[Commotion-admin] [avahi-client] Modify the avahi-client or avahi daemon to disallow name changes to avoid mDNS poisoning (#1)

areynold notifications at github.com
Tue Sep 10 20:57:44 UTC 2013


The mDNS protocol and security strongly relies on a trusted local network. Both race conditions and name poisoning exist within the RFC implementation. iSEC recommends not resolving name conflicts as outlined with in Section 9 "Conflict Resolution" of RFC 6762. Each Commotion Mesh router should have a unique mDNS name by default and not allow malicious mesh nodes to force mDNS name
changes by triggering collisions.

---
Reply to this email directly or view it on GitHub:
https://github.com/opentechinstitute/avahi-client/issues/1
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.chambana.net/pipermail/commotion-admin/attachments/20130910/f8d30c23/attachment.html>


More information about the Commotion-admin mailing list