Find anyone's address from their router MAC code
samy.pl
samy.pl
There was a big, overblown privacy scare some months ago because it was discovered that the cars also accidentally saved some stray unencrypted packets of traffic as they cruised around.
I'm sure pioneer map-makers got in trouble for plotting perfectly visible stuff that was located on private property.
I speculate that further routes for collection may be available. E.g. a user uses a wi-fi connection with a device that has geo-location turned on, and "Bob's your uncle".
http://gigaom.com/2010/09/15/skyhook-sues-google-in-a-locati...
So if you don't want to be hacked, change your password.
For connections coming from outside it forwards it to the DMZ computer, or blocks it.
There are really just two simple ideas here (taking a couple simple ideas and plugging them together in some totally unexpected way being a Samy Kamkar trademark):
* Any website can usually use reflected XSS to interact with a browser's upstream wireless router, because wireless routers suck, and because they assume that the "inside" network is safe.
* There are databases that translate wireless MAC into location (like Skyhook).
Besides that, this appears to only work with wireless routers, based on how google is locating them.
Getting to my router with an attack is a little less trivial since it is no longer on 192.168.1.1. Also I'm not sure if there's an XSS attack that an unauthenticated user can fire, as any attempt to do anything is just giving me a login box which itself doesn't have an XSS. But this is my 90 second security analysis, if I tried harder I'm sure there's something nasty somewhere.