Re: Port scans through NAT router?
Available news archives: comp.lang.tcl - comp.lang.python - comp.security.firewalls - sci.crypt - comp.lang.php - comp.lang.javascript
Google
 
Web news.hping.org


comp.security.firewalls archive

Re: Port scans through NAT router?

From: Jeff B <jbeard_No-SpAm_1185@adelphia.net>
Date: Mon Jan 30 2006 - 19:46:08 CET

PLEASE stop playing 'king of the mountain'; you loose all credibility.
Stick to the subject or Go embarrass yourselves elsewhere.

Duane Arnold wrote:
> Dom wrote:
>
>>> If the NAT router doesn't have SPI as part of its firmware, then
>>> unsolicited packets/probes can come through the NAT router like a hot
>>> knife through butter...
>>
>>
>>
>> Bullshit. For lack of a NAT mapping, the router would have no idea where
>> to forward the traffic. Many-to-one NATs are stateful by nature. If you
>> persist in claiming such, I suggest you present a layer 2/3 packet
>> capture to that effect.
>
>
> So you know this for a fact do you? Then what is SPI all about if the
> NAT router doesn't have it.
>
>>
>> I'm guessing that this mysterious traffic is Windows multicast uPNP or
>> netbios name requests from the Netgear.
>
>
> Your guess doesn't mean shit as fas as I am concerned. I know what the
> port probes that came through the NAT router at SQL server that was
> running on the machines on my network were about.
>
> You know where you can stick it.
>
> Duane :)
>
>

-- 
---
Jeff B (remove the No-Spam to reply)
Received on Tue Feb 7 20:58:25 2006