Open thomas-mangin opened 11 months ago
It is possible to create funny rules for flowspec with, for example, a source IP as IPv4 and a destination IP as IPv6.
It is obviously not going to match any packets and should surely be reported to the user when the rule is created.
Should the implementation at the other end not validate input correctly, it may even be able to cause mayhem.
The same can be said about attributes (accepting binary) or updates in general.
It is possible to create funny rules for flowspec with, for example, a source IP as IPv4 and a destination IP as IPv6.
It is obviously not going to match any packets and should surely be reported to the user when the rule is created.
Should the implementation at the other end not validate input correctly, it may even be able to cause mayhem.
The same can be said about attributes (accepting binary) or updates in general.