On Using Application-Layer Middlebox Protocols for Peeking Behind NAT Gateways
Teemu Rytilahti, Thorsten Holz
Abstract
—Typical port scanning approaches do not achieve a full coverage of all devices connected to the Internet as not all devices are directly reachable via a public (IPv4) address: due to IP address space exhaustion, firewalls, and many other reasons, an end-to-end connectivity is not achieved in today’s Internet anymore. Especially Network Address Translation (NAT) is widely deployed in practice and it has the side effect of “hiding” devices from being scanned. Some protocols, however, require end-to-end connectivity to function properly and hence several methods were developed in the past to enable crossing network borders. In this paper, we explore how an attacker can take advantage of such application-layer middlebox protocols to access devices located behind these gateways. More specifically, we investigate different methods for identifying such devices by using only legitimate protocol features. We categorize the available protocols into two classes: First, there are persistent protocols that are typically port-forwarding based. Such protocols are used to allow local network devices to open and forward external ports to them. Second, there are non-persistent protocols that are typically proxy-based to route packets between network edges, such as HTTP and SOCKS proxies. We perform a comprehensive, Internet-wide analysis to obtain an accurate overview of how prevalent and widespread such protocols are in practice. Our results indicate that hundreds of thousands of hosts are vulnerable for different types of attacks, e.g., we detect over 400,000 hosts that are likely vulnerable for attacks involving the UPnP IGD protocol. More worrisome, we find empirical evidence that attackers are already actively exploiting such protocols in the wild to access devices located behind NAT gateways. Amongst other findings, we discover that at least 24% of all open Internet proxies are misconfigured to allow accessing hosts on non-routable addresses.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 68be668d-1ff4-4972-a383-b1ce41f94217Cited by top-tier papers3
- Identifying VPN Servers through Graph-Represented BehaviorsChenxu Wang, Jiangyi Yin, Zhao Li, Hongbo Xu et al.WWW 2024 · 6 citations
- Off-Path TCP Exploits: PMTUD Breaks TCP Connection Isolation in IP Address Sharing ScenariosXuewei Feng, Zhaoxi Li, Qi Li, Ziqiang Wang et al.CCS 2025
- ReDAN: An Empirical Study on Remote DoS Attacks against NAT NetworksXuewei Feng, Yuxiang Yang, Qi Li, Xingxiang Zhan et al.NDSS 2025
Builds on3
- Resident Evil: Understanding Residential IP Proxy as a Dark ServiceXianghang Mi, Xuan Feng, Xiaojing Liao, Baojun Liu et al.S&P 2019 · 80 citations
- A Large-scale Analysis of Content Modification by Open HTTP ProxiesGiorgos Tsirantonakis, Panagiotis Ilia, Sotiris Ioannidis, Elias Athanasopoulos et al.NDSS 2018 · 38 citations
- Scalable Scanning and Automatic Classification of TLS Padding Oracle VulnerabilitiesRobert Merget, Juraj Somorovsky, Nimrod Aviram, Craig Young et al.USENIX Security 2019 · 27 citations
Related papers
- A Large-Scale Measurement Study of the PROXY Protocol and its Security ImplicationsStijn Pletinckx, Christopher Kruegel, Giovanni VignaNDSS 2025
- Where Have All the Firewalls Gone? Security Consequences of Residential IPv6 TransitionErik Rye, Dave Levin, Robert BeverlyCCS 2026 · 2 citations
- Lost in Encapsulation: Exploiting Open Tunnelling Hosts and Attacking Private NetworksAngelos Beitis, Mathy VanhoefUSENIX Security 2026
- Haunted by Legacy: Discovering and Exploiting Vulnerable Tunnelling HostsAngelos Beitis, Mathy VanhoefUSENIX Security 2025
- Beyond the Horizon: Uncovering Hosts and Services Behind Misconfigured FirewallsQing Deng, Juefei Pu, Zhaowei Tan, Zhiyun Qian et al.S&P 2025
