Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » El Cheapo Router Challenge
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
FoxTrot Cartoon on spam... »
« Weird Download Popup  
AuthorAll Replies


Link Logger
Premium,MVM
join:2001-03-29
Calgary, AB
·Shaw

reply to Daniel
Re: NAT Challenge

That sounds fair. Try scanning the 'El Cheapo NAT Router' and see if you can determine what ports are being used and if that doesn't work I'll tell you what ports are being used so we don't waste too much time on detection and can focus on exploitation.

Blake
--
Vendor: Firewall Logging Software »www.SonicLogger.com - SonicWall and 3Com »www.LinkLogger.com - Linksys, Netgear and Zyxel

B
Premium,MVM
join:2000-10-28

reply to Daniel

A variation to a site you own would probably be good too -- the attack could involve an HTML e-mail message with links back to an image at your site -- the image retrieval would alert you to the target's presence (and presumably NAT table state).

Stretching the definition of "unsolicited" I realize, but...

-- B
--
In a realm outside causality and function


Daniel
Premium,MVM
join:2000-06-26
Pleasanton, CA
clubs:

reply to Link Logger
said by Link Logger See Profile :

said by Daniel See Profile :

Can we have you surf and such while we try? I've wanted to do some of this testing for quite a while anyway.
When do you want to do it and do you have a preference as to which NAT device? Would I be surfing to your site, or just surfing in general?
I'm not sure what they paramaters would be, but no, it wouldn't be to a site I own. The idea would be to try and ride back through entries in your NAT table. I'm not saying I could do this, or that it can be done, but I don't see it as impossible.

As for whether or not someone could get packets into a modern SOHO router that doesn't have anything in the NAT table -- that I'd rate as highly unlikely.

But yeah, I think we should explore this for real this time. Many of us here have wanted to for a while now; we should just go ahead and do it. Let's set up a time to meet in #ATU or something.
--
dmiessler.com -- grep understanding knowledge


Link Logger
Premium,MVM
join:2001-03-29
Calgary, AB
·Shaw

reply to Daniel
said by Daniel See Profile :

Can we have you surf and such while we try? I've wanted to do some of this testing for quite a while anyway.
When do you want to do it and do you have a preference as to which NAT device? Would I be surfing to your site, or just surfing in general?

Blake
--
Vendor: Firewall Logging Software »www.SonicLogger.com - SonicWall and 3Com »www.LinkLogger.com - Linksys, Netgear and Zyxel
Forums » Up and Running » Security » SecurityFoxTrot Cartoon on spam... »
« Weird Download Popup  


Sunday, 06-Dec 11:27:44 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [147] Avast Antivirus Has Gone Mad
· [132] The Bandwidth Hog Does Not Exist
· [128] Comcast Makes NBC Universal Acquisition Official
· [105] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [101] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [85] FCC Ponders Moving From PSTN To IP Voice
· [82] Latest Consumer Reports Survey Not Kind To AT&T
· [81] New Bill Aims To Limit ETFs
· [75] Sprint Defuses GPS Privacy Media Bomb
Most people now reading
· Bulb for garage door opener [Home Repair & Improvement]
· False positive in Avast! or is it real? [Security]
· Wife might have to work in.... Iowa for a few months!!! [General Questions]
· Windows 7 boot manager editing questions [Microsoft Help]
· Problems with rlslog.net? [TekSavvy]
· Is there any true cure for, or way to prevent, a hangover? [General Questions]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· [DNS] Google's public DNS... performance increases? [Comcast HSI]
· How fast is your upstream internet connection? [General Questions]
· Unable to get incoming SIP with Callcentric [VOIP Tech Chat]