4 ms·
I'm not really seeing a vulnerability here. The entire IPv4 internet is scanned probably hundreds of times a day. Was anyone really counting on IPv6 addresses
by devicenull 11y ago
I'm not really seeing a vulnerability here. The entire IPv4 internet is scanned probably hundreds of times a day. Was anyone really counting on IPv6 addresses being longer to add security?
http://www.internetsociety.org/deploy360/blog/2015/02/ipv6-security-myth-4-ipv6-networks-are-too-big-to-scan/ http://www.internetsociety.org/deploy360/blog/2015/02/ipv6-s...
- qjighap 11y agoCould be wrong, but part getting through a firewall is establishing open ports and mapping the machines behind the firewall and since you have a verified machine name this would save bad actors a significant amount of time being that they can make the assumption that the computer exists rather than timeouts to nothing. While this goes in on the hiding an IP (disable ping) is not proper security argument it is valid that you would want to stop disclosure on such a public level.
- devicenull 11y agoIf you have a machine behind a firewall, why do you care that it's IP is secret? Do you also worry about people finding out your IPv4 IP?
- qjighap 11y agoI have worried about it the past. The more a bad actor has to thrash around the better chance an IDS will trigger. As well some older (read cheaper) firewalls have been known to allow through ACK packets through. This attack is not (IMHO) intended against properly secured sites, but rather than small business with consumer grade routers or something equivalent.
- dspillett 11y agoA machine with a random address that makes no (direct) contact with the outside world will be a lot harder to find in a 64-bit address space then a 32. As soon as it talks to the outside world though (by talking to public NTP servers in this case) that difference is rendered moot.
- clinta 11y agoUnless it's using Privacy Extensions in which case it will change it's outbound IP in a matter of hours and once again be lost in the huge address space. Unfortunately privacy extensions are not enabled by default on most linux distributions and server operating systems.
- deleted 11y ago[deleted]
- snowy 11y agoAt least most IPv4 addresses on a LAN are behind NAT. It's not a firewall but probably has saved some people.
- NelsonMinar 11y agoI've wondered that too. IP addresses have never been secrets.
- fapjacks 11y agoYou're absolutely right, I agree. I think this reaction ("Oh no! My 'private' IPs are known and being scanned!") is probably one that comes from having spent a lot of time with a personal network behind the NAT of an IPv4 router, which necessarily provides a wall to internal network scans. Using IPv6, NAT is no longer necessary, and therefore it can surprise people that aren't expecting that behavior. I thoroughly enjoyed the write-up though!