[70184] in North American Network Operators' Group
Re: BGP Exploit
daemon@ATHENA.MIT.EDU (Steven M. Bellovin)
Tue May 4 13:54:28 2004
From: "Steven M. Bellovin" <smb@research.att.com>
To: Kurt Erik Lindqvist <kurtis@kurtis.pp.se>
Cc: kwallace@pcconnection.com, nanog@merit.edu
In-Reply-To: Your message of "Tue, 04 May 2004 10:41:00 +0200."
<C4E8C22A-9DA6-11D8-B28B-000A95928574@kurtis.pp.se>
Date: Tue, 04 May 2004 13:53:51 -0400
Errors-To: owner-nanog-outgoing@merit.edu
In message <C4E8C22A-9DA6-11D8-B28B-000A95928574@kurtis.pp.se>, Kurt Erik Lindq
vist writes:
>>
>> Now that the firestorm over implementing Md5 has quieted down a bit, is
>> anybody aware of whether the exploit has been used?
>> Feel free to reply off list.
>
>Even more interesting, did anyone manage to reproduce it?
>
I don't know if it's being used; I know that reimplementations of the
idea are out there.
--Steve Bellovin, http://www.research.att.com/~smb