internal IP address revealed by e-mail

From: Vel (vel_at_sympatico.ca)
Date: 04/28/03

  • Next message: ashwini ajjappa: "project"
    To: <pen-test@securityfocus.com>
    Date: Mon, 28 Apr 2003 11:06:53 -0400
    
    

    HI all,

    question I have is:

    If e-mail header reveals the internal IP address of the sender (10.x.x.x),
    then how can this info be used for mapping the internal network.

    i.e, yes, I can use Firewalk. but the question is how. 10.x.x.x. is
    non-routable Internet address.

    and the Firewalk documentation explains itself by using 10.x.x.x address
    space.

    But if I am on public INternet outside of the victim's firewall DMZ, how can
    issue a command like Firewalk 10.0.0.1 ? I am just going to get Request
    Timed out !

    Any Firewalk gurus out there ?

    thanks.

    ---------------------------------------------------------------------------
    Did you know that you have VNC running on your network?
    Your hacker does.
    Plug your security holes.
    Download a free 15-day trial of VAM:
    http://www.securityfocus.com/StillSecure-pen-test
    ----------------------------------------------------------------------------


  • Next message: ashwini ajjappa: "project"

    Relevant Pages

    • Re: internal IP address revealed by e-mail
      ... There aren't any situations I can think of where you can run firewalk ... network level are the following: ... to gain internal network access. ... across the Internet, even more so if firewalls and proxies are in place. ...
      (Pen-Test)
    • Re: Intermittent Firewall 15108 Events on SBS2003/ISA2004
      ... This newsgroup only focuses on SBS technical issues. ... of |> the internal network object). ... If the ISA server receives a package with an |> internal IP as source address from the external port, the package would be |> treated as a spoof attack. ... |> 825763 How to configure Internet access in Windows Small Business ...
      (microsoft.public.windows.server.sbs)
    • Re: How to get through iptables/NAT, reality and risk calculation
      ... there have been no security issues with the ... # the external interface, and/or the internal one on all ports but 22 tcp ... # so the firewall itself can't talk to anything but the internal network over ... >> accepting traffic from the internet part of an existing connection (with ...
      (Security-Basics)
    • Re: Does ICS or Firewall have a NAT
      ... that a NAT creates a mapping of an intranet ... >>> computers request out to the Internet. ... > I agree that a router is usually better than ICS, ...
      (microsoft.public.windowsxp.network_web)
    • 192.168.x.x oddities
      ... and unrouteable on the Internet. ... from within the internal network. ... Ethical Hacking at the InfoSec Institute. ... Attend a course taught by an expert instructor with years of in-the-field pen testing experience in our state of the art hacking lab. ...
      (Security-Basics)