Nmap Development mailing list archives

nmap and the new BGP exploit


From: mike <dmciscobgp () hotmail com>
Date: Fri, 29 Aug 2008 11:10:48 +0000


hello
 
as we all know by now there is a huge gaping hole in the world of BGP and ISP internetworking that was just discovered. 
will the future of nmap be including this probe for testing purposes? i understand alot of the details are still being 
kept tight-lipped about, but i still am curious if we will be seeing nmap queries with 179 payloads anytime soon 
because of this discovery.
 
i do not know enough about the complexity of BGP to even try and delve into the payload aspect of this. anyone out 
there a BGP expert? i know about as much as a beginner would. i am assuming we could have a tcp payload to 179 that 
tries to determine what BGP version is being used (most of the internet now uses 4) and whether it will allow an update 
by a non-trusted source (us) and let us inject or request advertised/non routes. the way i read into the flaw, it 
sounds like BGP doesn't do a full "trust" in packet transactions. you can tell the AS you have a better route than what 
it has listed and you can update it on your behalf
 
anyway, i'll let the experts tackle this if they feel the need. my email was simply in a general asking of whether this 
exploit probe will be available in nmap soon as a script
 
thanks
M|ke
_________________________________________________________________
See what people are saying about Windows Live.  Check out featured posts.
http://www.windowslive.com/connect?ocid=TXT_TAGLM_WL_connect2_082008

_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://SecLists.Org


Current thread: