How did they get past my NAT?

Oct 10, 2007 85 Replies

You seem to think that only an smpt server uses SMTP - but the only compromised SMTP servers I've seen in years were workstations/laptops where the idiot had compromised their workstation is a malware that installs its own SMTP engine - the laptop becomes a SMTP server sending out hundreds of emails with the infection included per minute. The malware, in every case, didn't attempt to use the internal SMTP server, it had it's own built into it.

There are many threats, I look for more than just the common ones.

I too have seen what I think you describe. users running as administrator get compromised their windows firewall is taken down and they end up with an smtp server and others connecting(incoming) or trying to connect. I think mostly they are saved by their NAT router. That is a common one!!

They are screwed if they run a Bridge or half bridge thing. Where there is no NAT. Like some USB dsl modems and perhaps PCI DSL modems. Typically with those things the PPP is done by windows. ipconfig displays their public ip. Malicious people connect successfully , spam gets sent out from the user`s computer and user gets a threatening email from their ISP to get rid of it or else.

But, we were talking of blocking outgoing, and thus outgoing smtp.

That's NOT what I'm saying - I'm saying that users, on a LAN, behind a NAT router with no forwarding enabled, using loaded an application that was malware and it contained a SMTP service that was sending hundreds of emails per minute. It was not allowing external connections, it was not being connected to from the net, it was it's own SMTP service spewing emails out to domains - the Windows firewall would not an could not stop this.

Yes, we are, and in this case, you've mistaken what I've said/shown, where a blocking of SMTP outbound from the LAN by the workstations, or where SMTP would be limited to the ISP's SMTP server, would block the spreading of the malware in question.

True but one of the things this also shows is that it has been ( thoroughly) peer-reviewed by ( experts).I have my doubts as well since there is a lot of potential for fraud in this space.

I like to think of it as the commercial variant to opensource software. eg with many eyes bugs are shallow.

A true Firewall is a packet and port filter and is able to filter in both directions. Basically a firewall regulates the flow of traffic between 2 or more computer networks.

It is still not a TRUE firewall because it can't filter by port.

Port forwarding is used to allow unsolicited inbound traffic to pass through to a server listening on a certain port. Port forwarding only forwards traffic on the specified port. So if you hosting email then you would enable port forwarding on port 25.

Hope that is helpful,

Hex

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required