I-D Action:draft-ietf-6man-overlap-fragment-00.txt

2008-09-24 Thread Internet-Drafts
A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the IPv6 Maintenance Working Group of the IETF. Title : Handling of overlapping IPv6 fragments Author(s) : S. Krishnan Filename:

Re: I-D Action:draft-ietf-6man-overlap-fragment-00.txt

2008-09-24 Thread Rémi Denis-Courmont
On Wed, 24 Sep 2008 07:30:01 -0700 (PDT), [EMAIL PROTECTED] wrote: The fragmentation and reassembly algorithm specified in the base IPv6 specification allows fragments to overlap. This document demonstrates the security issues with allowing overlapping fragments and updates the IPv6

Re: I-D Action:draft-ietf-6man-overlap-fragment-00.txt

2008-09-24 Thread Suresh Krishnan
Hi Remi, Rémi Denis-Courmont wrote: On Wed, 24 Sep 2008 07:30:01 -0700 (PDT), [EMAIL PROTECTED] wrote: The fragmentation and reassembly algorithm specified in the base IPv6 specification allows fragments to overlap. This document demonstrates the security issues with allowing overlapping

Re: I-D Action:draft-ietf-6man-overlap-fragment-00.txt

2008-09-24 Thread Rémi Denis-Courmont
On Wed, 24 Sep 2008 11:23:28 -0400, Suresh Krishnan [EMAIL PROTECTED] wrote: 1) Inside_Host(Port X)-Outside_Host(Port Y) SYN=1,ACK=0 2) Outside_Host(Port Y)-Inside Host(Port X) SYN=1,ACK=1 3) Inside_Host(Port X)-Outside_Host(Port Y) SYN=0,ACK=1 ... 99) Outside_Host(Port Y)-Inside

Re: I-D Action:draft-ietf-6man-overlap-fragment-00.txt

2008-09-24 Thread Suresh Krishnan
Hi Remi, Rémi Denis-Courmont wrote: On Wed, 24 Sep 2008 11:23:28 -0400, Suresh Krishnan [EMAIL PROTECTED] wrote: 1) Inside_Host(Port X)-Outside_Host(Port Y) SYN=1,ACK=0 2) Outside_Host(Port Y)-Inside Host(Port X) SYN=1,ACK=1 3) Inside_Host(Port X)-Outside_Host(Port Y) SYN=0,ACK=1 ... 99)