<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>JunOS on rob.sh</title>
    <link>https://rob.sh/tags/junos/</link>
    <description>Recent content in JunOS on rob.sh</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 08 Jan 2010 07:55:37 +0000</lastBuildDate>
    <atom:link href="https://rob.sh/tags/junos/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Juniper PSN-2010-01-626 (AS4 Again!)</title>
      <link>https://rob.sh/post/180/</link>
      <pubDate>Fri, 08 Jan 2010 07:55:37 +0000</pubDate>
      <guid>https://rob.sh/post/180/</guid>
      <description>&lt;p&gt;I&amp;rsquo;ve had a couple of mails relating to this PSN, which again references the research that Andy Davidson, Jonathan Oddy and I did last year. It seems that some of the sources of the initial mailing list posts we made are gone (particularly the merit.edu one that is referenced from both Juniper&amp;rsquo;s site and most other places). For that reason, I&amp;rsquo;ve included both the mails that we sent to NANOG/C-NSP/J-NSP last year here.&#xA;&lt;br&gt;&lt;br&gt;&lt;div align=&#34;center&#34;&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>32-bit AS numbers introduce a new BGP flaw.</title>
      <link>https://rob.sh/post/175/</link>
      <pubDate>Mon, 19 Jan 2009 20:23:59 +0000</pubDate>
      <guid>https://rob.sh/post/175/</guid>
      <description>&lt;p&gt;Last Friday, &lt;a href=&#34;http://www.andyd.net&#34;&gt;Andy Davidson&lt;/a&gt;, Jonathan Oddy, and I pushed out &lt;a href=&#34;http://www.merit.edu/mail.archives/nanog/msg14345.html&#34;&gt;some research&lt;/a&gt; that has some quite worrying repercussions. Whilst I&amp;rsquo;ve heard from a lot of people privately about this matter, there&amp;rsquo;s a big flaw here, and as Andy &lt;a href=&#34;http://www.andyd.net/index.php/2009/01/17/asn32-asn4-internet-broken/&#34;&gt;posted on his blog&lt;/a&gt; (which is much more informative than mine, I think!), this is a big problem.&lt;br&gt;&lt;br&gt;&#xA;The reason, I think, that we&amp;rsquo;re getting limited public discussion of this exploit (I hesitate to call it an exploit, it&amp;rsquo;s a flaw really, because it&amp;rsquo;s actually a result of the RFC that the problem exists), is because the implementations of 4-byte AS support that are out there already are generally not standards compliant. Let&amp;rsquo;s run down the list:&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
