republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Equipment Support » Hardware By Brand » 2Wire » 2Wire Cross Site Request Forgery Vulnerability
Search Topic:
Uniqs:
17211
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
at&t »
« 2700hg-b trouble configuring to talktalk  
page: 1 · 2
AuthorAll Replies

bjparker

join:2004-09-13
England


2 edits
reply to Oligarchy
Re: 2Wire Cross Site Request Forgery Vulnerability

I've probably started a very red herring here! A little knowledge is a dangerous thing!

I'll tell you the story now because it seems to have vanished.

I recently installed Pidgin because I became fed-up with the connection diarrhoea from Yahoo IM. My software firewall was in learning mode and learnt to allow Pidgin to connect to 239.255.255.250 . When I pinged this address the router responded, despite having it's address set to 192.168.n.m and no router DNS or DHCP. Then I checked and found it to be a IP multicast address only, and found it would not accept http when I tried.

I did wonder whether Pidgin used broadcast mode to do its UPnP bit of opening ports. My ignorance is total in this area.

Now I can't replicate the behaviour! I can't even ping that address!

Apologies for winding you all up about it, it really was not intentional.

EDIT - Aha! I view some video on youtube and lo:

Pinging 239.255.255.250 with 32 bytes of data:

Reply from 192.168.n.m: bytes=32 time=1ms TTL=255

Reply from 192.168.n.m: bytes=32 time=1ms TTL=255

Reply from 192.168.n.m: bytes=32 time=1ms TTL=255

Reply from 192.168.n.m: bytes=32 time=1ms TTL=255

Ping statistics for 239.255.255.250:

Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 1ms, Maximum = 1ms, Average = 1ms

Note that I've edited my router address.

koolkid1563
Premium,MVM
join:2005-11-06
Powell, WY
clubs:
Is n.m the default 1.254, or is it whatever IP you have moved the 2wire to?

sodagreen

join:2007-01-13
Taiwan
reply to Oligarchy
Here are AT&T's instructions on how to verify you have been patched and are secure. »helpme.att.net/article.php?item=11659

remarc

join:2007-08-10
Philippines
well... finally, a new patch. its loong been overdue. lolz!


jr9730

join:2000-11-22
Torrance, CA
reply to Oligarchy
Chances are its been on your 2Wire for weeks to months by now without you knowing it.. : )
Forums » Equipment Support » Hardware By Brand » 2Wireat&t »
« 2700hg-b trouble configuring to talktalk  
page: 1 · 2


Wednesday, 02-Dec 20:51:31 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [161] Comcast Releasing Promised Usage Meter
· [93] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [79] Latest Consumer Reports Survey Not Kind To AT&T
· [70] Baltimore To Ban Lazy Cable Installs
· [62] Broadband Killed The Game Console
· [54] Rogers Unveils The ISP Dream Model
· [46] ACTA: Global Three Strikes
· [41] Rural Carriers Quickly Embracing Fiber
· [38] Charter Exits Chapter 11
· [38] AT&T, Verizon Drop 3G Ad Dispute
Most people now reading
· False positive in Avast! or is it real? [Security]
· MS admits Windows Updates principally created to annoy [Security]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· Quality/longevity of 15A 120V receptacles [Home Repair & Improvement]
· [Newsgroups] Newzleech down? [Filesharing Software]
· Poll: Have you ever been charged an overage fee since ... [TekSavvy]
· 16% packet loss. damn dsl. los angeles [AT&T West]
· Ooma changing features [VOIP Tech Chat]
· Furnace starts, then shuts off. [Home Repair & Improvement]