app: nat.stun_5780 — NAT mapping/filtering discovery, verified vs live server
Hand-rolled RFC 5389/5780 STUN client (stdlib only) that exercises the server's stun-5780 capability: one socket, three binding requests (primary, OTHER-ADDRESS alternate IP, CHANGE-REQUEST port) — the comparison classifies NAT mapping and filtering behavior. Verified on the OnePlus: local 10.13.102.124 -> mapped 178.191.120.247:53259 (behind_nat true), alternate address answered from the server's second IP, mapping endpoint-independent, filtering address/port-dependent. Finding nat.symmetric (medium) for the P2P-hostile case. Two real bugs found by running it: port preservation was misread as "no NAT" (compare addresses, not ports), and an unbound socket reports the wildcard local address (resolve via a throwaway connected socket). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
dd9ecf5032
commit
483de5ca54
@@ -15,6 +15,7 @@ import app.echo_lot.probe.CaptivePortalProbe
|
||||
import app.echo_lot.probe.DnsCanaryProbe
|
||||
import app.echo_lot.probe.IcmpProbe
|
||||
import app.echo_lot.probe.LinkSnapshotProbe
|
||||
import app.echo_lot.probe.StunProbe
|
||||
import app.echo_lot.probe.NetworkInventory
|
||||
import app.echo_lot.probe.Probe
|
||||
import app.echo_lot.probe.ProbeIds
|
||||
@@ -75,6 +76,7 @@ class RunViewModel(app: Application) : AndroidViewModel(app) {
|
||||
// Canary zone served by the Echolot probe server (probe-protocol §6.1). Hardcoded to
|
||||
// the reference deployment until profiles/enrollment land in the UI.
|
||||
DnsCanaryProbe(canaryZone = "c.echo-lot.app", sessionPrefix = "adhoc"),
|
||||
StunProbe(serverHost = "fmr-1.echo-lot.app"),
|
||||
)
|
||||
|
||||
val tests = ArrayList<Test>()
|
||||
@@ -185,6 +187,20 @@ class RunViewModel(app: Application) : AndroidViewModel(app) {
|
||||
)
|
||||
}
|
||||
}
|
||||
if (t.type == TestType.NAT_STUN_5780 && t.status == TestStatus.OK) {
|
||||
val ev = t.evidence?.toString() ?: ""
|
||||
if (ev.contains("address/port-dependent (symmetric NAT")) {
|
||||
out.add(
|
||||
Finding(
|
||||
id = ids.uuid(), code = "nat.symmetric", category = Category.NAT,
|
||||
severity = Severity.MEDIUM, confidence = Confidence.HIGH,
|
||||
title = "Symmetric NAT — peer-to-peer connections need a relay",
|
||||
description = "The NAT assigns a different external port per destination (address/port-dependent mapping). Direct peer-to-peer connections (calls, games, file transfer) will usually fail and fall back to relays.",
|
||||
evidenceRefs = listOf(EvidenceRef(t.id)),
|
||||
)
|
||||
)
|
||||
}
|
||||
}
|
||||
if (t.type == TestType.ICMP_PING6 && t.status == TestStatus.FAILED) {
|
||||
out.add(
|
||||
Finding(
|
||||
|
||||
Reference in New Issue
Block a user