public inbox for netdev@vger.kernel.org 
 help / color / mirror / Atom feed
From: Fernando Gont <fernando@gont•com.ar>
To: netdev <netdev@vger•kernel.org>
Subject: VPN traffic leaks in IPv6/IPv4 dual-stack networks/hosts
Date: Tue, 27 Nov 2012 11:54:50 -0300	[thread overview]
Message-ID: <50B4D43A.7030208@gont.com.ar> (raw)

Folks,

FYI. This is might affect Linux users employing e.g. OpenVPN:
<http://tools.ietf.org/html/draft-gont-opsec-vpn-leakages>.

For a project such as OpenVPN, a (portable) fix might be non-trivial.
However, I guess Linux might hook some iptables rules when establishing
the VPN tunnel, such that e.g. all v6 traffic is filtered (yes, this is
certainly not the most desirable fix, but still probably better than
having your supposedly-secured traffic being sent in the clear).

P.S.: Not sure if this is the right list to send this note. Please
advice of a more appropriate one and/or feel free to forward this note
if deemed appropriate...

Thanks,
-- 
Fernando Gont
e-mail: fernando@gont•com.ar || fgont@si6networks•com
PGP Fingerprint: 7809 84F5 322E 45C7 F1C9 3945 96EE A9EF D076 FFF1

             reply	other threads:[~2012-11-27 15:21 UTC|newest]

Thread overview: 12+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2012-11-27 14:54 Fernando Gont [this message]
2012-11-27 16:04 ` VPN traffic leaks in IPv6/IPv4 dual-stack networks/hosts Eric Dumazet
2012-11-27 16:07   ` Fernando Gont
2012-11-27 16:22     ` Michal Kubeček
2012-11-27 16:10 ` Jan Engelhardt
2012-11-28 19:57   ` Fernando Gont
2012-11-28 20:06     ` Jan Engelhardt
2012-11-28 20:14       ` Fernando Gont
2012-11-28 21:37         ` Jan Engelhardt
2012-11-29  2:29           ` Fernando Gont
2012-11-29  3:15             ` Jan Engelhardt
2012-11-29  4:38               ` Fernando Gont

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=50B4D43A.7030208@gont.com.ar \
    --to=fernando@gont$(echo .)com.ar \
    --cc=netdev@vger$(echo .)kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox