Security Basics mailing list archives
Re: Company Firewall's IP Address
From: "Chip McClure" <vhm3 () io gigguardian com>
Date: Wed, 13 Nov 2002 13:19:13 -0800 (PST)
tony tony said: This is quite easy to do, and in no way is a vulnerability in your firewall. Bonzi does this to attempt to generate sales, using an environmental variable of the web server (which in this case, is your IP address) and implants that in a dynamically generated script which shows your IP. The only places you're broacasting your IP to, would be in whatever sites that you visit, in their server logs. Chip ----- Chip McClure Sr. Unix Administrator GigGuardian, Inc. http://www.gigguardian.com/ -----
I was doing security research on the internet at work yesterday....when all of a sudden I got a pop up advertisement that stated that I was broadcasting my IP address to the entire internet. It then showed a screen with my IP address which was the the external IP interface of one of our companies firewalls. It just bothers me that someone would be able to determine the IP address of our firewall that easily. It seems to me that our firewall should operate in a more stealth mode. Our firewall administrator said it is not technically possible to do this. What is your take? I am not a checkpoint firewall guru so I do not know. All I know is that if I was a hacker, I would love to hammer away on an ip address that represented a firewall. Click on the following to learn more about this pop up site. http://www.bonzi.com/internetalert/ia99m.asp __________________________________________________ Do you Yahoo!? U2 on LAUNCH - Exclusive greatest hits videos http://launch.yahoo.com/u2
Current thread:
- Re: Company Firewall's IP Address, (continued)
- Re: Company Firewall's IP Address Eric Balsa (Nov 14)
- Re: Company Firewall's IP Address Mike Dresser (Nov 14)
- RE: Company Firewall's IP Address Bill Lavalette (Nov 14)
- Re: Company Firewall's IP Address David J. Bianco (Nov 14)
- Re: Company Firewall's IP Address Bill Hamel (Nov 16)
- Re: Company Firewall's IP Address Igor' Spivak (Nov 14)
- Re: Company Firewall's IP Address John Jasen (Nov 15)
- RE: Company Firewall's IP Address Rick Darsey (Nov 15)
- Re: Company Firewall's IP Address Steve Cooper (Nov 15)
- Re: Company Firewall's IP Address Bradley D. Moore (Nov 17)
- Re: Company Firewall's IP Address Chip McClure (Nov 15)
- RE: Company Firewall's IP Address John Tolmachoff (Nov 16)
- RE: Company Firewall's IP Address Daniel R. Miessler (Nov 16)
- RE: Company Firewall's IP Address Leonard.Ong (Nov 13)
- Re: Company Firewall's IP Address Meritt James (Nov 13)
- RE: Company Firewall's IP Address Bruce Fowler (Nov 15)
- Re: Company Firewall's IP Address Eric Schroeder (Nov 15)
- Re: Company Firewall's IP Address Ivan Coric (Nov 16)
- Re: Company Firewall's IP Address Meritt James (Nov 16)
- Re: Company Firewall's IP Address Bill Hamel (Nov 15)
- Re: Company Firewall's IP Address Meritt James (Nov 16)
- Re: Company Firewall's IP Address Bill Hamel (Nov 15)
(Thread continues...)
