ipv4: add option to drop unicast encapsulated in L2 multicast
In order to solve a problem with 802.11, the so-called hole-196 attack,
add an option (sysctl) called "drop_unicast_in_l2_multicast" which, if
enabled, causes the stack to drop IPv4 unicast packets encapsulated in
link-layer multi- or broadcast frames. Such frames can (as an attack)
be created by any member of the same wireless network and transmitted
as valid encrypted frames since the symmetric key for broadcast frames
is shared between all stations.
Additionally, enabling this option provides compliance with a SHOULD
clause of RFC 1122.
Signed-off-by:
Johannes Berg <johannes.berg@intel.com>
(cherry picked from commit fbe66ad7c46e98a3edaf426422c9030d1a3c8072)
Change-Id: I41b292ec33901b58b49859bc6b144f29257d5cc5
Loading
Please register or sign in to comment