Season 4 Episode 14

Malcolm Stagg on NatJack, a New Attack Class

Malcolm Stagg

Malcolm Stagg, an Independent Researcher at Sodium-24, LLC and a member of the Synack Red Team, found his biggest research project by accident, while investigating a customer’s virtual machine on a live Synack target.

In this episode of WE’RE IN!, Malcolm walks through NatJack, a set of NAT table manipulation attacks he’s spent 3–4 years developing, and how a joke RFC document from a teammate turned a slow proof-of-concept into an attack fast enough to hijack live HTTP connections.

How does manipulating a router’s NAT table let an attacker hijack a DNS response, or take over someone else’s TCP connection? Why does this affect Linux, Windows, and Mac alike, not just one implementation? And what should security teams actually do about it, starting today?

Don’t miss Malcolm’s rundown of the mitigations that matter most and follow his research at natjack.io.