arp_ignore: Add reference to 2024-12-10 Mullvad VPN audit details

This commit is contained in:
raja-grewal 2024-12-12 06:36:47 +00:00 committed by GitHub
parent 412b371e85
commit c116796854
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -467,6 +467,9 @@ net.ipv6.conf.*.accept_redirects=0
## Reduces IP spoofing attacks by limiting the scope of allowable ARP responses. ## Reduces IP spoofing attacks by limiting the scope of allowable ARP responses.
## ##
## https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf ## https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf
## https://github.com/mullvad/mullvadvpn-app/blob/main/audits/2024-12-10-X41-D-Sec.md#mllvd-cr-24-03-virtual-ip-address-of-tunnel-device-leaks-to-network-adjacent-participant-severity-medium
## https://github.com/mullvad/mullvadvpn-app/pull/7141
## https://www.x41-dsec.de/static/reports/X41-Mullvad-Audit-Public-Report-2024-12-10.pdf
## ##
#net.ipv4.conf.*.arp_ignore=2 #net.ipv4.conf.*.arp_ignore=2