[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <874nsyk982.fsf@mid.deneb.enyo.de>
Date: Thu, 05 Apr 2012 08:01:49 +0200
From: Florian Weimer <fw@...eb.enyo.de>
To: Al Viro <viro@...IV.linux.org.uk>
Cc: Martin Lucina <martin@...ina.net>, linux-kernel@...r.kernel.org,
netdev@...r.kernel.org
Subject: Re: [PATCH] Implement IP_EVIL socket option (RFC 3514)
* Al Viro:
> On Wed, Apr 04, 2012 at 09:17:00PM +0200, Florian Weimer wrote:
>> * Martin Lucina:
>>
>> > This patch implements the IP_EVIL socket option, allowing user-space
>> > applications to set the Security Flag in the IPv4 Header, aka "evil" bit,
>> > as defined in RFC 3514.
>>
>> I need this to fix a security issue. Could this be merged for real,
>> please?
>
> I would suggest switching away from your RFC1149 link - looks like your mail
> took 3 days on the way out...
Sorry, I saw it just now.
The idea is to change the JVM to set IP_EVIL when an applet creates a
socket, so that this socket cannot be used to trick firewalls to open
up access to totally unrelated services.
--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Powered by blists - more mailing lists