DHCP list avalible from web

Post new topic   Reply to topic    DD-WRT Forum Index -> General Questions
Author Message
Mad_Scientist
DD-WRT Novice


Joined: 22 Nov 2016
Posts: 3

PostPosted: Tue Nov 22, 2016 19:04    Post subject: DHCP list avalible from web Reply with quote
Hey folks,

I did a security on my Workstation today, and on of the things it gave me back was the companies router address in the form of a DNS style address I didnt know what it was so i went to it and it brought me to the ip address for the company router.

The problem I have with this, is that From the main page, I can see a complete list of everyone one of the DHCP Clients currently connected, along with the internal IP and mac address of each pc.

this seems like a huge security concern to me... but is it a valid concern? How do I hide the DHCP list?

again.. this was WITHOUT logging into the router. Just on the public IP of the router. (info page of the router i beleive)
Sponsor
d00zah
DD-WRT User


Joined: 06 Jun 2006
Posts: 211

PostPosted: Tue Nov 22, 2016 20:00    Post subject: Reply with quote
You can't hide the list, per se, but you can obscure the MAC addresses. Navigate to Administration > Management & check 'Info Site MAC Masking'. This will change all but the last 2 octets to 'xx:...' & still allow you to view active clients at a glance.
_________________
NetGear XR500 - FW Version: DD-WRT v3.0-r55819 std (04/17/24)
Linux 6.1.86 #130 SMP Wed Apr 17 05:48:30 +07 2024 armv7l
Updated from: DD-WRT v3.0-55779 std (04/12/24) via GUI (FF), NO reset
Gateway: SmartDNS, DDNS (FreeDNS), IPv4 DHCP, Static leases, SFE Disabled, QoS Disabled
AP: 2.4GHz NG-Mixed 40MHz, 5GHz AC/N-Mixed 80MHz, WPA2 w/ AES, MAC filtering, Isolated Guest VAP on wlan1, Vanilla FW
Services: USB Storage, NAS, Samba
Storage: Samsung Portable SSD T7 Shield USB 3.2 2TB, /jffs, /opt, /data (ext4)
Mad_Scientist
DD-WRT Novice


Joined: 22 Nov 2016
Posts: 3

PostPosted: Tue Nov 22, 2016 21:30    Post subject: Reply with quote
thank you for that info. I will do that.

Just to reiterate... this is not a security concern? correct?
d00zah
DD-WRT User


Joined: 06 Jun 2006
Posts: 211

PostPosted: Tue Nov 22, 2016 23:10    Post subject: Reply with quote
Not from my perspective. Info is only available within your LAN... just active client IP info.
_________________
NetGear XR500 - FW Version: DD-WRT v3.0-r55819 std (04/17/24)
Linux 6.1.86 #130 SMP Wed Apr 17 05:48:30 +07 2024 armv7l
Updated from: DD-WRT v3.0-55779 std (04/12/24) via GUI (FF), NO reset
Gateway: SmartDNS, DDNS (FreeDNS), IPv4 DHCP, Static leases, SFE Disabled, QoS Disabled
AP: 2.4GHz NG-Mixed 40MHz, 5GHz AC/N-Mixed 80MHz, WPA2 w/ AES, MAC filtering, Isolated Guest VAP on wlan1, Vanilla FW
Services: USB Storage, NAS, Samba
Storage: Samsung Portable SSD T7 Shield USB 3.2 2TB, /jffs, /opt, /data (ext4)
Mad_Scientist
DD-WRT Novice


Joined: 22 Nov 2016
Posts: 3

PostPosted: Wed Nov 23, 2016 0:03    Post subject: Reply with quote
that is not just accessible from inside my lan. i can see the info page and all the active clients from my cell phone and my home PC both.
d00zah
DD-WRT User


Joined: 06 Jun 2006
Posts: 211

PostPosted: Wed Nov 23, 2016 0:15    Post subject: Reply with quote
Never occurred to me, as I've never enabled remote admin... which I do see as a potential security risk. Still, obscuring MAC addresses is definitely s step in the right direction if you do so. And using https.

Any other opinions from the gallery?

_________________
NetGear XR500 - FW Version: DD-WRT v3.0-r55819 std (04/17/24)
Linux 6.1.86 #130 SMP Wed Apr 17 05:48:30 +07 2024 armv7l
Updated from: DD-WRT v3.0-55779 std (04/12/24) via GUI (FF), NO reset
Gateway: SmartDNS, DDNS (FreeDNS), IPv4 DHCP, Static leases, SFE Disabled, QoS Disabled
AP: 2.4GHz NG-Mixed 40MHz, 5GHz AC/N-Mixed 80MHz, WPA2 w/ AES, MAC filtering, Isolated Guest VAP on wlan1, Vanilla FW
Services: USB Storage, NAS, Samba
Storage: Samsung Portable SSD T7 Shield USB 3.2 2TB, /jffs, /opt, /data (ext4)
d00zah
DD-WRT User


Joined: 06 Jun 2006
Posts: 211

PostPosted: Wed Nov 23, 2016 0:20    Post subject: Reply with quote
And looking at the same group of settings, you could disable the Info Site altogether.

Or enable 'Info Site Password Protection'.

Either will just land you on a '401 Unauthorized' page without a username/password.

_________________
NetGear XR500 - FW Version: DD-WRT v3.0-r55819 std (04/17/24)
Linux 6.1.86 #130 SMP Wed Apr 17 05:48:30 +07 2024 armv7l
Updated from: DD-WRT v3.0-55779 std (04/12/24) via GUI (FF), NO reset
Gateway: SmartDNS, DDNS (FreeDNS), IPv4 DHCP, Static leases, SFE Disabled, QoS Disabled
AP: 2.4GHz NG-Mixed 40MHz, 5GHz AC/N-Mixed 80MHz, WPA2 w/ AES, MAC filtering, Isolated Guest VAP on wlan1, Vanilla FW
Services: USB Storage, NAS, Samba
Storage: Samsung Portable SSD T7 Shield USB 3.2 2TB, /jffs, /opt, /data (ext4)
Wildlion
DD-WRT Guru


Joined: 24 May 2016
Posts: 1416

PostPosted: Fri Nov 25, 2016 20:57    Post subject: Reply with quote
Mad_Scientist wrote:
thank you for that info. I will do that.

Just to reiterate... this is not a security concern? correct?


MAC addresses are only valid when on the same subnet. So unless you change to a different subnet the MAC address does not make a difference.

The one thing that you should know/remember is that wireless devices will broadcast their MAC address (this is how they know how to communicate to each other). The first 6 hex numbers (little x's below) are the manufacturer id and the last 6 (capital Y's below) are the unique device id assigned from manufacturer.

xx:xx:xx:YY:YY:YY

Since a MAC address is intended to be unique, there is more privacy concerns than security. For example, if you posted online the full MAC address, and then someone at a coffee shop saw the same MAC address, they could indirectly identify you.

But I agree with d00zah.

Just trying to educate you, so you can make the right choice for you.
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> General Questions All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum