4 ms·
Imagine the day everyone has an IPv6 and NAT has disappear from the map... that day will be like hacking in the 90's, like MS03-026 days or even worst, it will
by SadWebDeveloper 9y ago
Imagine the day everyone has an IPv6 and NAT has disappear from the map... that day will be like hacking in the 90's, like MS03-026 days or even worst, it will definitely be a disaster waiting to happen for the network engineers and CISO's worldwide.
- solotronics 9y agonot sure if thats true, its hard to find things on IPv6 currently. Is there any practical way to scan IPv6 ranges? its so large you cant really NMAP scan around
- SadWebDeveloper 9y agohttps://news.ycombinator.com/item?id=8804629 https://news.ycombinator.com/item?id=8804629 There is no tool yet available but with IPv6 numbers going up it just matter of time before it become a necessity.
- gerdesj 9y agoIPv6 is not IPv4 (FFS.) Read up on multicast. Do you actually have any experience of IPv6?
- SadWebDeveloper 9y agoDo you actually have any experience scanning for devices on the internet? or have a proper argument rather than "learn multicast"?... so many salty net-engies on the internet, IPv6 will bring an era of chaos with every "IOT device" not being well configured and allow external access or don't have a firewall built-in.
- bb88 9y agoIsn't the entire point of having 264 address space is to make it hard to scan? Basically you're looking for a needle in a haystack.
- gerdesj 9y agoNo: 128 bit address space isn't designed to be hard to scan (see multicast for example.) One of IPv6's design goals was/is to avoid running out of address space - that means a large space. If you naively scan individual addresses then you will not get very far. Please read up on IPv6 before posting - it's been available for 19 years or so now. I'll grant you that a lot of the write ups on it are absolute bollocks but you should be able to find a reasonably good treatise somewhere. Look for names that you trust.
- bb88 9y agoIn my defense, I asked a question. :) You can answer it without being rude.
- gerdesj 9y agoRead up on multicast addresses (which IPv4 also has but not enforced) but yes, if you are not local (wire-wise) then subnet scanning will take a while.
- SadWebDeveloper 9y ago> will take a while. Like in the old days, when scanning the entire IPv4 was seen unfeasible due to the high latency low speed internet but those numbers are going up each day on both network speeds and going down for latency by the time we have 100% IPv6 deployments it will be fast enough. Mirai 2.0 in the making thanks to net-engies pushing IPv6 hard.
- mmagin 9y agoI think most corporate deployments and most home routers that do IPv6 effectively firewall inbound connection attempts much like would have been done in IPV4 NAT implementations.
- SadWebDeveloper 9y agoAlmost every cheap consumer routers just do local-only IPv6 so they disallow IPv6 on the WAN, corporate deployments actually to this day disable IPv6 due to compatibility issues with legacy hardware and software. The problems are IOT, devices that need the internet to communicate that work on the premise that NAT exists, it will take a couple of years before every cheap chinese device have a firewall built-in. Expect the next Mirai.
- johncolanduoni 9y agoSort of like the disaster that totally happened when many routers exposed UPnP to the internet by default, allowing attackers to modify NAT mappings? https://www.google.com/amp/s/arstechnica.com/information-technology/2013/01/to-prevent-hacking-disable-universal-plug-and-play-now/%3Famp%3D1 https://www.google.com/amp/s/arstechnica.com/information-tec...