[Full-disclosure] QNAP Turbo NAS Multiple Path Injection

2012-09-04 Thread Andrea Fabrizi
** Vulnerability: Multiple Path Injection Product: QNAP Turbo NAS Vendor: QNAP Version affected: <= 3.7.3 build 20120801 Status: Unpatched Website: http://web.qnap.com/pro_detail_feature.asp?p_id=202 Discovered by: Andrea Fabrizi Email: an

[Full-disclosure] IPv6 implications on IPv4 nets: IPv6 RAs, IPv4, and VPN "evasion"

2012-09-04 Thread Fernando Gont
Folks, draft-gont-opsec-ipv6-implications-on-ipv4-nets has been adopted as an IETF opsec wg item (please see: ) I was thinking about discussing the following scenario, that I came up with a few days ago: A dual-stacked u