cisco IOS bug/exploit?

Mark Mentovai mark-list at mentovai.com
Mon Aug 20 15:26:20 UTC 2001


Barton F Bruce wrote:
>There is a chance that you have a static for 0.0.0.0 0.0.0.0 to eth0 or
>something like that even though the other end may be the only thing on the
>ethernet. DON'T do that!
>
>The router will arp for every address it needs to get to.
>With codered around, that can be bad.
>
>Use a static default to a real ip address.

Use "no ip proxy-arp" (you should all be doing this anyway).  With proxy ARP
disabled, a default route to an ethernet interface won't work unless
0.0.0.0/0 really is connected at layer 2.

>There is somthing on CCO about this.

http://www.cisco.com/warp/public/63/ts_codred_worm.shtml

Mark




More information about the NANOG mailing list