confused about new option (WAN IP € local)

Discussions about the Application Boundaries Enforcer (ABE) module
Czerno

confused about new option (WAN IP € local)

Post by Czerno »

Hi ! While I understand the " WAN IP (x.x.x.x) E LOCAL " is to do with protection against DNS rebinding attacks against local routers (and more), I am confused as whether the protection against trying to access my router locally through the WAN IP is granted when the above mentioned option is CHECKED (as seems to be default) or should it be UNCHECKED ????

Experiment : when checked, I seem to be able to locally access the router (assuming I remember the password!) without interference from NoScript , whereas when unchecked, I have to ask NoScript to unlock the page first, then enter the password. So, I guess, /unchecked/ is what that option wants to be, please confirm and then, why is the default setting the unsafe one ? BICBW !


--
Czerno
Mozilla/5.0 (Windows; U; Windows NT 5.0; fr; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: confused about new option (WAN IP € local)

Post by Giorgio Maone »

The page locked/unlocked is independent from this option and this protection feature (I'm not sure about what you mean by "locked" here).
This option definitely needs to be left checked in order to protect your router.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8
Czerno

Re: confused about new option (WAN IP € local)

Post by Czerno »

Giorgio Maone wrote:This option definitely needs to be left checked in order to protect your router.
Makes sense, thank you Giorgio !
Mozilla/5.0 (Windows; U; Windows NT 5.0; fr; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8
Post Reply