Re: Req: info on IP range popup ad software supposedly called "Extreme Marketing"

From: LXIX (post_replys_please@this.address.is.invalid)
Date: 12/31/02


From: "LXIX" <post_replys_please@this.address.is.invalid>
Date: Tue, 31 Dec 2002 02:05:19 GMT

Rich wrote:
> "Joe Schmoe" <nomail@forme.com> wrote in message
> news:pan.2002.12.31.01.05.40.224115@forme.com...
>> On Tue, 31 Dec 2002 00:33:01 +0000, LXIX wrote:
>>
>>> Joe Schmoe wrote:
>>>> On Mon, 30 Dec 2002 21:07:35 +0000, Todd Knarr wrote:
>>
>> <snipped>
>>>> Let's say a spammer has a cable modem and his IP is 66.186.5.20 and his
>>>> ISP is filtering packets and dropping illegal addresses. All he has to
>>>> do is to spoof the IP with a valid one say 66.186.5.21, it is a legal
>>>> address that will pass the filter but not point back to him.
>>>
>>> That won't work if the router is configured properly. It's going to see
>>> an inbound packet from the internet side
>> <snipped>
>>
>> Why would it be inbound? I'm talking about generating a valid IP that
>> exists within your own subnet that will pass an outbound filter. The
>> machine generating the packet AND the spoofed IP are both on the same
>> subnet controlled by the same router.
>>
>> Joe
>>
>
> To leave the subnet under another IP the client PC would either have to
> generate an ARP packet or it would have to use the same MAC as the existing
> IP address they intend to use. The former is not possible if the ARP table
> is manually hard-coded or controlled by an external add-on device (can be
> done with some SNMP-based products). The latter might work though.

Yea. My bad, I parsed the question wrong. However, in terms of cable modems
it still shouldn't work. Unless the modem knows your MAC and has assigned an IP
it won't route packets out. Not sure about DSL though.

FWIW, the Linksys BEFSX41 will let me change the "outside" MAC address.
Been toying with changing it to some sort of real old Sperry system. :)
http://www.cavebear.com/CaveBear/Ethernet/vendor.html

For some reason I was still fixated on the spoofing inbound.

I blame it on lack of coffee. yea..
--LXIX--



Relevant Pages

  • Re: gateway IP address
    ... Ethernet is Layer 2, IP is Layer 3. ... Layer 2 uses MAC address, and Layer 3 uses IP address. ... send the Ethernet frame to the router, so that it can pass it to the device ... the packet to the router. ...
    (comp.dcom.sys.cisco)
  • Re: Would a firewall have protected Jammie Thomas from being sued by the RIAA Safenet
    ... As most LAN are ethernet nowdays you'll find them ... a MAC address is not part of the routed IP packet. ... original frame which arrived at the router is not visible anymore. ...
    (comp.security.firewalls)
  • Re: Pure IP & ARP broadcasts
    ... It actually communicates via the MAC address of the Nics (aka Layer2 ... what the ARP request does. ... A host has a packet to send, it has the IP# and nothing else. ... But if the owner of the IP# is not on that segment then the Router replies ...
    (microsoft.public.windows.server.networking)
  • 6.x, 4.x ipfw/dummynet pf/altq - network performance issues
    ... Without a specific pf or ipfw rule to deal with a packet the box would fall over, with specific block rules it would manage an extra 30-40mbps and then fall over. ... UDP floods are much better handled - an ipfw block rule for the packet type and the machine responds as if there were no flood at all. ... Inbound floods appear to cause ALL inbound traffic to lag horrifically, which inherently causes a lot of outbound loss due to broken TCP. ...
    (freebsd-net)
  • 6.x, 4.x ipfw/dummynet pf/altq - network performance issues
    ... Without a specific pf or ipfw rule to deal with a packet the box would fall over, with specific block rules it would manage an extra 30-40mbps and then fall over. ... UDP floods are much better handled - an ipfw block rule for the packet type and the machine responds as if there were no flood at all. ... Inbound floods appear to cause ALL inbound traffic to lag horrifically, which inherently causes a lot of outbound loss due to broken TCP. ...
    (freebsd-questions)