lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <1098275646.21553.7.camel@mesquite.yi.org> From: michael at puffin.tamucc.edu (michael williamson) Subject: Sending remote procedure calls through e-mail (RPC-Mail) Someone could use an email scheme like this to to trigger an outbound secure shell connection with ports forwarded from the machine its connecting to back to the machine making the connection. In this way any firewall that allows SSH can be perforated. (now replace the afformentioned email sceme with dumb users)...I how much spyware already does stuff like this? This sure does demonstrate how _useless_ NAT really is for security. -Michael