On Fri, 2004-03-05 at 15:55, Robinson, Eric R. wrote: > Now, to follow up on Mark's question. I understand how session hijacking > works. I would not say that a dynamically NATed host is any more or less > susceptible to it than a statically translated one, or even one that is > protected by a stateful ACL. All depends on whether the attacker can > arp-poison his way into a middle position. I am very curious, however, as to > what sorts of packet mangling Todd is talking about, and how mangled packets > could be used to leverage an unauthorized inbound connection. (Not saying it > cannot be done, I just don't see how off the top of my head.)
I'd also like to see an example/link to this. > Here, I'll provide a notional NAT table to work from. In this case, a user > has connected to yahoo, cnn, and weatherbug in the course of less than a > minute. How can NAT be fooled into permitting an inbound connection to the > Inside_Source? I don't have an answer to your question, but I do have a suggestion on how to gain remote entry into a NAT'd network. Since you can establish outgoing connections from you machines inside the NAT, then I could always trick you, or one of your users, into establishing a connection to me, either by spyware, malware, or simply a virus or worm in an email. Users often fall pray to social engineering attacks, so this may be easier than it seems. Once you are connected to me, I can connect back over the same stream, and now I am on your network. Assuming I have a Windows NT or DOS machine on your network now, I most likely have root-level access to start flooding/scanning/sniffing/leveraging other hosts behind your NAT. Mark _______________________________________________ RLUG mailing list [EMAIL PROTECTED] http://www.rlug.org/mailman/listinfo/rlug
