OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Traceroutes to Cisco Routers

From: James Fields (jvfieldstds.net)
Date: Tue Jun 08 2004 - 16:55:14 CDT


Is this with all Cisco routers? You can set certain types of packets (I
believe ICMP is such a case) to always be sourced from a particular
interface.

----- Original Message -----
From: "Dieter Sarrazyn" <dsrascure.com>
To: <pen-testsecurityfocus.com>
Sent: Saturday, June 05, 2004 6:55 AM
Subject: Traceroutes to Cisco Routers

Hi all,

While performing pentests, I noticed some (strange) behaviour with
tracerouting to cisco routers.

Performing the trace with udp packets (default on linux), the router
answers with it's ip address of the interface closest to you (external
interface of the router).
Performing traces with icmp (-I flag in linux, default in windows), the
router answers with it's ip address that you are tracing to (mostlikely
the internal interface of the router).

Anybody noticed this behaviour as well?
Has somebody an explanation for this?

Regards,
Dieter