nanog mailing list archives
Re: control characters in BGP shutdown communication(RFC 9003) messages and NETCONF
From: Chris Adams via NANOG <nanog () lists nanog org>
Date: Sun, 7 Sep 2025 12:34:15 -0500
Once upon a time, Job Snijders <job () sobornost net> said:
If I worked at Juniper/HPE ... I'd use something like strnvis() to sanitize the (untrusted) network input contained within a Shutdown Communication. See the documentation here https://man.openbsd.org/vis.3
JUNOS already contains some XML encoding code, since essentially day 1 (since they were emitting XML from the backend)... but this makes it look like the NETCONF code isn't using it. This could be a security issue - what if somebody sends '</whatever><then-more-XML>...' in a message? -- Chris Adams <cma () cmadams net> _______________________________________________ NANOG mailing list https://lists.nanog.org/archives/list/nanog () lists nanog org/message/SHHBCOT6W6TACBKXQ62CTRDZRZPLONMB/
Current thread:
- control characters in BGP shutdown communication(RFC 9003) messages and NETCONF Martin Tonusoo via NANOG (Sep 07)
- Re: control characters in BGP shutdown communication(RFC 9003) messages and NETCONF Job Snijders via NANOG (Sep 07)
- Re: control characters in BGP shutdown communication(RFC 9003) messages and NETCONF Martin Tonusoo via NANOG (Sep 07)
- Re: control characters in BGP shutdown communication(RFC 9003) messages and NETCONF Job Snijders via NANOG (Sep 07)
- Re: control characters in BGP shutdown communication(RFC 9003) messages and NETCONF Jeffrey Haas via NANOG (Sep 07)
- Re: control characters in BGP shutdown communication(RFC 9003) messages and NETCONF Chris Adams via NANOG (Sep 07)
- Re: control characters in BGP shutdown communication(RFC 9003) messages and NETCONF Martin Tonusoo via NANOG (Sep 07)
- Re: control characters in BGP shutdown communication(RFC 9003) messages and NETCONF nanog--- via NANOG (Sep 07)
- Re: control characters in BGP shutdown communication(RFC 9003) messages and NETCONF Job Snijders via NANOG (Sep 07)
- Re: control characters in BGP shutdown communication(RFC 9003) messages and NETCONF Yang Yu via NANOG (Sep 08)
- Re: control characters in BGP shutdown communication(RFC 9003) messages and NETCONF Martin Tonusoo via NANOG (Sep 08)
