6 ms·
Yes. Non-LAN meaning the attacker doesn't have to be inside your home/work local network.
by paulv 9y ago
Yes. Non-LAN meaning the attacker doesn't have to be inside your home/work local network.
- londons_explore 9y agoIt could mean two things. Either it could mean it is not a requir mentioned to be able to send broadcast packets to the machine. Windows uses broadcast packets for lots of things, like discovering UPnP devices, media centers, other machines file/printer shares, etc. Or it could mean no need to have the ability to send the machine IP packets directly, so one can attack even if the machine is behind NAT. There are far fewer ways to attack a machine behind NAT with no user interaction, but things like sending back false NTP or DNS responses, spoofing windowsupdate servers, or some of the peer to peer services built into windows sound like possible ways.
- pdkl95 9y agos/NAT/firewall/g NAT does not provide security on its own, it's the firewall that drops packets. Most of the time you see both together on the same device; it's very rare to see a NAT-only device, which usually will route packets to hosts on the LAN.
- eriknstr 9y agoThe statement "there are far fewer ways to attack a machine behind NAT with no user interaction" is true even though NAT on it's own is not designed to be a firewall.
- rocqua 9y agoNat certainly does provide basic security. If you aren't routable, they can't setup a connection to you.
- mshook 9y agoThey can, it's called firewall punching... Skype does that routinely: ever wondered how it can setup a point to point connection without port forwarding? So to agree with PP, NAT is not a firewall...
- dec0dedab0de 9y agoI believe that's called ICE. and still needs both clients aware that theyre about to connect, and making outbound connections to each other with the goal of opening up sourceports. This does not negate the fact that NAT(PAT) provides protection against directly connecting to a device.
- mshook 9y agoIf you know a bug in the DNS resolving stack of the client, you can make it send a query to your DNS server and exploit it to establish a connection. So no, it doesn't have to know it's about to connect. A query is easily triggered by sending an email with a an external picture embedded or something like that. Nothing NAT/PAT can protect you against.
- slau 9y agoBut why would the client use _your_ DNS server? It will just use its local resolver, which will most likely use the router, or ISPs DNS server, and so forth.
- dec0dedab0de 9y agothats also something a firewall cant protect you against.
- rocqua 9y agoThe difference is that NAT doesn't track the counter party, so after you reached out to the DNS, any other service can use the opened port to connect to your PC. With a stateful firewall, it tracks that the port was opened only used for the DNS server. If a connection to that port from a different IP address than the DNS server is made, the firewall will block it.