On Fri, 2004-03-05 at 15:55, Robinson, Eric R. wrote:
> Now, to follow up on Mark's question. I understand how session hijacking
> works. I would not say that a dynamically NATed host is any more or less
> susceptible to it than a statically translated one, or even one that is
> protected by a stateful ACL. All depends on whether the attacker can
> arp-poison his way into a middle position. I am very curious, however, as to
> what sorts of packet mangling Todd is talking about, and how mangled packets
> could be used to leverage an unauthorized inbound connection. (Not saying it
> cannot be done, I just don't see how off the top of my head.)

I'd also like to see an example/link to this.

> Here, I'll provide a notional NAT table to work from. In this case, a user
> has connected to yahoo, cnn, and weatherbug in the course of less than a
> minute. How can NAT be fooled into permitting an inbound connection to the
> Inside_Source?

I don't have an answer to your question, but I do have a suggestion on
how to gain remote entry into a NAT'd network. Since you can establish
outgoing connections from you machines inside the NAT, then I could
always trick you, or one of your users, into establishing a connection
to me, either by spyware, malware, or simply a virus or worm in an
email. Users often fall pray to social engineering attacks, so this may
be easier than it seems.

Once you are connected to me, I can connect back over the same stream,
and now I am on your network. Assuming I have a Windows NT or DOS
machine on your network now, I most likely have root-level access to
start flooding/scanning/sniffing/leveraging other hosts behind your NAT.

Mark

_______________________________________________
RLUG mailing list
[EMAIL PROTECTED]
http://www.rlug.org/mailman/listinfo/rlug

Reply via email to