|
|||||||||||
|
The freeswan-snap1998May28 is still broken, other problems too
From: Hugh Daniel <hugh(at)road.toad.com>
Date: Thu May 28 1998 - 07:30:55 EDT
First here is now the denial of service attack/bug works. Set up a
the 'standard' test setup of two SG's and a ping machine behind each.
Set things up and then run 'ping -s other_client' for a while to run
up the replay counters.
Next I was going to make a run with debugging turned on, but debbugging control is broken currently as you can see:
root@west > klipsdebug --version
Next it seems that we are missing data in the various /proc/net/ipsec_* files that was there before. I understand that IV's and Keys etc. need to be kept private, but still something is missing.
SPI:
SPIGRP:
TNCFG:
# cat /proc/net/ipsec-spi
Ah, looking at the output of the scripts that set up the hand keyd link I see why the new output looks skimpy: So this util has changed in some way that breaks it, or the --help doc and CHANGES files faild to change to reflect the code. Well I think that is enough churn for one email message. It is clear that there are interesting attacks and bugs in this system yet! Well I should get back to something useful... Enjoy. ||ugh Daniel hugh@toad.com Systems Testing & Project mis-Management The Linux FreeS/WAN Project http://www.xs4all.nl/~freeswanReceived on Thu May 28 07:43:30 1998 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:15 EDT |
||||||||||
|
|||||||||||