RE: Privacy leak while surfing

From: Golden_Eternity (bhodi_jabir@yahoo.com)
Date: 04/25/02


From: "Golden_Eternity" <bhodi_jabir@yahoo.com>
To: "Kai Kretschmann" <K.Kretschmann@security-gui.de>, <vuln-dev@securityfocus.com>
Date: Thu, 25 Apr 2002 08:43:55 -0700


> I noticed a lot of netbios name service broadcast from different windows
> workstations for name resolution requests of various webserver names. It
> seems that the IE tries to resolve normal internet domain names
> using local netbios ways in addition to the configured DNS.

That's the standard search order for Windows; it checks lmhosts, WINS, hosts
and DNS (not necessarilly in that order, its been a while since my MS TCP/IP
class).

> Now I can all see surfed domain names with the requesting client
> IP without spoofing anything, simply watch the broadcasts coming along.

You could just as easilly get that information from watching DNS traffic.
Also, web requests include the domain name (otherwise virtual hosts wouldn't
work) so you can just monitor HTTP and get everything you want.

If you are on the local network (or along the path of travel) anything that
isn't encrypted is fair game.

-G_E



Relevant Pages

  • Re: Windows Update & System restore
    ... history" on the windows update page still lists the update. ... "phantom usage" relating to the unused portions of memory allocation ... the memory allocation requests that are issued by Windows components, ...
    (microsoft.public.windowsxp.general)
  • Re: Multimedia Timer
    ... First, as already observed, WIndows is *not* a real-time system, and 20ms events are ... Does the recipient of the serial port data need to receive one "chunk" ... delete buffer; ... That's because I need those 20ms delay between two requests. ...
    (microsoft.public.vc.mfc)
  • Re: why getstore cant work, especially for store xml file on freebsd
    ... >> It works well on windows platform, but doesn't on freebsd. ... > server with 1,000 requests in a way you aren't when issueing the same ...
    (perl.beginners)
  • Re: [fw-wiz] SANS Top Ten and Commercial Firewalls
    ... IIS malicious requests for cmd.exe and sample files ... Null netbios access ... netbios proxy, though, but it is not ready yet. ... Malicious HTTP responses exploiting IE defects. ...
    (Firewall-Wizards)
  • Re: FS Minifilters to sync with remote server
    ... Windows 2k/XP/2k3 Filesystem and Driver Consulting ... I'd set a reparse point. ... create and close requests and somehow communicate with some user-mode code ...
    (microsoft.public.development.device.drivers)