
Originally Posted by
mrrijo
Hello,
You know what, i am a frustrated customer of reliance wimax. I told this problem to reliance many times!!. They still leave that stuff just like that!! That is the wonder about reliance.
Let me tell you the real problem of "loosing IP/account lock etc" happens just after a power outage or modem disconnect without proper log out!!
this may help for many yelling customers out there..
Reliance uses two way mechanism for server authentication.
1. when you connect your pc to that crappy piece of white box, it tries to allocate an IP to your PC by reading your "PC's" MAC address.
2. Next you get the login screen. And you logs in successfully.
3. Then the server which authenticates you, records your IP along with username somewhere.
4. When you loose the power, your session with the above server is lost and the DHCP (which allocates ip) server thinks that, you have been disconnected. Here starts the wonder!!
5. Then DHCP server assigns "your IP" to some one else!!, RESULT, whoever got that IP has an authenticated session "with your user name" and he enjoys it nicely.
6. When your power comes back, you get a different IP and when you try to login, it wont work. Because some one else is using your account!!!!
How does that feel???
You call to reliance, yell at them, they reset your password!!, then you can login back again!!. Very nice!!
to make matters worse, if someone has the IP as well as same MAC address of yours, you are lost.. All sessions as well as your credentials (passwords, etc) can be seen by other user!!!.
Do you want this to happen?
A word to administrator,
I had no intention to make people hack reliance network. I wanted people to be aware of this security flaw which India's proud reliance has. Even after informing them.
I no longer use Reliance and that is crap. I discourage people from going after it, because of this security issues. Hope you will understand.!!