Re: 3Com OfficeConnect 812/840 Router DoS exploit code

From: Raistlin (raistlin@gioco.net)
Date: 09/23/01


Message-ID: <00a401c1440f$9382b6e0$01c8a8c0@raistlin>
From: "Raistlin" <raistlin@gioco.net>
To: "BugTraq" <BUGTRAQ@SECURITYFOCUS.COM>
Subject: Re: 3Com OfficeConnect 812/840  Router DoS exploit code
Date: Sun, 23 Sep 2001 11:09:48 +0200


> // 3Com OfficeConnect 812/840 ADSL Router Denial of Service (maybe others)

Filtering port 80 on the WAN interface is enough to prevent this DoS. Port
53 UDP and port 23 telnet are also wide open by default. In fact, this is
(IMHO) a bad symptom of lack of care in security.

As another issue, 3com 812 ADSL routers do NAT. This is great since you plug
in up to 40 PCs and do not have to care very much about settings. However,
the TCP/IP stack of these routers shamelessly uses fixed-increment ISNs on
packets, thus making a connection hijack / spoofing attack fairly simple.
Since they do NAT, every outbound packet suffers of this "carelessness".

I hope that someone from 3com hears us here... since on their whole site
there is NO SECURITY CONTACT whatsoever. This is another bad sign for a
network hardware vendor.

Stefano "Raistlin" Zanero
System Administrator Gioco.Net
public PGP key block at http://gioco.net/pgpkeys



Relevant Pages

  • Re: Network from home to office, etc.
    ... I have an 8 port router at the office ... This entails finding out if those routers have static or dynamic IPs. ... I suggest port 3389 for remote desktop to be your easiest solution. ... (Of course, that assumes Windows XP Professional, Windows 2000 Server ...
    (microsoft.public.windowsxp.work_remotely)
  • Re: Xbox initiates but loses connection
    ... The BEFW11S4 v2 WAP w/ 4 port switch is not a WAP. ... Incompatible Routers ...
    (microsoft.public.windows.mediacenter)
  • Re: "Slap" utility - ethics question
    ... computer network's routers and computers to see ... I wrote Slap ... > However, this may have them re-think their internet security, since that's ... >> I'm behind a broadband router with no DMZ or port forwarding enabled, ...
    (comp.security.firewalls)
  • Re: College ethernet switch problems
    ... We are not concerned about billing because a student pays for the port whether they use it or not because it is built into their room rate. ... We have told students that NAT routers are okay, but NAT routers with the wireless option are not okay. ... It is too complicated to try and explain how to enable wireless encryption on every vendor's broadband wireless router. ...
    (comp.dcom.lans.ethernet)
  • Re: College ethernet switch problems
    ... your sys admins of the DHCP servers have found relevant MAC address prefixes for the popular broadband routers and denied them from obtaining IP addresses. ... If your network admins are smart, then can detect all kinds of anomalies like downstream switches/hubs, broadband routers, wireless APs, etc. ... That port fee is probably for one port, and the network in your building may only be designed to support one host or two hosts per room. ... After being pissed my router no longer worked i turned off its DHCP server to, i thought, make it act as a switch. ...
    (comp.dcom.lans.ethernet)