On Using Application-Layer Middlebox Protocols for Peeking Behind NAT Gateways
Teemu Rytilahti, Thorsten Holz Horst Görtz Institute for IT-Security, Ruhr University Bochum, Germany Network and Distributed System Security Symposium 2020
1
On Using Application-Layer Middlebox Protocols for Peeking Behind - - PowerPoint PPT Presentation
On Using Application-Layer Middlebox Protocols for Peeking Behind NAT Gateways Teemu Rytilahti, Thorsten Holz Horst Grtz Institute for IT-Security, Ruhr University Bochum, Germany Network and Distributed System Security Symposium 2020 1
1
2
2
2
2
2
3
4
4
4
4
5
5
6
6
7
8
9
10
10
11
12
13
14
14
14
15
16
192.168.1.0/24
S A :12345 -> 192.168.1.2:139 : 3 1 2 3 5
1 9 2 . 1 6 8 . 1 . 3 : 1 3 9
17
192.168.1.0/24
S A :12345 -> 192.168.1.2:139 : 3 1 2 3 5
1 9 2 . 1 6 8 . 1 . 3 : 1 3 9 : 1 2 5 2 1
1 9 2 . 1 6 8 . 1 . 2 5 3 : 4 4 5 :43123 -> 192.0.1.254:445
17
Cloud providers :64611 -> :443 18
Cloud providers :64611 -> :443 Other vulnerable devices :12345 -> :80 18
Cloud providers :64611 -> :443 Other vulnerable devices :12345 -> :80 DNS servers :31234 -> :53 18
19
20
21
192.168.123.80:1080
Services listening on localhost 22 21 23 25 80 CONNECT 127.0.0.1:22 HTTP/1.1 22
192.168.123.80:1080
Services listening on localhost 22 21 23 25 80 CONNECT 127.0.0.1:22 HTTP/1.1 Establish TCP connection 22
192.168.123.80:1080
Services listening on localhost 22 21 23 25 80 CONNECT 127.0.0.1:22 HTTP/1.1 Establish TCP connection HTTP/1.1 200 Connection Established 22
192.168.123.80:1080
Services listening on localhost 22 21 23 25 80 CONNECT 127.0.0.1:22 HTTP/1.1 Establish TCP connection HTTP/1.1 200 Connection Established
22
192.168.123.80:1080
Services listening on localhost 22 21 23 25 80 CONNECT 127.0.0.1:22 HTTP/1.1 Establish TCP connection HTTP/1.1 200 Connection Established
SSH-2.0-OpenSSH_7.9p1 Debian-6 22
192.168.123.80:1080
Services listening on localhost 22 21 23 25 80 CONNECT 127.0.0.1:22 HTTP/1.1 Establish TCP connection HTTP/1.1 200 Connection Established
SSH-2.0-OpenSSH_7.9p1 Debian-6
22
23
23