• February 23, 2025, 06:28:50 AM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: Vulnerability to Older Attack? -- Browse to WAN IP Re-Routed to Internal IP  (Read 4231 times)

jclarkw

  • Level 2 Member
  • **
  • Posts: 93

More paranoia:  I'm trying to determine whether my new DIR-645 is vulnerable to a 2010-vintage attack that easily exposes the router's administrative-login page if the router "routes" traffic sent to its WAN IP, apparently from within the LAN, to its LAN IP (if I understand it correctly).  There's an interesting article on this exploit at "http://www.esecurityplanet.com/views/article.php/3911966/Improve-Network-Security-with-Better-Router-Security.htm.."  The author says, in part,

"It's easy to test if your router is vulnerable to this attack.
You can learn your public IP address at many websites...  Just enter this address into your favorite Web browser and see what happens...
If you get prompted for a userid and password, your router is vulnerable to this type of attack. If you get an error that the Web page can't be loaded, you're safe."

Question:  Do I understand correctly that the recommended test must be executed from a browser **inside** the LAN (in which case my old Linksys BEFSR41 **WAS** vulnerable)?  Or should the test be done from a browser **outside** the LAN (in which case the Linksys was **not** vulnerable)?

Thanks for any clarification of these instructions. -- jclarkw
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting

Yes, input the public IP address into your browser while you are connected on the LAN side of the router and see if you get anything. It should not appear or display the routers log in page. Now if you input the LAN side router IP address, then of course, you should get the routers log in page.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.

jclarkw

  • Level 2 Member
  • **
  • Posts: 93

Yes, input the public IP address into your browser while you are connected on the LAN side of the router and see if you get anything. It should not appear or display the routers log in page.



You are right.  With F/W Ver.: 1.03 at least, this vulnerability does not exist. -- jclarkw
Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting

Probably wasn't there in the shipping version of the FW either.  ::)

Enjoy.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.