Collected research
NAT Pinning: Penetrating routers and firewalls from a web page (forcing router to port forward)
samy kamkar - NAT Pinning
A web page can make a victim's router open an inbound port with no XSS or CSRF. A hidden multipart form POSTs to port 6667 on the attacker's host; the router's IRC connection-tracking helper reads the body as a DCC CHAT request and port-forwards the named port back to the victim. The attacker chooses the port, for example 21, then connects in from outside.
Record
- Document
- samy kamkar - NAT Pinning
- Researcher
- Samy Kamkar
- Published by
- samy.pl
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Samy Kamkar, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .