[Battlemesh] NAT Slipstreaming (CVE-2020-28041)

Saverio Proto zioproto at gmail.com
Wed Nov 4 00:30:30 CET 2020


Hello,

I apologize for cross posting.

on 31.10.2020 this new attack was released:
https://github.com/samyk/slipstream

I am not 100% OpenWrt is vulnerable. It is also hard to say because
the Kernel Version depends on the OpenWrt target.

What are common values for:
$ uname -a
and
$ cat /proc/sys/net/netfilter/nf_conntrack_helper

?

I tried to propose this PR, but I am not sure it is the correct way to
patch OpenWrt to fix this.

https://github.com/openwrt/openwrt/pull/3564

is anyone else working on this ?

my 2 cents

thanks

Saverio


More information about the Battlemesh mailing list