Re: [Full-disclosure] Attacking the local LAN via XSS



;) absolutely no worries mate, maybe I wasn't clear enough... I was
referring to home routers. In general I am talking about devices that
have http or https communication channels. This is because of
JavaScript's limitations. Although, by using Java you can do all sorts
of other stuff.

regards

BTW, there are quite a lot cisco devices that have http open on local
LAN vulnerable to IOS HTTP Authorization Vulnerability.

It has been always a matter of security vs. accessibility. This is way weak

On 8/4/06, Thierry Zoller <Thierry@xxxxxxxxx> wrote:
Dear pdp (architect),

pa> xecuted of the border router domain
I'd like to see a "border router" serving images on port 80 ???
Doesn't make sense, really ;) No pun intented.

--
http://secdev.zoller.lu
Thierry Zoller
Fingerprint : 5D84 BFDC CD36 A951 2C45 2E57 28B3 75DD 0AC6 F1C7




--
pdp (architect)
http://www.gnucitizen.org

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Point to Point T1 with Cisco 1841 Routers
    ... checked it in the morning and on my side, the router had a lot of CRC ... interface FastEthernet0/0 ... ip http access-class 23 ... minute output rate 0 bits/sec, 0 packets/sec ...
    (comp.dcom.sys.cisco)
  • Re: [Full-disclosure] Attacking the local LAN via XSS
    ... there are quite a lot cisco devices that have http open on local ... On 8/4/06, Thierry Zoller wrote: ... I'd like to see a "border router" serving images on port 80 ??? ...
    (Bugtraq)
  • Re: Streaming WMS via HTTP on same server as IIS 6.0
    ... I purchased another router. ... Performed the port forwarding for WMS as you described on the second ... Entered WMS and assigned the WMS HTTP Control Protocol to the second ... But still can not stream to work. ...
    (microsoft.public.windowsmedia.server)
  • Re: Trouble configuring Cisco 857, many sites not working
    ... it seems almost as though I can't do an HTTP POST in general across the ... When I plug in my old router, ... Enter configuration commands, one per line. ... temp#no ip inspect name INS.Home cuseeme ...
    (comp.dcom.sys.cisco)
  • XP Pro no http
    ... works, telnet works, just no http in mozilla or in IE6 ... So I figure its a problem with the router. ... So I'm look back to the Toshiba laptop. ... connection, to never connect and to use the existing ...
    (microsoft.public.windowsxp.network_web)