3 ms·
That's like saying that a bad firewall implementation leaks like a sieve. This is not what I was talking about.
by lzaaz 4y ago
That's like saying that a bad firewall implementation leaks like a sieve. This is not what I was talking about.
- lazide 4y agoAny router running a poor NAT implementation (aka most of them) essentially has a built in firewall bypass for the right attacker. A naive NAT implementation can allow an attacker to bypass the firewall.
- jraph 4y agoCurious, could you expand on this?
- vel0city 4y agoI gave an example just a few comments above this. Alice never wanted Charles' traffic, the firewall should not have let it through. But because the NAT is dumb, and the firewall rules are often tied to the NAT on these crappy home routers, it's allowed. So now because Alice wanted to talk to Bob, she opened a port to the world that she never wanted opened as wide.
- jraph 4y agoThanks! (you added this afterwards, right? Or it's just me being tired and skipping this)