RCE via ND6 Router Advertisements in FreeBSD
freebsd.org
RCE via ND6 Router Advertisements in FreeBSD
1–10 of 85 posts
Re: RCE via ND6 Router Advertisements in FreeBSD
#2"PC or computers or hardware that uses OS that consume FreeBSD, has a faulty software for the router's firmware?"
"The router's software performs ad distributions?"
"The version of internet, the router uses, is updated, whereas, the target machine, or the user's machine is still running a old version"
"The security patch works for the modern but not the precursor version?"
"This leaves older systems obsolete in the market?"
"is this a step-by-step instructions to business owners to introduce new products, selling that older products are obsolete" ?
Re: RCE via ND6 Router Advertisements in FreeBSD
#3is my understanding right? "PC or computers or hardware that uses OS that consume FreeBSD, has a faulty software for the router's firmware?" "The router's software performs ad distributions?" "The version of internet, the router uses, is updated, whereas, the target machine, or the user's machine is still running a old version" "The security patch works for the modern but not the precursor version?" "This leaves olde…
If you are a real human, the most interesting question you're bringing up is What about all the appliances backed by FreeBSD? Yes, they are obsolete if they use IPv6 and accept RAs and if they don't get updates.
Re: RCE via ND6 Router Advertisements in FreeBSD
#4Re: RCE via ND6 Router Advertisements in FreeBSD
#5 vulnerable to remote code execution from
systems on the same network segment
Isn't almost every laptop these days autoconnecting to known network names like "Starbucks" etc, because the user used it once in the past?That would mean that every FreeBSD laptop in proximity of an attacker is vulnerable, right? Since the attacker could just create a hotspot with the SSID "Starbucks" on their laptop and the victim's laptop will connect to it automatically.
Re: RCE via ND6 Router Advertisements in FreeBSD
#6is my understanding right? "PC or computers or hardware that uses OS that consume FreeBSD, has a faulty software for the router's firmware?" "The router's software performs ad distributions?" "The version of internet, the router uses, is updated, whereas, the target machine, or the user's machine is still running a old version" "The security patch works for the modern but not the precursor version?" "This leaves olde…
No, I don't think you are understanding this right, but there are some good questions you are asking. Where is the flag button? If you are a real human, the most interesting question you're bringing up is What about all the appliances backed by FreeBSD? Yes, they are obsolete if they use IPv6 and accept RAs and if they don't get updates.
Re: RCE via ND6 Router Advertisements in FreeBSD
#7Re: RCE via ND6 Router Advertisements in FreeBSD
#8Oh that's a nasty one, embedded FreeBSD users will have a hard time mitigating this.
Re: RCE via ND6 Router Advertisements in FreeBSD
#9IPv6 is a prerequisite for the bug to be exploited, it won't affect anyone.
Re: RCE via ND6 Router Advertisements in FreeBSD
#10vulnerable to remote code execution from systems on the same network segment Isn't almost every laptop these days autoconnecting to known network names like "Starbucks" etc, because the user used it once in the past? That would mean that every FreeBSD laptop in proximity of an attacker is vulnerable, right? Since the attacker could just create a hotspot with the SSID "Starbucks" on their laptop and the victim's lapto…
Joking, but not that much :)