5 ms·
This isn't about an attack scenario from this vector, it's about preventing reconnaissance that might yield helpful results to an adversary that can exploit it
by gxt 4y ago
This isn't about an attack scenario from this vector, it's about preventing reconnaissance that might yield helpful results to an adversary that can exploit it via any other vector.
- throw0101c 4y ago> […] that can exploit it via any other vector. And what are those vector(s)? Besides compromising a machine that is already inside per the above (which can then do scanning / lateral moves), or perhaps physically getting inside the premises (in which case a scanner can be physically installed to examine the network), what attack are you protecting against? Can you give me a link about an attack that knowing the topology of the network ahead of time would allow, but that not knowing would prevent?
- Retric 4y agoAn example of security being sidestepped is Network intrusion detection. An adversary who knows your network architecture can avoid poking around your network which looks really suspicious.
- deleted 4y ago[deleted]
- zamnos 4y agoJust because you've popped a box on the inside doesn't mean you automatically know everything about the network. It doesn't give you a mirrored port on the network switch. It doesn't mean ICMP is enabled, it doesn't automatically tell you what ports are open or what they serve. And any decent security team is going to see your nmap blast in the IDS and kick that box in jail. Seems intellectually dishonest not to acknowledge that making things easier, just y'know, makes things easier. Keeping attackers, who want to do you harm, in the dark as much as possible seems important to me.
- bert64 4y agoIPv6 actually makes such attacks more difficult, not less. An attacker looking to be stealthy is not going to blast the network with nmap... ARP is broadcast, NDP is solicited node multicast so simply by passively listening on the network you will discover nodes in the same layer 2 segment, with v6 and properly configured switches your passive discovery will be a lot more limited. Other passive techniques would be monitoring things like DNS, and things the host you've compromised is actively communicating with. This isn't any different regardless of the protocol used. You can also actively communicate with services like DNS or Active Directory and query information about the network, depending on your level of risk. Just knowing the in-use IPv6 block is useless, the blocks are massive so even just identifying active hosts in a single known IPv6 block is a lot harder than simply scanning the entire RFC1918 legacy address space. For active discovery, IPv6 is harder to attack - you can't scan the entire address block looking for hosts. The fact that such scans should be detected is exactly the same for either protocol. You also have to consider response time and what an attacker may be able to achieve before your response kicks in. IPv6 makes it harder for attackers, not easier.
- btgeekboy 4y agoCorrect. If I talk to service A and I see an address that’s in the same /64 as service B, it’s unlikely there’s a firewall between the two. Two different /56 or /48? Probably a different site.