UDP/123 policers & status

Saku Ytti saku at ytti.fi
Mon Mar 30 08:27:59 UTC 2020


On Mon, 30 Mar 2020 at 11:15, Harlan Stenn <stenn at nwtime.org> wrote:

> Please help me understand this.
>
> Exactly how bad is it if the query and response packets are of a
> different size?  Does it matter at 4 bytes?  32?

Presumably, if it's attenuation vector (1byte or more), presumably
attacker will use any of the other many vectors which are
amplification vectors or will directly attack from the zombie machines
they pwn. Since NST would have negative ROI on attack if there is
_any_ attenuation.

-- 
  ++ytti



More information about the NANOG mailing list