TIP: Click on subject to list as thread! ANSI
echo: nthelp
to: Robert Comer
from: Paul Ranson
date: 2005-03-09 16:14:52
subject: Re: Real or bogus

From: "Paul Ranson" 

It uses a Java applet to determine your local IP address. No Java, no address.

The applet posts the local address back to the server, so now they know too.

I don't see how exposing a local, but unreachable, IP address is a
vulnerability. I also don't see any need for Java. Problem solved.

Paul

"Robert Comer"  wrote in
message news:422f0de9{at}w3.nls.net...
> It doesn't show my internal IP address, it just shows my router's external
> IP address.
>
> - Bob Comer
>
> "Gregg N"  wrote in message
> news:Xns9614AF6BC6B6gregginvalidinvalid{at}216.144.1.254...
>> Could someone behind a NAT firewall visit this site and see if it reveals
>> your private (192.168.x.x) IP address? It shows mine (both IE and FF),
>> but
>> I haven't investigated to see if it is actually revealing a security
>> vulnerability. I suspect the address is being generated and displayed
>> locally by whatever script is running on the page.
>>
>> http://www.auditmypc.com/whats-my-ip.asp
>>
>> Gregg
>
>

--- BBBS/NT v4.01 Flag-5
* Origin: Barktopia BBS Site http://HarborWebs.com:8081 (1:379/45)
SEEN-BY: 633/267 270 5030/786
@PATH: 379/45 1 106/2000 633/267

SOURCE: echomail via fidonet.ozzmosis.com

Email questions or comments to sysop@ipingthereforeiam.com
All parts of this website painstakingly hand-crafted in the U.S.A.!
IPTIA BBS/MUD/Terminal/Game Server List, © 2025 IPTIA Consulting™.