Skip to content
This repository has been archived by the owner on Jan 9, 2019. It is now read-only.

Public IP potentially leaks other users IPs #75

Open
Altirix opened this issue Jul 28, 2017 · 2 comments
Open

Public IP potentially leaks other users IPs #75

Altirix opened this issue Jul 28, 2017 · 2 comments
Assignees
Labels

Comments

@Altirix
Copy link

Altirix commented Jul 28, 2017

Used Ulterius back when it first came out and it worked fine. uninstalled and never got it to work again with external connections and gave up. Came back to see if it had matured and was working or if i could work it out.

managed to get it to work by just disabling windows firewall entirely, but when i hover over the Public IP someone elses IP appears. i tested this ip in ulterius and it connected me to WORKSTATION/Joe.

image

image

ive seen it be other Ips (one starting in 47. )but have not confirmed if they are other users. i do not know what has caused this. The version is the latest from the site.

@Altirix Altirix changed the title Cannot connect to own pc with external ip. Public IP potentially leaks other users IPs Public IP potentially leaks other users IPs Jul 28, 2017
@andrewmd5
Copy link
Member

Wow, thank you for bringing this to my attention.

Cloudflare was caching the entire API over GET (https://api.ulterius.io/network/ip/). I'm not sure how this happened given I have a page rule that strictly told it to NOT cache the API domain, nonetheless it is fixed now.

I've reported this to Cloudflare.

@andrewmd5 andrewmd5 self-assigned this Jul 29, 2017
@andrewmd5 andrewmd5 added the bug label Jul 29, 2017
@andrewmd5
Copy link
Member

I performed a more in depth analysis and it doesn't seem anyone was breached as a result of this (thankfully). Ulterius does enforce you use a password for your Windows account and I can't see any indication this was a known issue until today.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Projects
None yet
Development

No branches or pull requests

2 participants