IPv6 Advertisements
Dale W. Carder
dwcarder at doit.wisc.edu
Wed May 30 01:37:51 UTC 2007
On May 29, 2007, at 8:28 PM, Donald Stahl wrote:
>> Scanning isn't AS EASY, but it certainly is still feasible,
> With 1.5 million hosts it will only take 3500 years... for a
> _single_ /64!
> I'm not sure that's what I would call feasible.
There are "smarter" ways to scan v6 address space than this approach.
My favorite is "First, the attacker may rely on the administrator
conveniently numbering their hosts from [prefix]::1 upward. This
makes scanning trivial."
Take a look at:
http://www.ietf.org/internet-drafts/draft-ietf-v6ops-scanning-
implications-03.txt
and
http://www.cs.columbia.edu/~smb/papers/v6worms.pdf
Dale
More information about the NANOG
mailing list