Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Zyxel / Netgear and probably other routers leaking information. |
|---|---|
| Date: | 31 Jan 2005 13:31:56 -0000 |
Hi! I have discovered a serious problem with the following routers: Zyxel P310, P314, P324 and Netgaear RT311, RT314 all with the latest firmware available as of 2005-01-20. I think that the problem is present in all routers using Zynos, but I am not sure. Let say you have a Computer with IP: 192.168.0.50 connected to the WAN side of a router that has 192.168.1.1 on WAN and 192.168.0.1 on the LAN side. If I send a ping to 192.168.0.1 (LAN on router) then I get request timed out, but if I look in my arp cache I will see this: 192.168.0.1 xx-xx-xx-xx-xx-xx where xx-xx-xx-xx-xx-xx is the mac address of the WAN side. So the result must be that if I send a packet with the same destination IP as the routers LAN IP, I will get an ARP reply from the WAN side. This can be used to get information about which IP adresses are used on the LAN side when you are sitting on the WAN side. It is also possible to pollute the ARP cache on your ISPs equipment by changing the IP adress on your lan side. Zyxels response to this is that we have choosen the wrong equipment (I agree :-) they told me to use VLAN as a workaround. /Jens
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [PersianHacker.net] Full Path Disclosure and PHP Injection In Pafiledb 3.1 Final, Pedram hayati |
|---|---|
| Next by Date: | New Whitepaper available on security best practices, Gunter Ollmann |
| Previous by Thread: | [PersianHacker.net] Full Path Disclosure and PHP Injection In Pafiledb 3.1 Final, Pedram hayati |
| Next by Thread: | New Whitepaper available on security best practices, Gunter Ollmann |
| Indexes: | [Date] [Thread] [Top] [All Lists] |