[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Exim and IPv6 Help
>So we are again in the area of IPv4-mapped addresses not supported under
>OpenBSD. NetBSD has a sysctl switch to enable this if I remember your
>previous mail right. What's wrong with this approach?
- kernel code gets more complex and we cannot audit kernel code.
- applications can still be tricked to do bad things. (think of FTP
bounce attacks on active mode FTP, with more complexity with IPv4
mapped address). for more complete attack scenarios see my recent
posting to bugtraq.
actually, I don't really like the switch we have in NetBSD. it has
certain brokenness in places like in6_pcbbind(), as well as possibility
to get abused.