Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 14th, 2012, 09:45 PM
EncryptedBytes EncryptedBytes is offline
Frequent Poster
 
Join Date: Feb 2011
Location: Odenton, Maryland
Posts: 416
Default Opening closed ports on NAT device and bypassing stateful firewalls with BeEF

-http://blog.beefproject.com/2012/07/opening-closed-ports-on-nat-device-and.html-

Quote:
In 2010 Samy Kamkar discovered a method that he called "NAT Pinning." The idea was, an attacker lures a victim to a web page and that web page forces the victim's router or firewall to forward any port number back to the user's machine.
  #2  
Old July 15th, 2012, 12:54 AM
Gullible Jones
 
Posts: n/a
Default Re: Opening closed ports on NAT device and bypassing stateful firewalls with BeEF

Eww, nasty. I cannot wait until malicious sites start using remote exploits, instead of tired old drive-by downloads.

Anyway... How would UFW's default configuration for iptables fair against such an attack? And what about Windows software firewalls? Would I be wrong in suspecting an interactive firewall might be safer in this case?
  #3  
Old July 15th, 2012, 01:27 AM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: Opening closed ports on NAT device and bypassing stateful firewalls with BeEF

Quote:
Originally Posted by Gullible Jones
Eww, nasty. I cannot wait until malicious sites start using remote exploits, instead of tired old drive-by downloads.

Anyway... How would UFW's default configuration for iptables fair against such an attack? And what about Windows software firewalls? Would I be wrong in suspecting an interactive firewall might be safer in this case?
AppArmor can limit your program and resitrct them from being able to use protocols like IRC, which are necessary for protocol spoofing (haven't read it yet, assuming that's what this is.)

An outbound Firewall would prevent this as well by locking the program to specific ports.
__________________
  #4  
Old July 15th, 2012, 03:24 AM
JRViejo's Avatar
JRViejo JRViejo is online now
Global Moderator
 
Join Date: Jul 2008
Posts: 10,455
Default Re: Opening closed ports on NAT device and bypassing stateful firewalls with BeEF

Merged Threads, Eliminating Redundant Posts.
__________________
JR
"You don't have to win every argument. Agree to disagree." Regina Brett
  #5  
Old July 15th, 2012, 07:19 PM
BrandiCandi
 
Posts: n/a
Default Re: Opening closed ports on NAT device and bypassing stateful firewalls with BeEF

Quote:
If the user had FTP/ssh/etc open but it was blocked from the router, it can now be forwarded for anyone to access (read: attack) from the outside world.
So the key there is that the user has some kind of server (FTP, ssh, etc) running. If you don't there's nothing to forward.

http://samy.pl/natpin/
  #6  
Old July 16th, 2012, 09:07 AM
xxJackxx's Avatar
xxJackxx xxJackxx is offline
Very Frequent Poster
 
Join Date: Oct 2008
Location: USA
Posts: 2,537
Default Re: Opening closed ports on NAT device and bypassing stateful firewalls with BeEF

Quote:
Originally Posted by BrandiCandi
So the key there is that the user has some kind of server (FTP, ssh, etc) running. If you don't there's nothing to forward.

http://samy.pl/natpin/

I'd probably want to make sure 135-139 and 445 were closed as well. I've found internet accessible shares that were meant to be private because those ports were open.
  #7  
Old July 16th, 2012, 12:16 PM
Gullible Jones
 
Posts: n/a
Default Re: Opening closed ports on NAT device and bypassing stateful firewalls with BeEF

Quote:
Originally Posted by BrandiCandi
So the key there is that the user has some kind of server (FTP, ssh, etc) running. If you don't there's nothing to forward.

http://samy.pl/natpin/

Doesn't Windows, by default, keep ports open beneath its firewall though?
  #8  
Old July 16th, 2012, 12:37 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: Opening closed ports on NAT device and bypassing stateful firewalls with BeEF

There are at least 3 open ports on Windows by default for the NetBIOS or something else.
__________________
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:59 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums