Detecting CVE-2020-16898

Here is a take at detecting CVE-2020-16898

https://github.com/initconf/CVE-2020-16898-Bad-Neighbor.git

Based of the blog post :

https://www.mcafee.com/blogs/other-blogs/mcafee-labs/cve-2020-16898-bad-neighbor/

While, I am running it on our cluster (s), I don't yet have pcaps to say if this
is getting a hit or not.

Any other feedback, improvements most welcome.

Aashish

Here’s another version:
https://github.com/esnet-security/cve-2020-16898

Installable with zkg install
https://github.com/esnet-security/cve-2020-16898.git

—Vlad

And yet another, we started yesterday and just released :slight_smile:
https://github.com/corelight/CVE-2020-16898

Have referenced both your packages. What a vibrant community.

Ben