|
|
 |
 |
 |
 |
register |
bbs |
search |
rss |
faq |
about
|
 |
 |
meet up |
add to del.icio.us |
digg it
|
 |
 |
| Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net. |
 |
|
|
#1
 2004-12-12, 10:09
|
:tru 
Regular
|
|
|
|
Determining NAT traffic destinations from outside the network..
I've been wondering about this. From my understanding, when I router NAT's its network, it basically "flags" the packets with it's internal destination in the address header, when traffic leaves the network. So, the real (external) address is untouched, and outisde the network can understand it. When the traffic returns, the router peels off it's own (destination) ip address, leaving it's flagged address it stuck on there when it left the LAN. Then, it routes it back to the appropriate NAT address.
That may not be EXACTLY what happens, but that's my general understanding of it. I was sleeping thru this part of class, heh.
Anyways, my question is, say you're capturing traffic directly outside the router. What sorts of things would you look for in the source/destination address (if that's where it is), to determine it's sender's internal IP? Of course the destination would be the router's address, but somewhere in the packet, there's data about the internal host, I just dont know where exactly it is. Is it universal, or different for every router? Is there a way to filter a sniffer and capture the internal address as well as the router address?
Can someone enlighten me here?
|
|
#2
 2004-12-12, 10:24
|
edf825 
Regular
|
|
|
|
Re: Determining NAT traffic destinations from outside the network..
If you were to capture the packets, then they would only show the MAC addresses of the sources and destinations, IIRC.
|
|
#3
 2004-12-12, 18:38
|
cense 
Regular
|
|
|
|
Re: Determining NAT traffic destinations from outside the network..
Depends on the type of NAT in use. From my experience, it's all based on TCP and UDP ports. The NAT router will send a packet with a source TCP or UDP port (depending on which protocol you are using) that it "knows" (table lookup/assignment) is related to internal machine A for instance. The external end point of that connection will simply reply with that destination point and the NAT router checks it's table, then forwards it on inside.
So,
Internal Machine A sends packet to www.google.com. (http://www.google.com.) The router decides to use TCP source port 110235 for the outgoing connection and labels port 110235 as refering to Machine A. Now, any connection back to the NAT box from www.google.com (http://www.google.com) with TCP destination port set as 110235 will be routed to Machine A by a simple table lookup.
I can't be certain this is the only way NAT works without reading some RFCs, but I know this is how NAT *can* work.
|
|
 |
 |
To the best of our knowledge, the text on this page may be freely reproduced and distributed.

totse.com certificate signatures
|
 |
 |
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
|
 |
 |
 |
 |
|
|