On Fri, 5 Mar 2004, Mark C. Ballew wrote:
> Could someone describe an attack that could happen to a NAT, other than
> "it is bad, don't do it"? So far we can count how many hosts there are,
> but now what?
Static translations offer no security. Hosts behind the NAT device can be
scanned/probed just the same as if they were directly connected.
Dynamic translations are a bit more difficult, but are still susceptible
to session hijacking and various timing issues on the NAT device. Packet
mangling may enable unauthorized inbound connections. And, depending on
the sophistication of the device (or lack thereof), unmangled out-of-flow
inbound connections may also be possible.
--
Todd's "Customer Disservice Hall of Shame" currently contains:
- Charter Communications: Mislead their customers about service
levels, block normal Internet connectivity, and exhibit excessive
downtime.
- AT&T: Honoring the "checks" they send out to entice you to switch
long-distance providers is apparently optional.
- eFax: Receive (not send) 20 pages of *unsolicited* faxes, and lose
your account.
_______________________________________________
RLUG mailing list
[EMAIL PROTECTED]
http://www.rlug.org/mailman/listinfo/rlug