[141717] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: The stupidity of trying to "fix" DHCPv6

daemon@ATHENA.MIT.EDU (Valdis.Kletnieks@vt.edu)
Fri Jun 10 14:19:32 2011

To: Jima <nanog@jima.tk>
In-Reply-To: Your message of "Fri, 10 Jun 2011 12:54:17 CDT."
	<4DF25A49.1050100@jima.tk>
From: Valdis.Kletnieks@vt.edu
Date: Fri, 10 Jun 2011 14:18:12 -0400
Cc: nanog@nanog.org
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org

--==_Exmh_1307729892_4421P
Content-Type: text/plain; charset=us-ascii

On Fri, 10 Jun 2011 12:54:17 CDT, Jima said:
>   If we go down this path, how long before we hear screaming about rogue 
> DHCPv6 servers giving v4-only networks a false v6 path?

Already happened.  Good way to install an MITM against any v6-enabled boxes
on a v4-only network, been multiple reported uses of that technique.


--==_Exmh_1307729892_4421P
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Exmh version 2.5 07/13/2001

iD8DBQFN8l/kcC3lWbTT17ARAj4eAKDP0LA7OSuRCPHmGNLCUU3XFyS8AQCdHs5g
qqXnbXF0lofl/l2apX6ayBA=
=pJn6
-----END PGP SIGNATURE-----

--==_Exmh_1307729892_4421P--



home help back first fref pref prev next nref lref last post