|
Brought to you by:
Suppliers of:
|
|
|
| |
| A security vulnerability in the way @Home handles IP address assignment (DHCP based) allows attackers to hijack IP addresses of other @Home users by very simple means. |
| |
Credit:
The information has been provided by Roadkill Randu.
|
| |
The @Home network assigns IP addresses on a fairly permanent basis to its subscribers, but it does use DHCP for IP address assignment. It is trivial matter, however, to take over another @Home account's IP address by providing another customer's ID for the hostname parameter in DHCP. It is also trivial to acquire this hostname parameter, since all it requires is 'host @HomeIPaddress' to determine what the customer ID is.
Notification:
@Home has been notified about this problem twice in the last two months, no response has been received.
|
|
|
|
|