Re: [RFC, PATCH 2.6.29.2] Ethernet V2.0 Configuration Testing Protocol, revision 20090428
From: Andi Kleen <hidden>
Date: 2009-05-04 09:29:59
From: Andi Kleen <hidden>
Date: 2009-05-04 09:29:59
Mark Smith [off-list ref] writes:
+ +4. Security + +ECTP was designed in the early 1980s, when protocol security was less of +a concern than it is now. Consequently, there are some features of the +protocol which could be abused for nefarious purposes. By default, this +implementation attempts to avoid participating in them. These features +could be useful for some test cases thought, so they can be enabled if +required.
I think security would need quite a bit more discussion. Opening new DOS this way sounds quite worrying, especially since this is a extremly obscure protocol that likely most admins don't know much about. Is this suspencible to ping to broadcast flood replication for example? Safest would probably be default to off. -Andi -- ak@linux.intel.com -- Speaking for myself only.