RFC 3620:The TUNNEL Profile
RFC-Ref

attack


Click on the red underlined text to get to the source

... proxy could mount a "man in the middle" attack if public key infrastructure is not deployed. ...
... source route to reach the desired service. This can prevents two attacks: o Attackers ...
... attacks: o Attackers sniffing packets on one side of the firewall cannot see IP addresses ...
... firewall; and, o Attackers cannot exhaustively attempt to connect to many FQDNs or IP addresses ...
... routing and use the error messages as an indication of whether the queried machine exists. For this attack to be prevented, the proxy must allow only "profile ...
... connections, always refusing to even attempt source-routed connections. This latter attack can also be thwarted by requiring a SASL identification before allowing a TUNNEL ...



Google
Web
RFC-Ref