IP Spoofing
idea.popcount.org
IP Spoofing
1–10 of 136 posts
Re: IP Spoofing
#2Re: IP Spoofing
#3Re: IP Spoofing
#4There is no excuse for not securing your network to allow spoofing from it. Most of the big players like leaseweb or ovh do not allow that. But there are some providers that still allow you to spoof source ip address. There should be consensus about droping routes on BGP level to networks that send packets with source ips that they do not announce. It's really simple to drop packets on switches/routers that do not or…
Re: IP Spoofing
#5Re: IP Spoofing
#6There is no excuse for not securing your network to allow spoofing from it. Most of the big players like leaseweb or ovh do not allow that. But there are some providers that still allow you to spoof source ip address. There should be consensus about droping routes on BGP level to networks that send packets with source ips that they do not announce. It's really simple to drop packets on switches/routers that do not or…
With what hardware?
Re: IP Spoofing
#7Re: IP Spoofing
#8[0] https://blog.torproject.org/blog/traffic-correlation-using-n...
[1] https://gitweb.torproject.org/torspec.git/tree/proposals/251...
Re: IP Spoofing
#9There is no excuse for not securing your network to allow spoofing from it. Most of the big players like leaseweb or ovh do not allow that. But there are some providers that still allow you to spoof source ip address. There should be consensus about droping routes on BGP level to networks that send packets with source ips that they do not announce. It's really simple to drop packets on switches/routers that do not or…
>There should be consensus about droping routes on BGP level to networks that send packets with source ips that they do not announce. With what hardware?
There is no excuse except laziness for not doing do.
https://tools.ietf.org/html/bcp38 (Note: This is from May 2000)
Re: IP Spoofing
#10There is no excuse for not securing your network to allow spoofing from it. Most of the big players like leaseweb or ovh do not allow that. But there are some providers that still allow you to spoof source ip address. There should be consensus about droping routes on BGP level to networks that send packets with source ips that they do not announce. It's really simple to drop packets on switches/routers that do not or…
I've also wondered why ISPs don't do more to shut down customers that are participating in a DDOS (at least for DDOS attacks where the source IP isn't spoofed)? I would be very happy if my ISP were to let me know that something on my network is involved in an attack.