126.0.0.1", "8.8.8.8", "example.com", "127.0.0.256"→0.

Solve this exercise in the browser editor — compile and run against the test harness, no setup required.