4 ms·
That is an awesome tool, but it requires a cooperating server inside your NAT; for security-breaching purposes, if you've got code execution on a machine inside
by alethiophile 9y ago
That is an awesome tool, but it requires a cooperating server inside your NAT; for security-breaching purposes, if you've got code execution on a machine inside the firewall, you've already won (against the firewall, anyway).
- occultist_throw 9y agoWell, indeed. But Im thinking that it could be done with a webapp and Websockets. In other words, get sent to a domain that initiates the knock sequence. Other machine in waiting responds, and NAT traversal takes over, to any machines inside NAT. The only real question is how much code is actually required to start this.
- alethiophile 9y agoWeb code is only allowed to send TCP packets (websockets go on port 80 by default, just like HTTP). It also doesn't allow crafting special packets. pwnat's method relies on being able to send ICMP and UDP, which the browser won't.
- occultist_throw 9y agoI didn't thank you for your response. I looked further in, and was mistaken - I thought that it allowed a bit more as in TCP and UDP. I was wrong. So yes, it looks like some sort of further in-depth hackery would be required, or planting some sort of SBC in the building on the network. It's quite a bit more infeasible than I had initially thought.