|
<- Previous Message | Next Message -> Thread Index [isp-bgp] Re: CERT advisory pertaining to BGP
hi all, indeed a new TCP vulnerability has been discovered in some ios here is the release note associated to this ... http://www.cisco.com/en/US/products/products_security_advisory09186a008021bc 62.shtml rgds, stephane > -----Message d'origine----- > De : E.B. Dreger [mailto:eddy+public+spam@...] > Envoyé : mercredi 21 avril 2004 21:03 > À : isp-bgp@isp-bgp.com > Objet : [isp-bgp] Re: CERT advisory pertaining to BGP > > > RG> Date: Wed, 21 Apr 2004 11:54:47 -0700 > RG> From: Rob Genovesi > > > RG> Just in case anyone out there didn't hear, there is a recent CERT > RG> advisory about a recently discovered weakness in the tcp > > If you consider a few years ago to be recent. > > > RG> protocol that puts certain types of traffic (ie BGP) at > risk. If you > RG> are running BGP it is highly recommended that you put > passwords on > RG> your BGP sessions. > RG> > RG> For more details: http://www.cert.org/advisories/CA-2001-09.html > > Maybe, maybe not. See also: TTL 255 hack for protecting > eBGP, and ingress spoof filtering for protecting iBGP. > > I'm seeing reports of sloppy MD5 checksum implementations > that compute the checksum _before_ other validity checks. > That can cause trouble in routers lacking in CPU power. > > > Eddy > -- > EverQuick Internet - http://www.everquick.net/ > A division of Brotsman & Dreger, Inc. - > http://www.brotsman.com/ Bandwidth, > consulting, e-commerce, > hosting, and network building > Phone: +1 785 865 5885 Lawrence and [inter]national > Phone: +1 316 794 8922 Wichita > _________________________________________________________________ > DO NOT send mail to the following addresses : > blacklist@... -or- alfra@intc.net -or- > curbjmp@... Sending mail to spambait addresses is a > great way to get blocked. > > > > To unsubscribe via postal mail, please contact us at: > Jupitermedia Corp. > Attn: Discussion List Management > 475 Park Avenue South > New York, NY 10016 > > Please include the email address which you have been contacted with. > > To unsubscribe via postal mail, please contact us at: Jupitermedia Corp. Attn: Discussion List Management 475 Park Avenue South New York, NY 10016 Please include the email address which you have been contacted with.
Thread Index |