[170844] in North American Network Operators' Group
RE: CVE-2014-0160 mitigation using iptables
daemon@ATHENA.MIT.EDU (David Hubbard)
Thu Apr 10 09:58:17 2014
Date: Thu, 10 Apr 2014 09:54:54 -0400
From: David Hubbard <dhubbard@dino.hostasaurus.com>
To: <nanog@nanog.org>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
He was also proven wrong on the Full Disclosure list but he seems to be
pushing this everywhere he can find an audience for some reason.=20
-----Original Message-----
From: Nick Hilliard [mailto:nick@foobar.org]=20
Sent: Thursday, April 10, 2014 6:13 AM
To: Fabien Bourdaire; nanog@nanog.org
Subject: Re: CVE-2014-0160 mitigation using iptables
On 09/04/2014 11:07, Fabien Bourdaire wrote:
> Following up on the CVE-2014-0160 vulnerability, heartbleed. We've=20
> created some iptables rules to block all heartbeat queries using the=20
> very powerful u32 module.
as someone pointed out on the UKNOF mailing list yesterday, you make a
number of assumptions in this ruleset which are not necessarily valid.
Please do not claim that this ruleset blocks all heartbeat queries
because it does not.
Nick