Re: Port scans through NAT router?
Available news archives: comp.lang.tcl - comp.lang.python - comp.security.firewalls - sci.crypt - comp.lang.php - comp.lang.javascript
Google
 
Web news.hping.org


comp.security.firewalls archive

Re: Port scans through NAT router?

From: Duane Arnold <NotMe@NotMe.com>
Date: Mon Jan 30 2006 - 20:43:56 CET

Jeff B wrote:
> PLEASE stop playing 'king of the mountain'; you loose all credibility.
> Stick to the subject or Go embarrass yourselves elsewhere.
>
> Duane Arnold wrote:
>
>> Dom wrote:
>>
>>>> If the NAT router doesn't have SPI as part of its firmware, then
>>>> unsolicited packets/probes can come through the NAT router like a hot
>>>> knife through butter...
>>>
>>>
>>>
>>>
>>> Bullshit. For lack of a NAT mapping, the router would have no idea where
>>> to forward the traffic. Many-to-one NATs are stateful by nature. If you
>>> persist in claiming such, I suggest you present a layer 2/3 packet
>>> capture to that effect.
>>
>>
>>
>> So you know this for a fact do you? Then what is SPI all about if the
>> NAT router doesn't have it.
>>
>>>
>>> I'm guessing that this mysterious traffic is Windows multicast uPNP or
>>> netbios name requests from the Netgear.
>>
>>
>>
>> Your guess doesn't mean shit as fas as I am concerned. I know what the
>> port probes that came through the NAT router at SQL server that was
>> running on the machines on my network were about.
>>
>> You know where you can stick it.
>>
>> Duane :)
>>
>>
>
>
Hey, I didn't start this and I didn't start cussing someone out off the
top of the bat either. I grew up in the streets where you learn *NOT* to
let someone step on you. The Internet is no more than the streets to me
  and I will apply street mentality when necessary and by any means
necessary.

I hope this is the end too because I am tired of that lunatic. :)

Duane :)
Received on Tue Feb 7 20:58:25 2006