Re: FreeBSD Security Advisory FreeBSD-SA-15:02.kmem

2015-01-29 Thread Darren Pilgrim
On 1/28/2015 2:46 PM, Joe Holden wrote: Really, how many SCTP users are there om the wild... maybe one? It shouldn't be in GENERIC at the very least! It's used for IP-based telecom backhaul with modern POTS networks and cell networks. It's far better than TCP at handling the vagaries of

Re: FreeBSD Security Advisory FreeBSD-SA-15:02.kmem

2015-01-29 Thread Ian Smith
On Wed, 28 Jan 2015 17:01:50 -0800, jungle Boogie wrote: Hi Nick, On Jan 28, 2015 4:56 PM, Nick Frampton nick.framp...@akips.com wrote: On 29/01/15 08:46, Joe Holden wrote: Really, how many SCTP users are there om the wild... maybe one? It shouldn't be in GENERIC at the very

Re: FreeBSD Security Advisory FreeBSD-SA-15:02.kmem

2015-01-29 Thread Gary Palmer
On Fri, Jan 30, 2015 at 01:20:56AM +1100, Ian Smith wrote: On Wed, 28 Jan 2015 17:01:50 -0800, jungle Boogie wrote: Hi Nick, On Jan 28, 2015 4:56 PM, Nick Frampton nick.framp...@akips.com wrote: On 29/01/15 08:46, Joe Holden wrote: Really, how many SCTP users are there om

Re: FreeBSD Security Advisory FreeBSD-SA-15:02.kmem

2015-01-29 Thread Robert Simmons
Nonsense. Throw out a protocol that is more resistant to Man-In-The-Middle and DDoS attacks due to an implementation bug? This is a protocol that is built on lessons learned from TCP. What should be done is more work improving the implementation and widening the usage and uptake of SCTP. On Thu,

Re: FreeBSD Security Advisory FreeBSD-SA-15:02.kmem

2015-01-28 Thread Mark Andrews
In message 20150128194011.2175b...@hub.freebsd.org, Roger Marquis writes: If SCTP is NOT compiled in the kernel, are you still vulnerable ? No -- we should have mentioned that too. For GENERIC kernel however SCTP is compiled in. Should probably fix that too, in GENERIC, considering

Re: FreeBSD Security Advisory FreeBSD-SA-15:02.kmem

2015-01-28 Thread leon@tuco
+1 and +10 to enable ALTQ in GENERIC in lieu of. On 28/01/2015 20:39, Roger Marquis wrote: If SCTP is NOT compiled in the kernel, are you still vulnerable ? No -- we should have mentioned that too. For GENERIC kernel however SCTP is compiled in. Should probably fix that too, in GENERIC,

Re: FreeBSD Security Advisory FreeBSD-SA-15:02.kmem

2015-01-28 Thread jungle Boogie
Hi Nick, On Jan 28, 2015 4:56 PM, Nick Frampton nick.framp...@akips.com wrote: On 29/01/15 08:46, Joe Holden wrote: Really, how many SCTP users are there om the wild... maybe one? It shouldn't be in GENERIC at the very least! We use Netflow over SCTP in our network monitoring product, so

Re: FreeBSD Security Advisory FreeBSD-SA-15:02.kmem

2015-01-28 Thread Oliver Pinter
Much more, than you explain. Hint: 3G and 4G mobile core networks. ;) On Wed, Jan 28, 2015 at 11:46 PM, Joe Holden li...@rewt.org.uk wrote: Really, how many SCTP users are there om the wild... maybe one? It shouldn't be in GENERIC at the very least! On 28/01/2015 21:19, Mark Andrews wrote:

Re: FreeBSD Security Advisory FreeBSD-SA-15:02.kmem

2015-01-28 Thread Nick Frampton
On 29/01/15 08:46, Joe Holden wrote: Really, how many SCTP users are there om the wild... maybe one? It shouldn't be in GENERIC at the very least! We use Netflow over SCTP in our network monitoring product, so it would be a pain to have to build a custom kernel. Nick -- Founder, CTO

Re: FreeBSD Security Advisory FreeBSD-SA-15:02.kmem

2015-01-28 Thread Joe Holden
Really, how many SCTP users are there om the wild... maybe one? It shouldn't be in GENERIC at the very least! On 28/01/2015 21:19, Mark Andrews wrote: In message 20150128194011.2175b...@hub.freebsd.org, Roger Marquis writes: If SCTP is NOT compiled in the kernel, are you still vulnerable ?

Re: FreeBSD Security Advisory FreeBSD-SA-15:02.kmem

2015-01-28 Thread Roger Marquis
If SCTP is NOT compiled in the kernel, are you still vulnerable ? No -- we should have mentioned that too. For GENERIC kernel however SCTP is compiled in. Should probably fix that too, in GENERIC, considering how little used this protocol is. It is not used much because there is not

Re: FreeBSD Security Advisory FreeBSD-SA-15:02.kmem

2015-01-27 Thread Michael Grimm
On 27.01.2015, at 22:03, Michael Grimm trash...@odo.in-berlin.de wrote: This mail: FreeBSD-SA-15:02.kmem Security Advisory Other Mail: | FreeBSD-SA-15:03.sctp Security Advisory 3) To update your vulnerable

Re: FreeBSD Security Advisory FreeBSD-SA-15:02.kmem

2015-01-27 Thread Xin Li
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 01/27/15 14:42, Mike Tancsa wrote: On 1/27/2015 2:55 PM, FreeBSD Security Advisories wrote: IV. Workaround No workaround is available. If SCTP is NOT compiled in the kernel, are you still vulnerable ? No -- we should have mentioned

Re: FreeBSD Security Advisory FreeBSD-SA-15:02.kmem

2015-01-27 Thread Mike Tancsa
On 1/27/2015 2:55 PM, FreeBSD Security Advisories wrote: IV. Workaround No workaround is available. If SCTP is NOT compiled in the kernel, are you still vulnerable ? ---Mike -- --- Mike Tancsa, tel +1 519 651 3400 Sentex Communications, m...@sentex.net Providing