Vulnerability Development mailing list archives

Disclosure of internal ip address of a Yahoo! Messenger user


From: "Onie Camara" <neil () restricted dyndns org>
Date: Tue, 11 Jun 2002 01:07:33 -0500

hi guys,

Yahoo Messenger and Outpost Firewall discloses the internal/private ip
address
of the other party.

I consider this as a security warning. I installed Outpost Firewall on my
Win2k.
Now, Outpost Firewall gives me a prompt to connect to the other party's
internal
ip address and not the global routable NATed address. I have verified these
from 3 different connections and found out that OutPost discloses the
internal
ip address of Yahoo messenger.


neil (neil () restricted dyndns org) - cc{na|sa}, mcse - pgp 0x777777B2
network/security engineer - dl := +1(847)2.21.0.224 cn := +1(847)9.80.17.53
echo "I love windows" | sed -e 's/wi/u/g' | cut -f1 -dd | \
awk '/u/ {printf("%s %s %six\n",$1,$2,$3)}'



Current thread: