Perimeter
6/8/2011
01:30 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

IPv6 Graduation Day

Big Bird, Google, and Facebook participate in first high-profile test flight of new IP protocol amid DDoS threat backdrop

My first IPv6 story warning of the eventual saturation of the IPv4 address space was published a long time ago. My daughter -- who graduates from high school this weekend -- was a toddler back then. So here we are today, on World IPv6 Day, finally running a global real-world test of the next-generation IP protocol, just a couple of months before I send my firstborn off to college.

The good news about IPv6 is that unlike its predecessor -- or much of the Internet for that matter -- it was built with security in mind. IPv6 includes IPSec encryption and address space with a lot of headroom that could help prevent things like worm propagation. But the irony is that the more secure IPv6 also introduces some security issues of its own, with an architecture that's inviting to distributed denial-of-service (DDoS) attacks due to its larger headers, which require more processing by network devices, as well as the likelihood of all-new vulnerabilities in the protocol and misconfigured implementations that expose security holes.

As I write this post, there are rumblings of concern that hackers might also do a little test-drive themselves today of IPv6 to see just how easily it can be DDoS'ed. Google, Facebook, Yahoo, Cisco, and more than 400 other organizations (even Sesame Street!) are using IPv6 on their sites today in the 24-hour test flight of the 128-bit protocol, which could provide some 670 quadrillion IP addresses, experts say.

But the good news is that more people are talking about security issues surrounding the transition to IPv6. Translated: I received a lot of PR pitches over the past couple of weeks about IPv6 security implications.

Dark Reading contributing editor and blogger John Sawyer has pointed out the challenges it will bring for vulnerability scanning and penetration testing. He talks here about how new host-discovery methods will be put in place to better target vulnerability scans, for example, as well as other methods of finding IPs.

Perhaps one of the biggest problems will be its "newness." IPv6 might be nearly two decades in the making, but once users start really running it in their networks, it's sure to expose previously unknown security flaws in IPv6-based products.

The likely missteps in implementation include not allocating sufficient memory for the longer IPv6 addresses, says Rob Rachwald, which could lead to remote code execution, for example. Human error is also highly likely when handling IPv6's new configuration rules and management, he says, leaving areas of the network exposed to attackers. All it would take is one request to a server that exploits a buffer overflow flaw in an IPv6-based system, according to Rachwald, who blogged on this today. Attackers could exploit mistakes in the Internet address translation process and pose as someone within the company, or sneak past a firewall that isn't properly configured for IPv6.

But we won't know until about 8 p.m. ET tonight, when World IPv6 Day's test concludes, how IPv6 security fared in its test-entry into the real world.

-- Kelly Jackson Higgins, Senior Editor, Dark Reading Follow Kelly (@kjhiggins) here on Twitter.

Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Title Partner’s Role in Perimeter Security
Title Partner’s Role in Perimeter Security
Considering how prevalent third-party attacks are, we need to ask hard questions about how partners and suppliers are safeguarding systems and data.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-8148
Published: 2015-01-26
The default D-Bus access control rule in Midgard2 10.05.7.1 allows local users to send arbitrary method calls or signals to any process on the system bus and possibly execute arbitrary code with root privileges.

CVE-2014-8157
Published: 2015-01-26
Off-by-one error in the jpc_dec_process_sot function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image, which triggers a heap-based buffer overflow.

CVE-2014-8158
Published: 2015-01-26
Multiple stack-based buffer overflows in jpc_qmfb.c in JasPer 1.900.1 and earlier allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image.

CVE-2014-9571
Published: 2015-01-26
Cross-site scripting (XSS) vulnerability in admin/install.php in MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 allows remote attackers to inject arbitrary web script or HTML via the (1) admin_username or (2) admin_password parameter.

CVE-2014-9572
Published: 2015-01-26
MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 does not properly restrict access to /*/install.php, which allows remote attackers to obtain database credentials via the install parameter with the value 4.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
If you’re a security professional, you’ve probably been asked many questions about the December attack on Sony. On Jan. 21 at 1pm eastern, you can join a special, one-hour Dark Reading Radio discussion devoted to the Sony hack and the issues that may arise from it.