Traceroutes to Cisco Routers

From: Dieter Sarrazyn (dsr@ascure.com)
Date: Sat Jun 05 2004 - 06:55:10 EDT


Hi all,

While performing pentests, I noticed some (strange) behaviour with
tracerouting to cisco routers.

Performing the trace with udp packets (default on linux), the router
answers with it's ip address of the interface closest to you (external
interface of the router).
Performing traces with icmp (-I flag in linux, default in windows), the
router answers with it's ip address that you are tracing to (mostlikely
the internal interface of the router).

Anybody noticed this behaviour as well?
Has somebody an explanation for this?

Regards,
Dieter



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:53:55 EDT