oss-sec mailing list archives

Re: Attack on badly configured Netfilter-based firewalls


From: yersinia <yersinia.spiros () gmail com>
Date: Mon, 27 Feb 2012 12:42:35 +0100

On Sun, Feb 26, 2012 at 11:37 PM, Eric Leblond <eric () regit org> wrote:

Hello,


This is a correct definition of the condition on the network required
for the attack.

Hi. If i have undestood correcly,  setting arp_announce and arp_ignore as
below should be fix the problem you have  described, isn't it ?

net.ipv4.conf.all.arp_announce=1
net.ipv4.conf.all.arp_ignore=2


We set so by default in our env by policy.

Thanks and Regards

Elia

Current thread: