[53095] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: no ip forged-source-address

daemon@ATHENA.MIT.EDU (Petri Helenius)
Wed Oct 30 17:08:40 2002

From: "Petri Helenius" <pete@he.iki.fi>
To: "Hank Nussbacher" <hank@att.net.il>, <variable@ednet.co.uk>
Cc: <nanog@nanog.org>
Date: Thu, 31 Oct 2002 00:01:59 +0200
Errors-To: owner-nanog-outgoing@merit.edu


> decides to attack, it would use some neighbor's IP.  The subnet I am on is
> a /24 and there very well may be a few dozen hosts.  I could be real
> sneaky and alter my IP randomly to be any of my neighbors for every packet
> I send out.
> 
This gets a lot sneakier when you got your /64 on the subnet. Specially 
if people start to build significantly larger subnets by default.

Pete



home help back first fref pref prev next nref lref last post