North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: IPv6 Advertisements

  • From: Dale W. Carder
  • Date: Tue May 29 21:42:43 2007



On May 29, 2007, at 8:28 PM, Donald Stahl wrote:
Scanning isn't AS EASY, but it certainly is still feasible,
With 1.5 million hosts it will only take 3500 years... for a _single_ /64!
I'm not sure that's what I would call feasible.

There are "smarter" ways to scan v6 address space than this approach. My favorite is "First, the attacker may rely on the administrator conveniently numbering their hosts from [prefix]::1 upward. This makes scanning trivial."

Take a look at:
http://www.ietf.org/internet-drafts/draft-ietf-v6ops-scanning- implications-03.txt


and

http://www.cs.columbia.edu/~smb/papers/v6worms.pdf

Dale