samyk / slipstream

NAT Slipstreaming allows an attacker to remotely access any TCP/UDP services bound to a victim machine, bypassing the victim’s NAT/firewall, just by anyone on the victim's network visiting a website
https://samy.pl/slipstream/
1.9k stars 209 forks source link

Uhm, Samy? #12

Closed analyserdmz closed 3 years ago

analyserdmz commented 3 years ago

Couldn't this method be used to kind of de-anonymize TOR/VPN users with some modifications? I mean, I can see the potential. Do you?

samyk commented 3 years ago

Tor and VPN traffic is encapsulated by their respective protocols so the users' router ALGs will not match the traffic and evade the attack. Let me know if you're thinking something else specifically though that I'm missing. Thanks!