Skip to content

Comment on Hacker 'handshake' hole found in common firewallsparent

Comments

The "server" doesn't necessarily need to be the target in an attack. The attacker would be in control of the server in this scenario, and the "client" is a machine within the targeted network. The "client" and "server" labels are only representative of who is initiating the tcp connection.

Hi! Thanks for your response. I didn't mean to get us hung up on the terminology. Let's call one machine the "Internet side" and one machine the "Protected side". I have read the Macrothink paper another time, and I still believe that you need to modify the behavior of the "Protected side" host (ie, you'd need to have prior access) before this attack would work. Is that incorrect?

Unfortunately, I haven't had time to read through the paper, and only got through the first few pages. From what I see though, the point of the attack is to punch through by using the improper handling of the split handshake by a client, which apparently fools some firewalls. For this to happen, you would only need to get a client to open a tcp connection to your malicious server, which is trivial. I'll have to take a closer look at the paper later on to to give more detail though. Hopefully someone else will chime in in the meantime.

And, from the Macrothink paper, it looks like it's not so much "open an inbound connection through the firewall" as "trick the firewall into not scanning the payload". Not relevant for, say, home routers that don't do scanning in the first place.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.