Beyond the Horizon: Uncovering Hosts and Services Behind Misconfigured Firewalls
Qing Deng, Juefei Pu, Zhaowei Tan, Zhiyun Qian, Srikanth V. Krishnamurthy
Abstract
Public IP addresses can expose devices and services to risks such as port scanning and subsequent cyberattacks. Therefore, firewalls are extensively deployed and play a critical role in enforcing security policies and preventing unauthorized access. However, vulnerabilities can allow firewalls to be by-passed, effectively nullifying the protection. In this paper, we present the first comprehensive study of a previously understudied attack surface: firewall misconfigurations that inadvertently expose protected services to the public Internet. Specifically, we demonstrate flawed firewall rules that allow inbound connections from special source ports to bypass the firewall, and explore the prevalence and security implications thereof. To this end, we scan the IPv4 space for 15 commonly high-risk TCP and UDP services from two special source ports. Our measurement reveals the widespread existence of such misconfigurations and identified over 2,000,000 otherwise unreachable services spread over 15,837 autonomous systems, expanding the “observable Internet” for various protocols by up to 12.60%. More importantly, the affected services generally exhibit higher security risks than the publicly accessible ones, like outdated software versions and weak configurations. Despite the severity of this vulnerability, our honeypot experiment provides little evidence of active exploitation in the wild. Our findings offer insights for better security posture and network administration, helping researchers and organizations anticipate and mitigate potential cyber threats emanating from the Internet.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get c5c78091-56b5-4196-a311-cacabb6ffcbfCited by top-tier papers2
- Aliens Among Us: Observing Private or Reserved IPs on the Public InternetRadu Anghel, Carlos Gañán, Qasim Lone, Matthew Luckie et al.NDSS 2026
- TED: Abusing Tunnel Hosts and IPv6 Extension Headers for Pulsing DoS AttacksLe Gai, Zedong Jia, Lin He, Daguo Cheng et al.USENIX Security 2026
Related papers
- A Large-Scale Measurement Study of the PROXY Protocol and its Security ImplicationsStijn Pletinckx, Christopher Kruegel, Giovanni VignaNDSS 2025
- On Using Application-Layer Middlebox Protocols for Peeking Behind NAT GatewaysTeemu Rytilahti, Thorsten HolzNDSS 2020
- LZR: Identifying Unexpected Internet ServicesLiz Izhikevich, Renata Teixeira, Zakir DurumericUSENIX Security 2021 · 63 citations
- Measuring and Mitigating the Risk of IP Reuse on Public CloudsEric Pauley, Ryan Sheatsley, Blaine Hoak, Quinn Burke et al.S&P 2022 · 22 citations
- Domains Do Change Their Spots: Quantifying Potential Abuse of Residual TrustJohnny So, Najmeh Miramirkhani, Michael Ferdman, Nick NikiforakisS&P 2022 · 15 citations
