Re: Hijack IP Address using cable modem

From: Marcin Dawcewicz (mivat_private)
Date: Mon Apr 30 2001 - 10:40:47 PDT

  • Next message: russi: "Re: Hijack IP Address using cable modem"

    On Wed, 30 Apr 1997, inigma_x wrote:
    
    >     I have a few questions about accessing the cable modem. I'm having
    > trouble making any kind of connection with my Toshiba (PCX 1100) DOCSIS
    > cable modem. After the modem grabs the CMTS file and configures itself
    > it goes into bridging mode. When its in this bridging mode it doesn't
    > directly accept connects from either side,
    
    How exactly have you checked that it doesn't accept connections ?
    
    > so I'm wondering how the CMTS
    > sends SNMP data to the modem and visa versa.
    >
    > Also:
    > > ----- Original Message -----
    > > From: "fejed" <fejedat_private>
    > > To: <VULN-DEVat_private>
    > > Sent: Friday, April 27, 2001 2:08 AM
    > > Subject: Re: Hijack IP Address using cable modem (fwd)
    > >
    > >
    > > > from what I've seen, my configuration file is delivered via bootp, I
    > have
    > > a
    > > > surfboard sb3100 cable modem, if anyone wishes to see a dump of the
    > > > configuration, email me off list
    >
    > how do you manage to get the config file?
    
    I've contacted fejed some time ago. He just sniffed on his LAN and what he
    wrote about is simply DHCP/BOOTP packet catched in the wild (they're sent
    to 255.255.255.255). If you wanna get CM configuration file you have to
    go one step further. Acquire similar packet from your network, take a look
    at it, find TFTP server address and filename and just grab this file from
    TFTP server.
    
    
    >
    > RFC 2669 has some interesting stuff about the DOCSIS system, though its somewhat outdated.
    
    I think that most interesting resources are at cablemodems.com and
    cablelabs.com.
    
    --
    pozdrawiam,
    
    -= Marcin Dawcewicz =-         mailto: mivat_private
    "When freedom is outlawed, only outlaws will be free"
    



    This archive was generated by hypermail 2b30 : Tue May 01 2001 - 00:34:19 PDT