Attacks on the IPv6 protocol stack
Summary
van Hauser explains the differences from IPv4, demonstrates weaknesses in IPv6 environments and presents the THC-IPv6 attack toolkit. A larger address field removes neither local attacks nor configuration mistakes. Unnoticed IPv6 can bypass the security rules of operations designed only for IPv4.
Ideas
- IPv6 changes addressing, neighbour discovery and automatic network configuration.
- New protocol mechanisms create their own attack surfaces beyond classic IPv4 rules.
- Packet generators make faulty assumptions in implementations reproducible.
Recommendations
- Take inventory of IPv6 on all interfaces, even if you do not use it deliberately.
- Test router advertisements, neighbour discovery and firewall rules in an isolated network.
References
Links to the original source and the Web Archive open in a new tab.