Zone Alarm Pro and Private IP Addresses

From: Philip Wagenaar (PB.Wagenaarat_private)
Date: Mon Nov 12 2001 - 14:17:19 PST

  • Next message: Vasisht Tadigotla: "Re: Bug in bash ?"

    On a system running Windows XP, with the Windows XP firewall turned off, and Zone Alarm Pro with no internal network selected, a packet was allowed through originating from the IP address 10.10.1.1 and was addressed to 255.255.255.0.
    
    I know 10.10.1.1 is to be used for internal networks only so I think that’s a spoofed address because the computer is connected directly to a cable modem and the subnetmask for the network card connected to the ethernet card is 255.255.254.0.
    
    Can anyone else reproduce this by sending a packet originating from 10.10.*.* or 192.168.*.* to a computer running Zone Alarm Pro and with local network not selected?
    
    Philip Wagenaar
    
    Time/Date(03:30:51/10.11.2001) Protocol/Number(UDP/17)
     Source(10.10.1.1) Destination(255.255.255.255)
     Source Port (67) Destination Port (68)
     Length (308) CheckSum (14577)
    
           01 02 03 04 05 06 07 08 09 10 11 12 13 14 15 16 17 18
    
     000001 45 00 01 48 c2 3e 00 00 80 11 6c 5c 0a 0a 01 01 ff ff E..HÂ>..€.l\....ÿÿ
     000019 ff ff 00 43 00 44 01 34 38 f1 02 01 06 00 00 00 00 00 ÿÿ.C.D.48ñ........
     000037 00 00 80 00 d4 8e 06 79 00 00 00 00 00 00 00 00 00 00 ..€.ÔŽ.y..........
     000055 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ..................
     000073 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ..................
     000091 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ..................
     000109 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ..................
     000127 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ..................
     000145 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ..................
     000163 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ..................
     000181 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ..................
     000199 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ..................
     000217 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ..................
     000235 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ..................
     000253 00 00 00 00 00 00 00 00 00 00 00 00 63 82 53 63 35 01 ............c‚Sc5.
     000271 05 36 04 0a 0a 01 01 01 04 00 00 00 00 2b 0f 5f 0d 48 .6...........+._.H
     000289 61 6c 69 78 2e 4c 6f 6b 61 61 6c 00 ff 00 00 00 00 00 alix.Lokaal.ÿ.....
     000307 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ..................
     000325 00 00 00 00                                           ....
    



    This archive was generated by hypermail 2b30 : Mon Nov 12 2001 - 14:56:00 PST