© SANS Institute 2000 - 200
5
, Author retains full rights.
Key fingerprint = AF19 FA27 2F94 998D FDB5 DE3D F8B5 06E4 A169 4E46
Key fingerprint = AF19 FA27 2F94 998D FDB5 DE3D F8B5 06E4 A169 4E46
© SANS Institute 2000 - 200
5
Author retains full rights.
27
etin/MS01-009.asp
or install service Pack 6a or migrate to Windows 2000.
Another possible work around is to try to
filter GRE packets by their
source
address at your perimeter, only allowing traffic from known addresses.
However, since GRE
is a connectionless protocol,
source address spoofing is
trivial. There are a number of tools and sites
describing how to abuse any
networks that allow any kind of GRE traffic. If
an attacker can guess what
source
addresses are allowed, the attacker can simply
send packets with the
allowed source IP forged and bypass the filtering.
Do'stlaringiz bilan baham: