Important to note is that the malicious spoofer can also have their own
hacked version of the MDS library. The server side MDS logic is where
the protection needs to be. It needs to be at the level below services
specific handles.
---
** [tickets:#1163] IMM: no verification of handle and msg source correlation**
**Status:** unassigned
**Milestone:** future
**Created:** Wed Oct 08, 2014 04:03 PM UTC by Hans Feldt
**Last Updated:** Wed Nov 26, 2014 10:30 AM UTC
**Owner:** nobody
This is a continuation of https://sourceforge.net/p/opensaf/tickets/938/
Each message received that contains a handle must be verified to be from the
correct mds source to prevent package spoofing.
---
Sent from sourceforge.net because [email protected] is
subscribed to https://sourceforge.net/p/opensaf/tickets/
To unsubscribe from further messages, a project admin can change settings at
https://sourceforge.net/p/opensaf/admin/tickets/options. Or, if this is a
mailing list, you can unsubscribe from the mailing list.
------------------------------------------------------------------------------
Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server
from Actuate! Instantly Supercharge Your Business Reports and Dashboards
with Interactivity, Sharing, Native Excel Exports, App Integration & more
Get technology previously reserved for billion-dollar corporations, FREE
http://pubads.g.doubleclick.net/gampad/clk?id=157005751&iu=/4140/ostg.clktrk
_______________________________________________
Opensaf-tickets mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/opensaf-tickets