We did NAT see that coming: How malicious JavaScript can open holes in your firewall for miscreants to slip through

What's this? I know, I'll plug it in...

"The third chunk is designed so that it appears to contain a SIP packet used to initiate video-conferencing sessions and the like. This is parsed by the ALG, which is fooled into thinking a SIP session is starting, and opens an external port that's routed through to the victim's PC."

So this is the ALG (Application Level/Layer Gateway) picking up a 'lost' thumb drive in the parking lot and plugging it in to a USB port to see what's on it? Who knew that was a bad idea...

