Koozali.org: home of the SME Server

My box is sending out its internal IP address!

Offline nate

  • **
  • 55
  • +0/-0
    • http://www.solardepot.com
My box is sending out its internal IP address!
« on: December 12, 2006, 06:59:16 PM »
Calling all you network security uber-gurus...

….should I be worried?

When I go to this web site: http://isc.sans.org/   they have a sniffer that detects my internal IP – not the public router address like it does everywhere else that sniffs me.  Also, only one machine does this?  From every other client on my network if I go to a site that says you IP is: blah.blah.blah.1  - it only sees my router (sme 6.01-01 w/smeplus).  However, from one client machine the Internet Storm Center’s port detector sees my internal address and get’s it right every time!   I talked to them and they said they looked at the browser headers and the proxy.  

The box is Win-XP Pro running IIS and SMTP. – BUT, …I have several of these that are exactly the same and this is the only one that is doing this.
 
(1)   Should I be worried / Pull the box off line?
(2)   What would push my 192.168.. address out on port 80?

 
 
Nate
....Making the Jump to 7.x   8-)

Offline piran

  • ****
  • 502
  • +0/-0
My box is sending out its internal IP address!
« Reply #1 on: December 15, 2006, 10:46:11 AM »
Nate: my best recommendation is that you need more underwear.
Until you've resolved the resources problem in the underwear department
don't even think about http://grc.com or http://dnsstuff.com or that your
email package is likely to put that address into the outgoing headers too.

Offline william_syd

  • ****
  • 1,608
  • +0/-0
  • Nothing to see here.
    • http://www.magicwilly.info
My box is sending out its internal IP address!
« Reply #2 on: December 15, 2006, 01:33:02 PM »
Where on that page is the sniffer?

I've seen having java/javascript enabled in your browser as being a cause of this.
Regards,
William

IF I give advise.. It's only if it was me....

Offline piran

  • ****
  • 502
  • +0/-0
My box is sending out its internal IP address!
« Reply #3 on: December 15, 2006, 01:36:35 PM »
william_syd:
<Where on that page is the sniffer?>
...left sidebar near the top ("IP Lookup")?

Offline william_syd

  • ****
  • 1,608
  • +0/-0
  • Nothing to see here.
    • http://www.magicwilly.info
My box is sending out its internal IP address!
« Reply #4 on: December 15, 2006, 01:42:57 PM »
Looks more like a whois than a sniffer.

Interesting...

http://forums.dnsstuff.com/tool/post/dnsstuff/vpost?id=1005293
Regards,
William

IF I give advise.. It's only if it was me....

Offline piran

  • ****
  • 502
  • +0/-0
My box is sending out its internal IP address!
« Reply #5 on: December 15, 2006, 02:13:24 PM »
So... just a damp Squid;~)

Offline william_syd

  • ****
  • 1,608
  • +0/-0
  • Nothing to see here.
    • http://www.magicwilly.info
My box is sending out its internal IP address!
« Reply #6 on: December 15, 2006, 02:15:28 PM »
Quote from: "piran"
So... just a damp Squid;~)


damp Squid ?
Regards,
William

IF I give advise.. It's only if it was me....

Offline piran

  • ****
  • 502
  • +0/-0
My box is sending out its internal IP address!
« Reply #7 on: December 15, 2006, 02:24:34 PM »
English humour... it was mildly amusing at that moment.
Correct spelling is 'damp squib'.
Exciting firework but but wasn't due to dampness, coupled with
an allusion to excessive worry and OP's underpants signature.

Offline nate

  • **
  • 55
  • +0/-0
    • http://www.solardepot.com
My box is sending out its internal IP address!
« Reply #8 on: December 15, 2006, 07:35:29 PM »
Quote from: "piran"
Nate: my best recommendation is that you need more underwear.
Until you've resolved the resources problem in the underwear department
don't even think about http://grc.com or http://dnsstuff.com or that your
email package is likely to put that address into the outgoing headers too.


I guess the underwear comment is some kind of attempt at humor?  Thanks for the reply anyway...  BTW - The two sites you mention only see my public gateway!  206.176.229.195  Thats all I can ever see from the outside unless I VPN in?
....Making the Jump to 7.x   8-)

Offline nate

  • **
  • 55
  • +0/-0
    • http://www.solardepot.com
My box is sending out its internal IP address!
« Reply #9 on: December 15, 2006, 07:39:44 PM »
Quote from: "william_syd"
Looks more like a whois than a sniffer.

Interesting...

http://forums.dnsstuff.com/tool/post/dnsstuff/vpost?id=1005293

 
Thank you for the reply.  However, the like above does not work for me.  
 
I spoke with someone from ISC and he told me about the Java issue, but assured me they were not using that method.  He could not figure it out either?  
 
- Nate
....Making the Jump to 7.x   8-)

Offline piran

  • ****
  • 502
  • +0/-0
Re: My box is sending out its internal IP address!
« Reply #10 on: December 15, 2006, 07:50:11 PM »
Quote from: "nate"
* All controlled from home in my underwear using PPTP & VNC!  Cool

Quote from: "nate"
I guess the underwear comment is some kind of attempt at humor?

Well, you said it. My site's Squid also puts that (internal IP) into my email headers
too. Consider it a fact of life. Shouldn't matter to a properly set up server site as
it's a non-routable IP. Squid is really not something with which I'd want to mess.

Offline william_syd

  • ****
  • 1,608
  • +0/-0
  • Nothing to see here.
    • http://www.magicwilly.info
My box is sending out its internal IP address!
« Reply #11 on: December 15, 2006, 11:58:12 PM »
Quote from: "nate"
Quote from: "william_syd"

http://forums.dnsstuff.com/tool/post/dnsstuff/vpost?id=1005293

 
Thank you for the reply.  However, the like above does not work for me.  
 


Interesting.

Quoting the posts at the above link...

Quote
Hi Guys,

 

There is something very strange. I am using a NAT server to access internat from my computer, (Also use Squid as proxy server for web accessing). My computer address is something like 192.168.1.108 and the NAT server external address is 206.X.X.X. When I go to www.dnsstuff.com, it surprises me that it shows both the external ip address and my internal ip address. How does it figure out my internal ip address then? Any explanation for this?

 

Thanks in advance and have a nice day.

 

Nick.

Quote
The key is Squid.

With a normal web connection, it would be impossible to know your internal IP address (no matter what your firewall does); the internal IP can't be leaked.

However, web proxies were originally designed for ISPs, in which case the websites wanted to know what IP the user was using (the "client IP", so they could distinguish hits).  Therefore, Squid (and most other web proxies) are normally set up to give out the client IP.  In fact, if you were getting blocked from our site because someone else using the Squid proxy was attacking our site, we would only be able to add the proxy as a "trusted" proxy if the client IP was reported (but only if it was a public IP, so see below).

When used on a local network, though, using internal IPs, giving out the client IP often isn't desired.  It would normally only be beneficial in cases of abuse, so the abuser could be tracked down.  And it can provide the "bad guys" with information about your local network (that probably wouldn't be very useful, but might).

To get around this, you could set up Squid to not report the client IP.

Quote
a "normal" web-connection might detect your internal ip via java - have a look at http://serversniff.net/browser_header.php
to see such an applet in action. the applet has no problem to submit your private ip back to the originating webserver without you knowing it.
Regards,
William

IF I give advise.. It's only if it was me....

boss_hog

My box is sending out its internal IP address!
« Reply #12 on: December 16, 2006, 04:17:18 PM »
Hi guys,
this same issue was briefly discussed here:

http://forums.contribs.org/index.php?topic=29342.0

It didn't seem to cause Charlie any un-due concern.
Joe