ToorCon 21 - NAT PINNING 2.0 BYPASSING ROUTERS AND FIREWALLS VIA WEB NAT - Sammy Kamkar

Опубликовано: 12 Январь 2025
на канале: ToorCon
661
22

NAT Pinning is a combination of techniques to allow an attacker to remotely access any TCP/UDP services bound on a victim machine, bypassing the victim’s NAT/firewall (arbitrary firewall pinhole control), just by the victim visiting a website.
This talk will go over a new tool I'm releasing, NAT Pinning v2. NAT Pinning allows an attacker to remotely access any TCP/UDP services bound on a victim machine, bypassing the victim’s NAT/firewall (arbitrary firewall pinhole control), just by the victim visiting a website. It uses multiple techniques to be cross-platform, cross-browser, and multi-proto- col. Some areas we'll cover: - NAT (Network Address Translation) - Router Investigation
Firmware Dumping - Reverse Engineering Firmware - Network Protocol Investigation - Browser Protocols - Timing Attacks

saMy KaMKaR

Samy Kamkar is an independent security researcher, sometimes known for creating The MySpace Worm, one of the fastest spreading viruses of all time. He attempts to illustrate terrifying vulnerabilities with playfulness, and his exploits have been branded: “Controversial” -The Wall Street Journal “Horrific” -The New York Times “Now I want to fill my USB ports up with cement” -Gizmodo
His open source software, hardware, and research highlight the insecurities and privacy implications in everyday tech- nologies, from the Evercookie, which produces virtually immutable respawning cookies, to SkyJack, a drone that wirelessly hijacks and autonomously controls any other drones within wireless distance. His work has been cited by the NSA, trig- gered hearings on Capitol Hill, and has been the basis for security advancements across most web browsers, smartphones, and vehicles.