Technical Discussion
  >> Security Related Issues


Register (or login) on our website and you will not see this ad.


These posts have been archived and can no longer be replied to or modified.
  Print Thread
Standard User Sandgrounder
(knowledge is power) Wed 04-Aug-10 01:07:15
Print Post

Web attack knows where you live


[link to this post]
 
BBC News item - Creepy crazy



Line One:- Zen - DrayTek Vigor 2600VG
Line Two:- EntaNet - DrayTek Vigor 2600
Standard User deleted
(deleted) Wed 04-Aug-10 01:16:25
Print Post

Re: Web attack knows where you live


[re: Sandgrounder] [link to this post]
 
Creepy indeed. I'd like to know more but for obvious reasons the article doesn't quite tell all smile

I thought that an IP address by itself, which is interrogatable by a website at the server end, can locate a user within a reasonably small area.

But the database of MAC addresses would seem to serve no useful, realistic purpose other than for this exploit. Why on earth was that data captured and more to the point, what's it doing being made publicly available?
Standard User camieabz
(legend) Wed 04-Aug-10 02:04:27
Print Post

Re: Web attack knows where you live


[re: deleted] [link to this post]
 
Wait for the bogus warnings from kiddies pretending to be big:

"I know where you live!"

Yup, then you have to sail an ocean, or drive hundreds of miles, and then you have to go through lots of other little obstacles, such as doors, guard dogs, alarm systems and the person at the other end could built like a tank.

No, I don't think it's going to be a hit with the scrawny little armchair warriors. wink

Not great if combatting organised crime though. Maybe we should rotate our MAC addys or places of residence. smile


Register (or login) on our website and you will not see this ad.

Standard User deleted
(deleted) Wed 04-Aug-10 08:27:20
Print Post

Re: Web attack knows where you live


[re: deleted] [link to this post]
 
Yeah that is what it is using the mac address table that has been harvested by Streetview.

When they have been round photoing the streets they have also scanned wireless networks and recorded all of the information, they've come under fire for it but have said its nothing illegal.

What I'm not sure is how they get your routers mac address from its ip address that would usually only be available from your ISP's RADIUS server/routers so there must be an exploit via the router.

Anyway, blame Google idiots
Standard User deleted
(deleted) Wed 04-Aug-10 08:54:38
Print Post

Re: Web attack knows where you live


[re: Sandgrounder] [link to this post]
 
Isn't this just an update from his earlier cross site scripting exploit, meaning for it to work you would need to be logged into your router admin at the same time as visiting the booby-trapped website?

or using the other method, would need to know (or find) the ip of the router and hopefully login with default password?

and surely it's the WLAN (wireless) MAC database that's being used, not the ethernet one.
Standard User deleted
(deleted) Wed 04-Aug-10 09:15:29
Print Post

Re: Web attack knows where you live


[re: deleted] [link to this post]
 
In reply to a post by user101:
and surely it's the WLAN (wireless) MAC database that's being used, not the ethernet one.


Depends whether your browsing via wireless at the time I guess, if so it will all tie up nicely.

Google info:- http://googlepolicyeurope.blogspot.com/2010/04/data-...
  Print Thread

Jump to