FreeBSD Security Advisory FreeBSD-SA-03:14.arp

Michael Sierchio kudzu at tenebras.com
Wed Sep 24 09:27:14 PDT 2003


Ruslan Ermilov wrote:
> On Wed, Sep 24, 2003 at 07:44:26AM -0700, Michael Sierchio wrote:
> 
>>FreeBSD Security Advisories wrote:
>>
>>
>>>IV.  Workaround
>>>
>>>There is no known workaround at this time.
>>
>>Using static ARP entries and turning off ARP on the interface
>>should be a workaround.  Whether this is remotely feasible
>>depends on your situation.
>>
> 
> I still have not committed the code that supports static ARP
> on an interface -- there's currently no way to do static ARP
> only, if you disable ARP on an interface it will be disabled
> in its whole.

I'm puzzled by this -- you mean when I see

wi0: flags=88c3<UP,BROADCAST,RUNNING,NOARP,SIMPLEX,MULTICAST> mtu 1366

it's just *kidding* about the NOARP flag?  IOW the NOARP flag
changes the output of ifconfig, and that's it?






More information about the freebsd-security mailing list