ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Emerging tech Toolkit

Hackers may be snooping on you - Broadband scare

Published: 12 Aug 1999 11:43 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

That's the danger highlighted in a security advisory released on Wednesday by hacker-cum-security specialists L0pht Heavy Industries. The flaw affects Windows 95, 98 and 2000 as well as the SunOS and Solaris 2.6 running a network service known as the ICMP router discovery protocol, or IRDP, that determines the route computers use to connect to the Internet.

The result: An unauthorised user can intercept outgoing information, possibly modify unencrypted or lightly encrypted data, or deny service to the network. Except for the denial of service attack, the malicious programmer needs to be inside the network, stated the advisory. For cable modem users, however, an internal user could be anyone on the local loop -- a neighbour or someone on the next block. Since many cable-modem-based networks use the rerouting technology, users are left open to someone snooping their communications to the Internet.

In essence, another computer on the same network can be used to change the default path that packets take out to the Internet. By placing the address of their own server in the system, an attacker can look at all the outgoing packets of information.

While it's a bit of a one-sided conversation -- since incoming packets enter the network normally -- a great deal of information can be gleaned from the outgoing packets, possibly including passwords and credit cards numbers. The most worrisome part of the flaw on Microsoft Windows is that the operating system continues to be vulnerable even when the user believes they have closed the hole.

In a move long considered controversial, L0pht has decided to release the source code to the basics of a program that could exploit such a hole. However, L0pht did delay the release of the advisory at Microsoft's request, said one L0pht member, known by his handle Space Rogue, in an e-mail.

Microsoft and Sun Microsystems Inc. declined to offer comment while members of L0pht could not be contacted.

Take me to the ADSL Special

Take me to Hackers

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
68 out of 97 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:















Discussions

andyraff99 andyraff99

Questions regarding IT services

Saturday 6 September 2008, 5:46 PM

1 post
182706 182706

dont forget fixed wireless

Saturday 6 September 2008, 5:21 PM

2 comments
ysridhar ysridhar

poweredge

Saturday 6 September 2008, 3:59 PM

1 post
Tezzer Tezzer

Perennial or Hardy Annual?

Saturday 6 September 2008, 3:15 PM

3 comments

Blog Posts

Avatar Xwindowsjunkie

Billy & Jerry

Saturday 6 September 2008, 4:04 PM

0 comments
Avatar Richard A Johnson

CKS in Administration

Saturday 6 September 2008, 1:26 PM

0 comments
Avatar nico5038

The Experts-Exchange cash cow

Saturday 6 September 2008, 3:01 AM

0 comments
Avatar roger andre

Prozone, Vertigo And Captivity.

Friday 5 September 2008, 4:53 PM

0 comments

Featured Talkback

While full medical records may be of (dubious) value at rear/base medical facilities, these could be provided much simpler by either physical disk or electronic transfer to an "in theatre" database for individuals posted in. That £80m (and it's associated running costs) could have been far better employed in resuscitating a disbanded infantry battalion or providing a big boost in equipment quality and quantity.

By: 1000215420

Read full story:
Photos: MoD unveils £80m IT health programme