 NormanS Premium,MVM join:2001-02-14 San Jose, CA | reply to Inflex Re: home web server
I set up a cousin behind NAT. Kind of hard to reach his computer from the Internet. -- Norman ~Oh Lord, why have you come ~To Konnyu, with the Lion and the Drum |
|
  Inflex
join:2002-09-05
| said by NormanS :I set up a cousin behind NAT. Kind of hard to reach his computer from the Internet. Not with the right tools. AT&T researchers cracked NAT about a decade ago. |
|
 NormanS Premium,MVM join:2001-02-14 San Jose, CA | What tools would one need? $50 off-the-shelf stuff from your local Fry's Electronics, or $50,000 stuff only the NSA can afford? -- Norman ~Oh Lord, why have you come ~To Konnyu, with the Lion and the Drum |
|
  Inflex
join:2002-09-05 | Just plain old software. |
|
 NormanS Premium,MVM join:2001-02-14 San Jose, CA | Show me. |
|
  Inflex
join:2002-09-05 edit: June 16th, @12:31PM
| Google is your friend. |
|
 NormanS Premium,MVM join:2001-02-14 San Jose, CA | You posted it, you prove it. |
|
  Inflex
join:2002-09-05
| said by NormanS :You posted it, you prove it. With an attitude like that?
Nah...I don't have the time. |
|
 NormanS Premium,MVM join:2001-02-14 San Jose, CA | The burden of proof of an assertion is on the one making the assertion. Nothing wrong with that attitude. -- Norman ~Oh Lord, why have you come ~To Konnyu, with the Lion and the Drum |
|
  Inflex
join:2002-09-05 | "Prove it" is much different from "That's interesting, could you point me somewhere that I can learn more?". |
|
  jdong Eat A Beaver, Save A Tree. Premium join:2002-07-09 Rochester, MI clubs:  
| reply to NormanS said by NormanS :You posted it, you prove it. Do you use Skype? Ever wondered why it can do direct peer-to-peer TCP connections without port forwarding? Skype uses many forms of NAT port-punching to fool NAT routers into forwarding ports. This usually requires some level of knowledge about the host computers (i.e. the two copies of Skype communicate first via a 3rd party Skype server to coordinate which source and destination ports to hammer)
But yes, NAT can be defeated from the perspective as a firewall and it typically only requires luring the remote party to establish one connection to you to figure out their TCP stack characteristics. -- Ubuntu MOTU Developer and Forums Council |
|
 NormanS Premium,MVM join:2001-02-14 San Jose, CA | Even HTTP can defeat NAT, in that respect. But you first have to initiate an outbound connection to accomplish that. -- Norman ~Oh Lord, why have you come ~To Konnyu, with the Lion and the Drum |
|
  jdong Eat A Beaver, Save A Tree. Premium join:2002-07-09 Rochester, MI clubs:  
| said by NormanS :Even HTTP can defeat NAT, in that respect. But you first have to initiate an outbound connection to accomplish that. No, it's not the same thing. In HTTP, the remote host is NOT behind a NAT. In Skype, the remote host IS under a NAT. By sending probe packets with mirrored src/dst ports, NAT can be fooled to allow a connection through. -- Ubuntu MOTU Developer and Forums Council |
|