Mark C. Ballew wrote:

On Fri, 2004-03-05 at 14:25, Hector E. Urtubia wrote:


Todd is right, NAT is not really a security measure, just a clever way to
overcome the shortage of IPv4. This paper shows a technique to count the
hosts behind a NAT.

http://www.research.att.com/~smb/papers/fnat.pdf

wow.. hadn't posted to the list in a while...



Hector lives!


Could someone describe an attack that could happen to a NAT, other than
"it is bad, don't do it"? So far we can count how many hosts there are,
but now what?

Depending on how lame the NAT box you are relying on is -- one could poison its ARP cache to hijack packets. I think one of the BSDs had an issue with ARP cache poisoning not to long ago that did exactly this. Aside from data-theft this would be good for DoSing a network.

chris








_______________________________________________ RLUG mailing list [EMAIL PROTECTED] http://www.rlug.org/mailman/listinfo/rlug

Reply via email to