To: bugtraq@xxxxxxxxxxxxxxxxx Subject: FON Router allows anonymous web access From: l.friedrichs@xxxxxxxxxxxx Date: 6 Jan 2007 19:49:56 -0000 Description: "La Fonera" routers distributed by FON allow web access to unauthenticated users via DNS tunneling. Explanation: The router gives a client an DHCP answer but does not forward ip traffic until the client authenticates via the captive portal. The