mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-06 11:38:24 +00:00
The NAT-punch packet's discriminator is a plain digest of the session id, a value both peers already know, and it travels in the clear in every probe, so a matching packet proved only that its sender had seen one. The receive loop broke on the first packet whose digest matched, whatever its source, and returned that source as the peer address. Anyone who observed a probe could therefore have an arbitrary address adopted as the peer: the legitimate traversal was denied, the handshake and its retransmissions went to an address of the attacker's choosing, and the pair was charged a failure against its backoff state. The source address is now ranked against the planned target list before anything else happens with the packet. An unplanned source is dropped and is deliberately not acked either, since acking it is a reflection this node controls. A source matching a planned target exactly is adopted immediately, as before. A source matching a planned target's IP on a different port is what a symmetric NAT's fresh mapping toward us looks like, so it is still adopted rather than dropped, because that is the main class of NAT pairing punching exists to rescue; it is held as a candidate for a settle window first, so an exact match arriving inside that window supersedes it. The honest path returns as fast as it did. Two consequences to state rather than discover. A sender able to source packets from a planned target's IP on any port is still accepted, which is the residue that only an authenticated probe can close. And an attempt under a flood of spoofed matching packets now runs to its full timeout instead of ending on the first one, so refused sources are counted and reported once when the attempt ends rather than logged per packet.