nanog mailing list archives
Re: OSPF Vulnerability - Owning the Routing Table
From: Saku Ytti <saku () ytti fi>
Date: Sun, 4 Aug 2013 11:17:03 +0300
On (2013-08-03 18:38 -0500), Jimmy Hess wrote:
That's not news to me, but fully expected. Do the vendors /really/ have a code fix to what would seem to be an inherent problem; if you failed to properly secure your OSPF implementation (via MD5 authentication)?
It is news to me. It's design flaw in the protocol itself which has gone unnoticed for two decades and I would have naively fully expected that this flaw does not exist in standard. As I've understood issue lies in the fact that 'link state id' and 'advertising router' should always be the same (so it's redundant information in the LSA, single field should suffice?). But standard does not enforce this at all. Victim will omit doing corrective reflood for received bogus LSA if 'advertising router' is something else than 'router-id', even while 'link state id' == 'router-id' I suppose vendors implement fix where either a) corrective reflood occur if 'link state id' == 'router-id' or b) LSA is rejected unless 'link state id' == 'advertising router' How serious or new this is, may be debatable, as only thing it seems remove, is the need for attacker to inject 0.2pps worth of packets which will suppress the corrective reflooding. -- ++ytti
Current thread:
- OSPF Vulnerability - Owning the Routing Table Glen Kent (Aug 02)
- Re: OSPF Vulnerability - Owning the Routing Table Adam Atkinson (Aug 02)
- Re: OSPF Vulnerability - Owning the Routing Table Aled Morris (Aug 02)
- Re: OSPF Vulnerability - Owning the Routing Table Jimmy Hess (Aug 03)
- Re: OSPF Vulnerability - Owning the Routing Table Saku Ytti (Aug 04)
- Re: OSPF Vulnerability - Owning the Routing Table Jimmy Hess (Aug 04)
- Re: OSPF Vulnerability - Owning the Routing Table Saku Ytti (Aug 04)
- Re: OSPF Vulnerability - Owning the Routing Table Jeff Tantsura (Aug 04)
- Re: OSPF Vulnerability - Owning the Routing Table Jimmy Hess (Aug 03)
- Message not available
- Re: Returned mail: see transcript for details Jimmy Hess (Aug 04)
- Re: Returned mail: see transcript for details Warren Bailey (Aug 04)
- Message not available
- Re: Returned mail: see transcript for details Larry Sheldon (Aug 04)
- Re: Returned mail: see transcript for details Valdis . Kletnieks (Aug 04)
- Re: Returned mail: see transcript for details Andrew Koch (Aug 05)
- Re: Returned mail: see transcript for details Valdis . Kletnieks (Aug 05)
- Re: Returned mail: see transcript for details Jay Ashworth (Aug 05)
