Alteon AceDirector Half-Closed HTTP Request IP Address Revealing Vulnerabililty
BID:3964
Info
Alteon AceDirector Half-Closed HTTP Request IP Address Revealing Vulnerabililty
| Bugtraq ID: | 3964 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 25 2002 12:00AM |
| Updated: | Jan 25 2002 12:00AM |
| Credit: | This vulnerability was announced by Dave Plonka <[email protected]> via Bugtraq on January 25, 2002. |
| Vulnerable: |
Nortel Networks WebOS 9.0 |
| Not Vulnerable: | |
Discussion
Alteon AceDirector Half-Closed HTTP Request IP Address Revealing Vulnerabililty
Alteon ACEdirector is a hardware solution distributed by Nortel Networks. ACEdirector runs the Nortel WebOS operating system.
It is possible to retrieve the real IP addresses of webservers that are managed by an ACEdirector. When a client is connected to a webserver via the virtual IP address of the ACEdirector, the connection to a web server in the load balanced pool is tracked by a cookie and session id, and the traffic is altered to appear as though it is coming from the ACEdirector.
When a client has half-closed a connection to the ACEdirector, the load balancer will no longer alter the traffic to the client to appear as though it is coming from the ACEdirector's IP address. The traffic will continue to come from the webserver, but will instead come from the real IP address of the web server.
Alteon ACEdirector is a hardware solution distributed by Nortel Networks. ACEdirector runs the Nortel WebOS operating system.
It is possible to retrieve the real IP addresses of webservers that are managed by an ACEdirector. When a client is connected to a webserver via the virtual IP address of the ACEdirector, the connection to a web server in the load balanced pool is tracked by a cookie and session id, and the traffic is altered to appear as though it is coming from the ACEdirector.
When a client has half-closed a connection to the ACEdirector, the load balancer will no longer alter the traffic to the client to appear as though it is coming from the ACEdirector's IP address. The traffic will continue to come from the webserver, but will instead come from the real IP address of the web server.
References
Alteon AceDirector Half-Closed HTTP Request IP Address Revealing Vulnerabililty
References:
References:
- Nortel Networks Homepage (Nortel Networks)