Author Topic: IPv6  (Read 686 times)

0 Members and 1 Guest are viewing this topic.

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
IPv6
« on: March 24, 2014, 08:32:13 am »

Looks like we dont have to worry about going to ipv6 for a long time.
Not sure in which year the movie Dredd is supposed to be but it is a pleasant thought that its still using IPv4 :P

Hell look at this (Matrix);


More IPv4 :P

No seriously , just wanted to discuss what you guys will expect to happen to firewalling and NAT in the IPv6 realm.
In theory we don't need NAT no more yet it is the primary method of firewalling.
Any thoughts here?
« Last Edit: March 24, 2014, 08:40:31 am by proxx »
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline frog

  • Knight
  • **
  • Posts: 232
  • Cookies: 16
    • View Profile
Re: IPv6
« Reply #1 on: March 24, 2014, 10:04:05 am »
I think IPv6 is great in that it simplifies things by consolidating them. NDP is built into ICMP, which facilitates addressing and routing; almost replacing DHCP and ARP. There is a DHCPv6 functionality if you want it(nice to have options).

I do like the idea of extending ICMP with what's called Neighbor Discovery Protocol. NDP defines new packet types responsible for routing functionality similar to what ARP provides, except it's consolidated into ICMP.

I have much more to learn about using IPv6 as I don't really use it. I do know that you can send rogue 'router-advertisement' packets(ICMPv6-NDP type 134) which is equivalent to an ARP reply packet in how it functions. It's letting all computers on the network know, "i'm the new gateway; here's my address and route all traffic through me". The same thing can be done for other nodes on the network, but instead of router advertisement it's called neighbor-advertisement(ICMPv6-NDP type 136). A type 136 packet would say "here's my IPv6 address and here's my MAC" like how an ARP reply packet would function. This is the basis of a MITM attack using IPv6.

You can also use 'solicitation packets' for discovering gateways and other hosts on the network. This would be like an ARP request packet looking for other hosts on the LAN. You can see the parallels in function when comparing to IPv4, and it's apparent that they've 'cleaned' things up quite a bit by consolidating functionality.

Sources: http://en.wikipedia.org/wiki/IPv6, http://en.wikipedia.org/wiki/Neighbor_Discovery_Protocol, https://www.thc.org/thc-ipv6/README

Offline lucid

  • #Underground
  • Titan
  • **
  • Posts: 2683
  • Cookies: 243
  • psychonaut
    • View Profile
Re: IPv6
« Reply #2 on: March 24, 2014, 09:41:03 pm »
Well there certainly will be a whole new plethora of attacks.... as well as the dying of old ones. Since IPv6 won't be using ARP anymore for example. Idk, I'm just trying to figure out how I'm going to remember IP addresses once the switch happens.
"Hacking is at least as much about ideas as about computers and technology. We use our skills to open doors that should never have been shut. We open these doors not only for our own benefit but for the benefit of others, too." - Brian the Hacker

Quote
15:04  @Phage : I'm bored of Python

Offline frog

  • Knight
  • **
  • Posts: 232
  • Cookies: 16
    • View Profile
Re: IPv6
« Reply #3 on: March 25, 2014, 01:25:00 am »
Well there certainly will be a whole new plethora of attacks.... as well as the dying of old ones. Since IPv6 won't be using ARP anymore for example. Idk, I'm just trying to figure out how I'm going to remember IP addresses once the switch happens.

No shit right? Apparently I smoke too much weed to use IPv6.

Offline vezzy

  • Royal Highness
  • ****
  • Posts: 771
  • Cookies: 172
    • View Profile
Re: IPv6
« Reply #4 on: March 25, 2014, 01:51:22 am »
IPv6 certainly solves the problem of address exhaustion what with its extremely high number of combinations, but it is just as big of an insecure mess as ever, if not even more so.

Try playing around with the THC IPv6 toolkit some time.
Quote from: Dippy hippy
Just brushing though. I will be semi active mainly came to find a HQ botnet, like THOR or just any p2p botnet

Offline kenjoe41

  • Symphorophiliac Programmer
  • Administrator
  • Baron
  • *
  • Posts: 990
  • Cookies: 224
    • View Profile
Re: IPv6
« Reply #5 on: March 25, 2014, 08:09:18 am »
Idk, I'm just trying
to figure out how I'm going to remember IP
 addresses once the switch happens.
For all i know there isn't going to be a one big switch like
'hello world, we are dropping all IPv4 stuff today and switching to the
new IPv6 protocol.' Nah, we are going to live in harmony with both
protocols for quite sometime.
About remembering the ip address, well its gonna be the price we pay.
« Last Edit: March 25, 2014, 09:20:23 am by Kulverstukas »
If you can't explain it to a 6 year old, you don't understand it yourself.
http://upload.alpha.evilzone.org/index.php?page=img&img=GwkGGneGR7Pl222zVGmNTjerkhkYNGtBuiYXkpyNv4ScOAWQu0-Y8[<NgGw/hsq]>EvbQrOrousk[/img]