Worth Reading: NatJack

Repeat after me: NAT is not a security feature

Every time I wrote something along the lines of NAT is not a security feature, I got the expected pushback from people defending their bad suboptimal design choices.

Fortunately, rational1 engineers no longer need to have that discussion: the NatJack website documents2 a half-dozen attacks on typical NAT implementations.

Obvious next step: coping mechanisms like “this is all theoretical”, like the “but the remote host cannot reply” argument made 23 years after the Slammer worm 🤦‍♂️.


  1. Yeah, I know that’s a pretty high bar 😜 ↩︎

  2. With the expected dose of the world is burning security hype ↩︎

Add comment
Sidebar