Ross ROSS = Recommend OSS · open-source software intelligence for agents

samyk/slipstream

NAT Slipstreaming allows an attacker to remotely access any TCP/UDP services bound to a victim machine, bypassing the victim’s NAT/firewall, just by anyone on the victim's network visiting a website observed · 2026-08-28

github.com/samyk/slipstream · homepage · Perl observed · 2026-08-28

Health v2 · maintenance only

32/100

  • Activity 0
  • Release rhythm 35
  • Longevity 100

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2132
  • days_rel: n/a
  • days_push: 1327
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1984 stars · 214 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

NAT Slipstreaming is a security research tool by Samy Kamkar that demonstrates remotely opening arbitrary firewall pinholes through a victim's NAT by exploiting browser behavior and Application Level Gateway (ALG) connection tracking. It chains timing attacks, WebRTC IP extraction, packet fragmentation control, and protocol confusion to bypass NAT/firewall port restrictions.

Use cases

  • test whether a NAT router is vulnerable to slipstreaming attacks
  • demonstrate firewall pinhole bypass via browser exploitation
  • research ALG connection tracking vulnerabilities in routers
  • verify NAT/firewall protections against protocol confusion attacks
  • study packet fragmentation and MTU manipulation techniques
  • audit network perimeter security against browser-driven NAT attacks

When to choose

  • you are a security researcher studying NAT/ALG vulnerabilities
  • you need to test router or firewall resilience to pinhole attacks
  • you want a reference implementation of the NAT Slipstreaming attack chain

When to avoid

  • you need a general-purpose penetration testing suite
  • you want a supported tool with a license or active maintenance
  • you are looking for defensive firewall configuration tooling rather than an exploit demo

Facets

cli-tool · maturity maintenance

security networking penetration-testing security networking penetration-testing cli nat-slipstreaming firewall-bypass nat-pinhole alg-exploit attack-research proof-of-concept perl linux macos

2 sources

Member repositories

RepositoryRoleHealth v2
samyk/slipstreammain32

For agents

markdown · JSON · MCP: product_card(name="samyk/slipstream")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem