Home page logo

nanog logo nanog mailing list archives

RE: BCP38 tester?
From: "Frank Bulk \(iname.com\)" <frnkblk () iname com>
Date: Mon, 1 Apr 2013 13:50:11 -0500

The good news is that source address spoofing does seem to fail with most CPE's NAT.  

At the end of the day, just turn on uRPF and/or use ACLs.  It's amazing how much destination and our ACLs also block.


-----Original Message-----
From: Jay Ashworth [mailto:jra () baylink com] 
Sent: Sunday, March 31, 2013 9:35 PM
Subject: Re: BCP38 tester?

----- Original Message -----
From: "Alain Hebert" <ahebert () pubnix net>

An easy target would be anti-virus/trojan/security software
providers that could add a BCP38 check to their software =D

Yes, but penetration is a problem, which is why I was thinking about
people like YouTube, Ookla, and the like.

Any Flash app that lots of people run frequently.  Assuming those apps
could generate the packets, which, on reflection, I would bet they can't.

-- jra
Jay R. Ashworth                  Baylink                       jra () baylink com
Designer                     The Things I Think                       RFC 2100
Ashworth & Associates     http://baylink.pitas.com         2000 Land Rover DII
St Petersburg FL USA               #natog                      +1 727 647 1274

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]