Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 03 Apr 2015 14:41:58 +0200
From:      Hans Petter Selasky <hps@selasky.org>
To:        Gleb Smirnoff <glebius@FreeBSD.org>
Cc:        Mateusz Guzik <mjguzik@gmail.com>, Ian Lepore <ian@freebsd.org>, svn-src-all@freebsd.org, src-committers@freebsd.org, "Robert N. M. Watson" <rwatson@FreeBSD.org>, svn-src-head@freebsd.org
Subject:   Re: svn commit: r280971 - in head: contrib/ipfilter/tools share/man/man4 sys/contrib/ipfilter/netinet sys/netinet sys/netipsec sys/netpfil/pf
Message-ID:  <551E8A96.6030806@selasky.org>
In-Reply-To: <20150403112927.GQ64665@FreeBSD.org>
References:  <551DA5EA.1080908@selasky.org> <551DAC9E.9010303@selasky.org> <358EC58D-1F92-411E-ADEB-8072020E9EB3@FreeBSD.org> <551DEF26.4000403@selasky.org> <4B7DAA59-389F-41AE-99D8-034A7AA61C99@FreeBSD.org> <551E520E.1040708@selasky.org> <6DF5FB51-8135-4144-BD3A-6E4127A23AA7@FreeBSD.org> <551E5C38.7070203@selasky.org> <78DD67BD-621C-451D-8E30-EC9BF396716F@FreeBSD.org> <551E6E72.8050208@selasky.org> <20150403112927.GQ64665@FreeBSD.org>

next in thread | previous in thread | raw e-mail | index | archive | help
On 04/03/15 13:29, Gleb Smirnoff wrote:
> On Fri, Apr 03, 2015 at 12:41:54PM +0200, Hans Petter Selasky wrote:
> H> "ip_do_randomid" is zero by default, and is not documented anywhere:
> H>
> H> grep -r ip_do_randomid share/
>
> It is documented in inet(4).
>
> The actual sysctl knob doesn't match the kernel symbol name, which is
> allowed in sysctl(9).
>

Hi,

Will you mind if I rephrase that paragraph in the "inet.4" manual page from:

"This closes a minor information leak which allows remote observers to
determine the rate of packet generation on the machine by watching the
counter."

Into:

"This prevents high-speed information exchange between internal and 
external observers using packet frequency modulation. An outside 
observer can ping the outside facing port at a fixed rate watching the 
counter. An inside observer can ping the inside facing port watching the 
same counter. Even though packets don't flow between the two ports, data 
can be exchanged by watching changes in the packet rate. It is believed 
that data can be exchanged in Kb/s range this way. Setting this sysctl 
also prevents remote and internal observers to determine the rate of 
packet generation on the machine by watching the counter."

--HPS



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?551E8A96.6030806>