Re: OSPF Vulnerability - Owning the Routing Table

2013-08-04 Thread Saku Ytti
On (2013-08-03 18:38 -0500), Jimmy Hess wrote: That's not news to me, but fully expected. Do the vendors /really/ have a code fix to what would seem to be an inherent problem; if you failed to properly secure your OSPF implementation (via MD5 authentication)? It is news to me. It's design

Re: OSPF Vulnerability - Owning the Routing Table

2013-08-04 Thread Jimmy Hess
On 8/4/13, Saku Ytti s...@ytti.fi wrote: On (2013-08-03 18:38 -0500), Jimmy Hess wrote: That's not news to me, but fully expected. Do the vendors /really/ have a code fix to what would seem to be an inherent problem; if you failed to properly secure your OSPF implementation (via MD5

Re: OSPF Vulnerability - Owning the Routing Table

2013-08-04 Thread Saku Ytti
On (2013-08-04 05:01 -0500), Jimmy Hess wrote: I would say the risk score of the advisory is overstated. And if you think ospf is secure against LAN activity after any patch, that would be wishful thinking. Someone just rediscovered one of the countless innumerable holes in the back of the

Re: IP allocations / bogon - ARIN Inconsistency

2013-08-04 Thread Rene Wilhelm
On 8/4/13 6:50 AM, Geoff Huston wrote: On 04/08/2013, at 2:06 PM, Rob Mosher rmos...@he.net wrote: Frank, HE uses the extended files for these stats since the standard ones will soon be deprecated. As Rene pointed out, the extended and standard delegation files from ARIN do not match

Re: OSPF Vulnerability - Owning the Routing Table

2013-08-04 Thread Jeff Tantsura
Agree, that't why using p2p has been mentioned as BCP in networking howto's for at least last 10 years. Regards, Jeff On Aug 4, 2013, at 3:14 AM, Saku Ytti s...@ytti.fi wrote: On (2013-08-04 05:01 -0500), Jimmy Hess wrote: I would say the risk score of the advisory is overstated. And if

Re: Returned mail: see transcript for details

2013-08-04 Thread Jimmy Hess
This was just received a flood of bounces reporting delivery failuers on messages I sent to nanog@ a few days ago... Actually, I have just received a flood of about 15 messages just like this one around 9:00pm; from various nanog posts I had sent 2 to 5 days in the past.. Is that strange

Re: Returned mail: see transcript for details

2013-08-04 Thread Warren Bailey
I got hit the same. Sent from my Mobile Device. Original message From: Jimmy Hess mysi...@gmail.com Date: 08/04/2013 9:09 PM (GMT-08:00) To: nanog@nanog.org Subject: Re: Returned mail: see transcript for details This was just received a flood of bounces reporting delivery

Re: Returned mail: see transcript for details

2013-08-04 Thread Larry Sheldon
On 8/4/2013 11:13 PM, Warren Bailey wrote: I got hit the same. me too. e, me two. No clues as to what the messages were that I could see. -- Requiescas in pace o email Two identifying characteristics of System Administrators: Ex turpi

Re: Returned mail: see transcript for details

2013-08-04 Thread Valdis . Kletnieks
On Sun, 04 Aug 2013 23:07:59 -0500, Jimmy Hess said: I thought the mailing list software rewrote the return path to suppress bounces? Yeah, but every once in a while you'll come across a mail server hosted at Billy Bob's Bait, Tackle, and E-mail, or Klooful Joe's Bargain Hosting, that doesn't