Penetration Testing mailing list archives
RE: Ping a mac address
From: "Dario Ciccarone (dciccaro)" <dciccaro () cisco com>
Date: Sun, 4 Dec 2005 16:47:48 -0500
For instance, I have a few IP cameras around myinfrastructure... IfI add a static ARP entry for the MAC to some arbitrary IP(that's still onmy subnet) I can use that arbitrary IP to access the unit's HTTP configuration... works just fine.You're lucky to be facing theses non RFC compliant devices :)))
Agree with Cedric here. Which opens another issue: say your device assigned IP address is 1.2.3.4, MAC A, and the device also allows you to configure access control based on IP address - this would probably allow you to bypass those controls. But - iff the IP stack is so dumb, which source address does it use to reply? The real IP address configured on its interface? Or it just swaps SRC/DST on the original packet? That would allow 2-way communications. Guess it works on Axis cameras at least, if you're able to do the 3-way and actually configure them ;) Dario ------------------------------------------------------------------------------ Audit your website security with Acunetix Web Vulnerability Scanner: Hackers are concentrating their efforts on attacking applications on your website. Up to 75% of cyber attacks are launched on shopping carts, forms, login pages, dynamic content etc. Firewalls, SSL and locked-down servers are futile against web application hacking. Check your website for vulnerabilities to SQL injection, Cross site scripting and other web attacks before hackers do! Download Trial at: http://www.securityfocus.com/sponsor/pen-test_050831 -------------------------------------------------------------------------------
Current thread:
- Re: Ping a mac address, (continued)
- Re: Ping a mac address kuisma (Dec 04)
- Re: Ping a mac address Joshua Shaffer (Dec 03)
- Re: Ping a mac address Maxime Ducharme (Dec 05)
- RE: Ping a mac address John Tavares (Dec 03)
- Re: Ping a mac address rob . dijkshoorn (Dec 04)
- Re: Ping a mac address James Eaton-Lee (Dec 07)
- Re: Ping a mac address mccauley () gmx net (Dec 09)
- Re: Ping a mac address Bob Foxworth (Dec 11)
- RE: Ping a mac address Dario Ciccarone (dciccaro) (Dec 04)
- RE: Ping a mac address Dario Ciccarone (dciccaro) (Dec 05)
- RE: Ping a mac address Dario Ciccarone (dciccaro) (Dec 05)
- Re: Ping a mac address Thor (Hammer of God) (Dec 05)
- Re: Ping a mac address neil (Dec 06)
- Re: Ping a mac address Chris Kuethe (Dec 06)
- Re: Ping a mac address Thor (Hammer of God) (Dec 05)