4 ms·
Author here. I confirm that OPNSense was vulnerable. It has been fixed in v23.7.1 (August 8, 2023): https://forum.opnsense.org/index.php?topic=35298.0 https://f
by enrico204 3y ago
Author here. I confirm that OPNSense was vulnerable. It has been fixed in v23.7.1 (August 8, 2023): https://forum.opnsense.org/index.php?topic=35298.0 https://forum.opnsense.org/index.php?topic=35298.0
We haven't tested pfSense, but I suppose that they are vulnerable too as they use `pf` and they are FreeBSD-based.
- justsomehnguy 3y agoThanks! Can you clarify, does that works on the forwarded packets? I assume it should, given the vuln in the scrubbing function, but it would help if that would be stated clearly.
- enrico204 3y agoYes, it works on forwarded packets. In the example ruleset in the blog post, `em1` and `em2` are two network interfaces (victim and attacker, think them as LAN and WAN respectively), and the FreeBSD machine is configured as router/firewall.