nanog mailing list archives

Re: tcp md5 bgp attacks?


From: Niels Bakker <niels=nanog () bakker net>
Date: Sun, 19 Aug 2018 22:32:51 +0200

* randy () psg com (Randy Bush) [Wed 15 Aug 2018, 04:27 CEST]:
my memory is that seq num guessing and sending rst was the core problem motivating tcp/md5 for bgp, and btsh came some years later. but no big deal.

And a few looking glasses exposed detailed TCP window information when run against certain hardware vendors' routers, making that very easy.


        -- Niels.


Current thread: