03.04.2013 Views

The menace came from below - Hack.lu

The menace came from below - Hack.lu

The menace came from below - Hack.lu

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Protection for Netfilter<br />

We only have to use the rp_filter feature.<br />

It is available since last century in all Linux kernel.<br />

Disabled by default. Enabled by all decent firewall scripts.<br />

To activate it:<br />

echo " 1 " > / proc / sys / net / ipv4 / conf / a l l / r p _ f i l t e r<br />

Wait and for IPv6?<br />

Éric Leblond, Victor Julien (OISF) <strong>The</strong> <strong>menace</strong> <strong>came</strong> <strong>from</strong> <strong>below</strong> <strong>Hack</strong>.<strong>lu</strong> 2012 33 / 66

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!