From: Fernando Gont <fernando@gont•com.ar>
To: netdev <netdev@vger•kernel.org>
Subject: VPN traffic leaks in IPv6/IPv4 dual-stack networks/hosts
Date: Tue, 27 Nov 2012 11:54:50 -0300 [thread overview]
Message-ID: <50B4D43A.7030208@gont.com.ar> (raw)
Folks,
FYI. This is might affect Linux users employing e.g. OpenVPN:
<http://tools.ietf.org/html/draft-gont-opsec-vpn-leakages>.
For a project such as OpenVPN, a (portable) fix might be non-trivial.
However, I guess Linux might hook some iptables rules when establishing
the VPN tunnel, such that e.g. all v6 traffic is filtered (yes, this is
certainly not the most desirable fix, but still probably better than
having your supposedly-secured traffic being sent in the clear).
P.S.: Not sure if this is the right list to send this note. Please
advice of a more appropriate one and/or feel free to forward this note
if deemed appropriate...
Thanks,
--
Fernando Gont
e-mail: fernando@gont•com.ar || fgont@si6networks•com
PGP Fingerprint: 7809 84F5 322E 45C7 F1C9 3945 96EE A9EF D076 FFF1
next reply other threads:[~2012-11-27 15:21 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-11-27 14:54 Fernando Gont [this message]
2012-11-27 16:04 ` VPN traffic leaks in IPv6/IPv4 dual-stack networks/hosts Eric Dumazet
2012-11-27 16:07 ` Fernando Gont
2012-11-27 16:22 ` Michal Kubeček
2012-11-27 16:10 ` Jan Engelhardt
2012-11-28 19:57 ` Fernando Gont
2012-11-28 20:06 ` Jan Engelhardt
2012-11-28 20:14 ` Fernando Gont
2012-11-28 21:37 ` Jan Engelhardt
2012-11-29 2:29 ` Fernando Gont
2012-11-29 3:15 ` Jan Engelhardt
2012-11-29 4:38 ` Fernando Gont
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=50B4D43A.7030208@gont.com.ar \
--to=fernando@gont$(echo .)com.ar \
--cc=netdev@vger$(echo .)kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox