pwnatpy
NAT traversal tool - peer-to-peer communication through NATs without port forwarding
pwnatpy enables direct communication between a client behind a NAT and a server behind a separate NAT without any port forwarding, DMZ, UPnP, or third-party proxy. The connection is established peer-to-peer using ICMP Time Exceeded packets to penetrate NATs.
Install
pip install pwnatpy
Usage
Server Mode
pwnatpy -s [bind_ip] [proxy_port] [[allowed_host]:[allowed_port] ...]
Example:
sudo pwnatpy -s 0.0.0.0 2222
Client Mode
pwnatpy [local_ip] <local_port> <proxy_host> [proxy_port] <remote_host> <remote_port>
Example:
sudo pwnatpy 127.0.0.1 0 3.3.3.1 2222 192.168.1.100 22
How It Works
The pwnat protocol operates in three phases:
-
NAT Penetration (ICMP-based)
- Server sends periodic ICMP Echo Request packets to 3.3.3.3 (fake destination)
- Client sends ICMP Time Exceeded packets containing the server's original packet
- Server's NAT recognizes the inner packet and forwards the ICMP to the server
- Server extracts client's public IP address from the ICMP payload
-
UDP Session Establishment
- Server sends UDP packets to client (initially dropped by client's NAT)
- Client sends UDP packets to server (server's NAT allows as it's responding to server's outgoing packets)
- Both NATs now have "pinholes" allowing bidirectional UDP traffic
-
TCP Tunneling
- UDP tunnel carries TCP payload between client and server
- Custom protocol handles reliability, ordering, and flow control
Requirements
- Root/sudo privileges (required for raw socket access)
- Python 3.11+
CLI Options
| Option | Description |
|---|---|
-c |
Client mode (default) |
-s |
Server mode |
-6 |
Use IPv6 |
-v |
Increase debug verbosity |
-a |
Enable SO_REUSEADDR |
-p |
Enable SO_REUSEPORT |
Development
git clone https://github.com/user/pwnatpy.git
cd pwnatpy
pip install -e ".[test]"
# run tests
pytest
# format
ruff format src/ tests/
# lint
ruff check src/ tests/
# type check
mypy src/
Version
v0.1.0.1
Metadata
Release files for pwnatpy 0.1.0.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| pwnatpy-0.1.0.1.tar.gz | 10.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| pwnatpy-0.1.0.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 24.9 kB
Release files / pwnatpy-0.1.0.1.tar.gz
| Download URL | pwnatpy-0.1.0.1.tar.gz |
|---|---|
| Size | 10.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
3b1266e1e877077238a36ae95925a75847488c73b5b8746d07d679486ad707e9
|
|
BLAKE2b-256 checksum How to use checksums |
8e07ca654b2aff1c8dac5cf60bd3905dc3dc5960dab2102f204fffe07afd4a8e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Mar 24, 2026.
Transparency logRelease files / pwnatpy-0.1.0.1-py3-none-any.whl
| Download URL | pwnatpy-0.1.0.1-py3-none-any.whl |
|---|---|
| Size | 14.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
8bbd45b5095a5c9cc2a06fdb880df7941b9c5654685379c12d19c7ee21d05508
|
|
BLAKE2b-256 checksum How to use checksums |
7f568d9d06218ac49fe5ff45b37e71b76b54921d9690452f2ec81207bfa5701a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Mar 24, 2026.
Transparency log