Skip to main content

Synack Red Team researcher Malcolm Stagg presents NatJack attack class

Synack Red Team researcher Malcolm Stagg presented research on NatJack, an attack class that targets design assumptions in network address translation implementations. The work is relevant to enterprise network and security teams because it focuses on how NAT behavior can be manipulated rather than on a single software coding error.

The research described how testing identified affected behavior across independently developed NAT implementations, including Windows, Linux and macOS, and how two CVEs were assigned. Stagg conducted the research over several years and credited Synack Red Team alongside his own research handle Sodium-24, of SODIUM-24, LLC.

NatJack was described as stemming from a design assumption that devices sharing a NAT table can trust one another. The research said it can be behavioral rather than signature-based, and that conventional automated scanning may not detect it. Stagg outlined four techniques: hijacking active TCP connections, poisoning DNS responses, identifying ports assigned to other connections, and forcing denial of service by exhausting a NAT table.

Two CVEs were identified as affecting Microsoft Windows NAT in Hyper-V and the Linux netfilter conntrack subsystem. The article said there was no single patch, and that available fixes included a Linux kernel patch (kernel 6.6.142 and higher) and a FreeBSD update (15.0 and higher), which raise exploitation difficulty but do not close the underlying design gap. In the interim, Synack recommended traffic encryption, segmenting untrusted workloads away from trusted ones, and enabling protections such as IP Source Guard. “Malcolm’s research on NatJack shows why effective security testing must challenge long-held design assumptions, not only search for familiar software flaws,” said Mark Kuhr, co-founder and CTO of Synack.

Provided by Globe Newswire on behalf of Synack. Click to read original content. The original article was written by Decision Insights Editorial.