[j-nsp] PSN-2013-08-987 - OSPF Advisory - Impact?

Sebastian Wiesinger juniper-nsp at ml.karotte.org
Fri Aug 2 05:17:32 EDT 2013


* Chris Morrow <morrowc at ops-netman.net> [2013-08-02 11:12]:
> 
> 
> On 08/02/2013 04:26 AM, Sebastian Wiesinger wrote:
> > So, it's friday and there is PSN-2013-08-987. Am I overlooking
> > something or is that only a problem for people who speak OSPF with
> > other parties (customers, strangers,...)? I don't see the big attack
> > vector in comparison to speaking OSPF with others in the first
> > place...
> 
> or maybe people that mistakenly turn it on on 'external' (not network
> facing) interfaces... like lan interfaces.

Yes, that could be possible but that would allow the "external" party
to mess with OSPF anyway...

Regards

Sebastian

-- 
GPG Key: 0x93A0B9CE (F4F6 B1A3 866B 26E9 450A  9D82 58A2 D94A 93A0 B9CE)
'Are you Death?' ... IT'S THE SCYTHE, ISN'T IT? PEOPLE ALWAYS NOTICE THE SCYTHE.
            -- Terry Pratchett, The Fifth Elephant


More information about the juniper-nsp mailing list