Nice writeup from The Datatech Times on
@malcolmst and his NatJack research. Stagg first discovered that NAT table entries could be corrupted or replaced while on assignment for the Synack Red Team.
In his own words: “For a lot of business and enterprise customers, I would say the TCP and HTTP session hijacking techniques are the most dangerous, since a lot of internal network traffic is still unencrypted, and untrusted/trusted workloads often share the same NAT."
Worth the read if you want the story behind the NatJack research:
hubs.ly/Q04x8SM70