[00:06.080 --> 00:21.520] And this is my experience. [00:22.980 --> 00:25.420] You ready? [00:37.800 --> 00:39.520] Waiting for the camera guy. [01:24.840 --> 01:25.920] Good evening. [01:26.220 --> 01:27.180] It's 9 o'clock. [01:29.420 --> 01:30.600] This isn't the bar. [01:30.760 --> 01:31.780] What are you guys doing here? [01:34.720 --> 01:35.860] My name is Joe Klein. [01:37.020 --> 01:40.680] The name of this talk is IPv6 Next Generation Network Playground. [01:40.920 --> 01:41.120] Yes. [01:41.260 --> 01:42.820] How to connect and explore the network. [01:43.320 --> 01:43.880] Can I see? [01:44.200 --> 01:45.040] Well, let's see. [01:45.080 --> 01:46.080] I'll have to step aside. [01:46.620 --> 01:49.340] Hands on people that are running IPv6 today. [01:51.040 --> 01:51.460] Now. [01:52.000 --> 01:56.440] Now, everybody else put their hand up because there's a good chance IPv6 is on your network. [01:56.580 --> 02:01.180] By the end of this presentation, we're going to talk about all the systems that are potentially vulnerable. [02:02.100 --> 02:04.000] Let me do the standard disclosure. [02:04.260 --> 02:04.460] Yes. [02:04.540 --> 02:06.240] I am responsible for this presentation. [02:06.300 --> 02:06.980] Not my day job. [02:07.380 --> 02:08.320] Not my customers. [02:08.540 --> 02:09.160] Not my girlfriend. [02:09.300 --> 02:09.760] Not my laptop. [02:09.900 --> 02:10.240] Not my dog. [02:10.320 --> 02:11.120] I don't have a dog. [02:11.200 --> 02:12.620] But, you know, we'll get over that. [02:14.780 --> 02:17.020] I've been researching this for about five years. [02:17.240 --> 02:21.560] This is the first time I've gone to a conference and really talked about some of my discoveries. [02:22.060 --> 02:25.080] Some of the vulnerability towards the end we're going to discuss. [02:26.500 --> 02:28.040] It's been around for two years. [02:28.280 --> 02:34.020] We've been friends of mine and I are trying to get certain people to fix these problems. [02:34.160 --> 02:37.020] It takes a while until we tell them, hey, guess what? [02:37.200 --> 02:39.780] We're going to talk about this at a hacker conference. [02:40.100 --> 02:42.940] So, they suddenly decided to move. [02:43.560 --> 02:47.740] We're going to talk about a background on IPv6. [02:47.920 --> 02:50.880] I mean, how did we get to the mess that we're in right now? [02:51.000 --> 02:52.340] And we'll talk about what that mess is. [02:52.340 --> 03:01.760] I want to talk about the features of IPv6 that are going to provide a lot of us, especially in the security field, a lot of features that we'll be able to use and control. [03:02.960 --> 03:05.460] And also some privacy issues, which is pretty cool. [03:06.260 --> 03:07.140] How to connect. [03:07.440 --> 03:13.860] You know, what are the three steps that we need to do to connect a system, a network, whatever, up to the Internet? [03:14.120 --> 03:16.160] And lastly, some testing we performed. [03:16.500 --> 03:19.540] And if we have the time, we'll show the demo of the vulnerability. [03:21.240 --> 03:22.000] Okay. [03:24.920 --> 03:32.440] The Internet, IPv4 Internet, really started with NCP back in the 60s. [03:32.480 --> 03:45.780] It was a concept that DOD was tired of paying the price of shipping scientists back and forth so that one scientist could actually view the records and programs of another scientist. [03:45.780 --> 03:52.000] So an East Coast scientist would have to see something, and they'd have to fly to the West Coast to actually run that application. [03:52.300 --> 03:56.100] So they came up with the concept of NCP. [03:56.560 --> 03:58.600] Unfortunately, it had a limited address space. [03:59.580 --> 04:00.940] 256 devices. [04:01.160 --> 04:01.940] Kind of small, right? [04:03.860 --> 04:07.300] Really, it was based on a lot of the concepts from the 60s. [04:08.820 --> 04:17.080] Currently, IPv4 is based on a lot of computing environment ideas, mini computers, mainframes from the 70s. [04:17.080 --> 04:26.980] Our operating systems that IPv4 were based on is early versions of BSD, Linux, UNIX, applications, networks, programming languages. [04:27.240 --> 04:38.020] And we've gotten a lot of operational experience and real headaches, especially on the security and the operational side in the 90s and 2000s. [04:38.020 --> 04:45.420] The results are that IPv4 is suffering from its success, and we're going to talk about what that suffering really is. [04:47.300 --> 04:50.420] We're going to also talk about why IPv6 is ready to go today. [04:52.200 --> 04:53.420] Okay, current problem. [04:54.660 --> 04:59.000] IPv4 was designed with the capability of providing end-to-end connectivity. [04:59.000 --> 05:10.840] So, if I had an application, if I wanted to telnet into a system, if I was authorized to telnet into that system, I'd be able to telnet into the system without all the crazy nets and all the other complexity. [05:10.840 --> 05:14.440] I didn't have to have lots of code to actually perform that activity. [05:15.520 --> 05:19.400] Today, we have this real inability to make that connection anymore. [05:20.740 --> 05:26.540] The reason is that back in 1990, there was a perception that we were running out of addresses. [05:27.100 --> 05:31.640] IETF announced publicly in 1990, we're running out of IP addresses. [05:31.880 --> 05:34.420] Yes, this has been around a long time. [05:36.020 --> 05:40.600] So, after about four years, they determined, hey, we need to do something about this. [05:40.840 --> 05:55.340] They decided to put some stopgap measures in place so that we could extend IPv4 as long as we could, but give time for IPv6 to be a generator, this new technology. [05:55.340 --> 05:57.860] At the time, it was IPNG. [05:58.320 --> 06:01.280] At the time, Star Trek Next Generation was hot. [06:01.460 --> 06:03.880] Can you, you know, next generation IP? [06:04.160 --> 06:04.520] Yeah, okay. [06:04.720 --> 06:05.680] Very creative geeks. [06:07.640 --> 06:09.580] So, we ended up with a lot of workarounds. [06:09.740 --> 06:11.140] We established gateways. [06:11.460 --> 06:14.760] Again, NCP, we had to establish gateways to connect. [06:14.980 --> 06:18.320] We created v4, so we didn't have to establish gateways. [06:18.440 --> 06:22.140] We started running out of address space, and now we have to create more gateways. [06:22.140 --> 06:28.400] These gateways were using NAT and PAT, network address translation, port address translation. [06:28.680 --> 06:39.400] We then had to establish the 1918 space because people were trying to suddenly apply, say, Berkeley IP addresses internal to large corporations. [06:40.000 --> 06:47.060] Anybody working in the early to mid-90s ran into this on a regular basis, where somebody would say, I can't get to this website, or I can't get to... [06:47.060 --> 06:54.040] Well, yeah, your whole domain is based on AT&Ts, and you can't route internally to AT&T. [06:54.040 --> 06:57.980] We also saw a lot of mapping of standard ports. [06:58.160 --> 07:12.420] Port 80 suddenly became port 81, port 82, port 794, whatever the programmers had to deal with, because we only had one address for a small amount of addresses for a small amount of servers. [07:12.420 --> 07:16.540] We also had multiple address ranges that we have today. [07:16.760 --> 07:28.520] Most organizations have address ranges from maybe two, three, four, maybe a dozen, maybe a hundred, maybe in certain organizations, a thousand address ranges. [07:29.300 --> 07:35.920] And mapping all of that through the firewall so that we have connectivity, it's very error-prone. [07:35.920 --> 07:38.080] So we have some real problems there. [07:38.280 --> 07:41.860] So the real workarounds have resulted in nested NAT. [07:42.100 --> 07:48.440] There are cases in India that NAT is six to seven levels deep. [07:48.660 --> 07:51.180] Can you imagine programming in that scenario? [07:52.060 --> 07:55.620] Voice over IP, mmm, real good application at that point. [07:55.920 --> 07:57.420] A lot of broken applications. [07:57.820 --> 08:08.060] Those of us that had to run, I don't know, file share across NAT broke the protocol, so then Microsoft had to make changes, make it even more complex. [08:08.780 --> 08:20.240] We had established in the, around 2000, the programming community said, heck, this NAT stuff is just a pain to our application, so let's create some workarounds for this. [08:20.240 --> 08:29.700] So the programming community, supported by AOL, Microsoft, fund people like that, they created technologies like STUN and TURN and ICE. [08:29.700 --> 08:40.440] So today what we have is we have a lot of applications that we have in our internal networks that all have these additional libraries, these additional code libraries. [08:40.480 --> 08:43.360] We also have to have these in our firewalls, in our routers. [08:43.480 --> 08:48.720] So we basically are getting to a code bloat scenario in a lot of our situations. [08:49.040 --> 08:53.780] And some of that code really wasn't fully tested in the past. [08:54.800 --> 08:59.860] Anyway, we end up with more gateways, real complex infrastructure, security. [09:01.120 --> 09:12.420] If you are in an organization that has, say, four Internet connections, three or four DMZs, a dozen extranets to customers, mapping that is a total headache. [09:12.700 --> 09:22.820] And then ensuring from an auditing standpoint, from an assessment standpoint, from a penetration test standpoint, it's very easy because you know they're going to make a mistake in it, because it is so complex. [09:24.440 --> 09:30.900] It takes a lot of time, effort, and you really have an inability to identify devices on a network. [09:31.060 --> 09:40.840] Has anybody performed an assessment and all of a sudden realized, hey, there's this whole other network hiding behind this NAT box that somebody decided to put up? [09:41.040 --> 09:42.700] Anybody run into that scenario? [09:43.140 --> 09:44.740] You know, I have many times. [09:45.680 --> 09:53.160] So really, IPv6 is focused on removing those gateways again so we can see and touch those devices. [09:53.820 --> 10:14.400] Reduce the application protocol and security complexity so we can start, you know, down the path where we have simpler code, a more secure code, and also reestablish the end-to-end connectivity so we don't have to have specialized voice over IP gateways to be able to jump four or five NAT environments. [10:16.380 --> 10:18.660] The justification... ooh, there we go. [10:19.100 --> 10:20.780] Justification, the second justification. [10:21.160 --> 10:22.920] We have a lot of devices. [10:23.320 --> 10:26.720] How many of you have more than one phone with you? [10:27.920 --> 10:29.140] And a computer. [10:29.460 --> 10:30.540] That's three addresses. [10:30.540 --> 10:40.780] How many of you have, well, like I do, TiVos and Apples and our own little networks and two firewalls and all the other things at home? [10:41.840 --> 10:55.260] Companies like the cable companies, Comcast, Verizon, Fios, they're now realizing that their customers really need anywhere from 10 to 20 to 50 addresses within their address space, their home address space. [10:55.400 --> 10:59.880] And right now they're all behind NAT, so it causes a lot of complexity. [10:59.880 --> 11:02.080] We also have Xbox. [11:02.360 --> 11:03.580] I guess everybody has an Xbox. [11:03.840 --> 11:05.300] It has an address also. [11:05.620 --> 11:08.820] So we have a lot of IP addresses. [11:09.240 --> 11:11.200] We don't even have the list of sensors. [11:11.420 --> 11:17.000] We see a lot of IPv6 sensors for temperature and cameras and things like that now being deployed. [11:17.260 --> 11:29.220] So at this point we have, by 2012, we're expecting about 16 billion devices, unique devices, on the NAT. [11:29.220 --> 11:31.800] That's about four times bigger than the current Internet. [11:32.100 --> 11:34.280] I mean, that adds a lot of complexity. [11:34.300 --> 11:39.120] I'm not sure if you guys want to map all those NATed firewalls around, then it's kind of crazy. [11:41.040 --> 11:42.400] We also have an address exhaustion. [11:42.980 --> 11:49.940] To be able to reach out and touch those specific devices, people have to have those addresses. [11:49.940 --> 12:00.480] So if the organization you're with has to suddenly implement a new network, or maybe integrate two additional networks, they have a new idea. [12:00.860 --> 12:04.780] Getting access to address space is getting harder and harder. [12:04.960 --> 12:10.320] And because it's getting harder and harder, it's requiring more complex firewall setups, routing setups. [12:10.320 --> 12:13.160] It's making it a real mess. [12:13.500 --> 12:20.020] Also, a lot of countries that were only allocated just a few addresses have moved to IPv6 today. [12:20.320 --> 12:26.160] Some of those customers, some of those people are customers of some of your companies and organizations. [12:27.960 --> 12:36.220] So what we have is basically people with IPv6 addresses trying to communicate with IPv4, which doesn't work. [12:36.540 --> 12:44.240] And a lot of organizations really won't even know that their customer base is dropping off until their help desks start increasing. [12:44.280 --> 12:47.540] And people are saying, look, I'm trying to get to you via v6 and I can't. [12:47.860 --> 12:50.440] But most of our customers wouldn't say that, would they? [12:50.520 --> 12:53.880] They would say, I can't get to your website and drive your help desk people crazy. [12:55.760 --> 13:04.400] So we're basically at a point right now that a lot of organizations need to put an outside-facing IPv6 infrastructure in place. [13:04.820 --> 13:13.560] Unfortunately, as we go into the vulnerabilities that we've done research on, you're going to notice that there's a lot of business apathy, denial of service. [13:13.640 --> 13:17.840] Yes, that's a new buzzword I'm trying to implement across the community. [13:17.840 --> 13:28.580] And that's where businesses decide not to take action, just like we had with wireless access points, where security really isn't implemented until we start seeing bad things. [13:28.700 --> 13:30.540] We don't want to see bad things this time. [13:32.340 --> 13:33.620] Yes, you are here. [13:33.640 --> 13:36.540] And yes, you might be here if you don't know it. [13:36.580 --> 13:43.700] If you notice, that's the IPv4 network, a diagram, with the IPv6 network ten years later. [13:43.700 --> 13:46.360] Yes, the IPv6 network does exist out there. [13:46.500 --> 13:47.600] There are a lot of nodes. [13:48.360 --> 13:49.740] It is currently routing. [13:49.900 --> 13:57.320] Matter of fact, I attempted to get us on the IPv6 network here at this conference so people could start playing with it. [13:58.700 --> 13:59.540] Not this time. [14:00.880 --> 14:13.240] It's a pretty big network as we see depletion of the addresses we're expecting the IPv6 to look more like the IPv4 within the next five to eight years. [14:14.780 --> 14:17.800] Okay, so let's review some of the features of IPv6. [14:17.800 --> 14:23.440] If you haven't seen an IPv4 versus IPv6 address, yes, it's a lot longer. [14:23.680 --> 14:27.080] Yes, you will learn how to type a lot more accurately. [14:27.080 --> 14:31.920] But, if you notice the grayed out zeros, not enough caffeination. [14:32.180 --> 14:33.200] It's nine o'clock. [14:34.340 --> 14:37.720] Also, the capability of doing stateless auto configuration. [14:38.180 --> 14:44.260] The ability to make one-line configuration your router and support thousands of systems behind it. [14:44.640 --> 14:46.760] Minimal change, minimal configuration. [14:47.260 --> 14:49.900] The ability to actually see multicast implemented. [14:50.120 --> 14:53.260] Single data stream that can have multiple drops. [14:53.260 --> 14:57.020] So we can finally, you know, reduce the bandwidth going out. [14:57.520 --> 14:59.440] Extension headers and mobility. [14:59.620 --> 15:05.720] Extension headers so we can add new features without being forced to, say, maybe coming up with an IPv7 or 8 or 9. [15:07.100 --> 15:08.640] At least in our lifetime. [15:10.560 --> 15:11.560] IPv6 mobility. [15:11.560 --> 15:18.680] It can be done with IPv4 and that is that a specific node can have an address that follows them. [15:19.220 --> 15:23.980] So things, connections don't get dropped as they run across the network. [15:24.120 --> 15:30.720] Right now, it's been attempted with IPv4 and there's just not enough address spaces to deal with, say, all the cell towers in the United States. [15:31.360 --> 15:32.500] Very difficult problem. [15:33.240 --> 15:35.600] Another really neat thing is the jumbogram. [15:35.780 --> 15:39.540] The capability of having PIT packets that are 6GB. [15:40.560 --> 15:45.020] That's going to make data transfers and a lot of other things very, very effective. [15:45.680 --> 15:52.420] Simplify the routing because now all the packets are on 64-bit alignment. [15:52.900 --> 15:59.320] So we're really reducing the processing our routers have to go through by reducing the L3 checksum. [16:00.100 --> 16:00.580] QoS. [16:00.780 --> 16:05.320] The QoS provides a lot more granularity. [16:05.480 --> 16:08.320] We have both a traffic class and a flow class. [16:08.880 --> 16:13.560] So the application can actually say, hey, I need this kind of capability. [16:13.560 --> 16:18.260] And the routing infrastructure can say, this is all I can provide you or this is what I can provide you. [16:18.500 --> 16:20.580] And be able to provide some custom routing. [16:21.260 --> 16:23.200] In addition, privacy addressing. [16:24.680 --> 16:29.140] Today, if we connect out, we're directly connected to the Internet. [16:29.140 --> 16:33.000] We have a globally routable address. [16:33.860 --> 16:37.820] That address is pretty much assigned to us during that connection time. [16:37.980 --> 16:42.700] So if we bring up a browser or somebody tries to connect to us, it's the same capability. [16:42.900 --> 16:47.100] The privacy address has the ability to provide you a temporary random address. [16:48.760 --> 16:54.200] And in some cases, you can browse for five minutes and you get another address for the next browse. [16:54.580 --> 16:55.740] Kind of makes it nice. [16:58.240 --> 16:59.780] Let's talk about the addresses. [16:59.780 --> 17:01.680] We have the left side and the right side. [17:01.680 --> 17:04.020] Not to be confused with the political situation. [17:04.920 --> 17:08.400] The left side was really allocated by Aaron. [17:09.200 --> 17:12.780] Currently, the 1 8th space is what's been allocated. [17:12.780 --> 17:14.580] We have a lot more space to go. [17:16.980 --> 17:22.640] IANA has issued blocks of it to the five regionals around the world. [17:23.800 --> 17:27.620] We then have the ISPs, which are assigned a slash 32. [17:27.900 --> 17:30.580] And as you can see from the red, that's a lot of address space. [17:32.300 --> 17:47.020] End sites can be allocated a slash 48, which is equivalent to a B, a slash whatever, 16 in IPv4. [17:47.020 --> 17:51.080] So you can pretty much end up with enough space. [17:51.340 --> 17:56.280] Small companies and home users themselves end up with 254 networks at home. [17:56.480 --> 17:57.280] Wouldn't that be neat? [18:00.220 --> 18:03.840] Again, notice everything is 64-bit boundary. [18:05.220 --> 18:07.840] Everything to the right, by the way, is locally assigned. [18:07.940 --> 18:09.600] We're going to talk about the right side. [18:11.180 --> 18:25.740] On this segment itself, the local host assignment, even for a single IPv6 address, that's enough hosts I think I could get away with for a little while within my house. [18:27.960 --> 18:32.420] We also have, if the system is self-assigned, if it self-assigns an address. [18:32.840 --> 18:38.880] We also have the vendor ID associated in the address. [18:38.880 --> 18:41.960] That could be very handy from an assessment standpoint, maybe. [18:42.700 --> 18:47.540] We have an FFFE, so that we can see that it is a self-assigned address. [18:47.540 --> 18:51.820] Then we have a vendor alignment or a vendor assignment. [18:52.080 --> 18:57.900] By the way, just like in IPv4, we have different ways we can allocate addresses. [18:58.120 --> 18:59.020] We can hard code them. [18:59.100 --> 19:01.340] That's totally a pain and very difficult to manage. [19:01.340 --> 19:06.380] We have the stateless auto-configuration, where it creates addresses like this. [19:06.620 --> 19:11.020] And we have the stateful addresses using DHCPv6. [19:11.020 --> 19:20.960] So it's not much different, except we get one more option in fast implemented networks, which is the stateless auto-config. [19:22.060 --> 19:23.760] Here's what the blocks look like. [19:23.760 --> 19:27.040] Yes, not to scale, so stand back. [19:28.880 --> 19:30.820] V4 address, let's be serious. [19:30.940 --> 19:32.680] It goes from 20 to 60 bytes. [19:35.400 --> 19:36.620] It changes. [19:37.060 --> 19:42.140] Again, everything is on alignment scales right there, 64-bit alignment scales. [19:42.840 --> 19:48.260] You notice a lot of the components have been dropped out, so it makes it simpler. [19:48.260 --> 20:01.180] And again, if L2 is doing CRC and L4 is doing some kind of checksum, we really don't need IPv6 doing checksum also. [20:02.380 --> 20:05.760] One of the other features it has is the ability to have extension headers. [20:06.280 --> 20:12.700] This gives us the ability to create link lists within the packets themselves and create custom configurations. [20:13.540 --> 20:17.500] So in this case, we have an IPv6 header. [20:17.980 --> 20:25.440] The header itself says, hey, here's the next packet following is going to be a TCP header and the data within the TCP header. [20:26.020 --> 20:26.820] Kind of cool. [20:28.140 --> 20:34.160] From the routing header, where we're doing source routing, we would have it the second one. [20:34.260 --> 20:37.800] And the third one might be fragmentation. [20:38.020 --> 20:39.660] I'm going to mention something about fragmentation. [20:39.660 --> 20:54.200] Unlike in V4, where fragmentation is done on path during flight, V6, the fragmentation is actually performed on the host end, on the transmission end. [20:54.300 --> 20:59.180] It makes that decision based on ICMP packets that it communicates with. [20:59.320 --> 21:02.100] And unfortunately, we don't have time to go through a lot of that fun stuff. [21:02.500 --> 21:05.300] Extension headers, here are some of the extension headers. [21:05.300 --> 21:12.600] Yes, you see IPsec authentication encryption, AHN, ESP as part of it, fragmentation routing. [21:12.840 --> 21:15.900] And yes, others exist, and others can be defined. [21:15.900 --> 21:23.600] So if there's a specific need within the industry to create a specific type of header, it's available. [21:26.440 --> 21:26.960] Okay. [21:27.300 --> 21:35.720] So, now that we know the basics and we know that V4 is running out and we have these problems, let's figure out how to get ourselves configured. [21:35.920 --> 21:44.180] Well, the first thing is, let's make sure our devices, whether it's your home or your business or as large as you want to go. [21:44.440 --> 21:47.400] We have to determine that our hosts and routers can support IPv6. [21:47.780 --> 21:49.720] We're going to show you some systems. [21:50.160 --> 21:53.900] We're going to check to see if IPv6 is already enabled on these systems. [21:53.900 --> 21:55.540] Very simple process. [21:55.820 --> 21:58.880] Then we discuss how to connect to the IPv4... [21:58.880 --> 22:02.960] Excuse me, the IPv6 Internet through three different methods. [22:04.700 --> 22:05.340] Okay. [22:05.740 --> 22:10.040] So, does anybody have an operating system that's on that list? [22:11.440 --> 22:12.080] Okay. [22:12.240 --> 22:12.780] Oh, wait a second. [22:13.000 --> 22:14.180] A second page! [22:15.680 --> 22:16.320] Okay. [22:17.240 --> 22:18.540] On by default. [22:18.840 --> 22:22.000] So, how many of you are now running IPv6? [22:22.820 --> 22:24.220] A lot more, aren't you? [22:25.900 --> 22:27.240] Kind of scary, isn't it? [22:27.880 --> 22:29.640] They forgot to tell us, didn't they? [22:34.260 --> 22:38.300] No, the Blackberry does not run IPv6 or are capable of doing networking. [22:40.760 --> 22:41.200] Okay. [22:41.540 --> 22:42.680] So, let's go to the next component. [22:44.560 --> 22:49.080] So, we want to find out that our devices will... are running IPv6. [22:49.800 --> 22:50.920] Well, here's three tests. [22:51.220 --> 22:51.660] Real simple. [22:53.100 --> 22:54.840] Type in any of those three commands. [22:54.840 --> 22:57.700] It will come back with a result, which described it in results. [22:58.260 --> 22:59.220] Those with XP. [22:59.440 --> 23:00.440] XP has it. [23:00.860 --> 23:05.280] It can... you can simply type IPv6 install and it will install in the system. [23:05.920 --> 23:11.700] By the way, that can be used by bad guys pretty easily to install v6 without you knowing it. [23:13.020 --> 23:14.600] It's kind of a side note. [23:16.980 --> 23:18.560] Oh, we're going to talk about that in a minute. [23:20.900 --> 23:21.260] Oh. [23:22.180 --> 23:23.700] Oh, by the way, the slides... [23:23.700 --> 23:27.500] I'll have an email address so you email me and I'll drop you the slides in a PDF format. [23:27.780 --> 23:29.760] With all those crazy pictures in them, yes. [23:31.380 --> 23:34.680] So, the next component we've got to deal with is infrastructure. [23:35.740 --> 23:39.700] Currently, Internet service providers come in four different flavors. [23:40.100 --> 23:45.920] We have the IPv4 only, which you're going to have to use a transition or tunnel technology. [23:46.440 --> 23:48.100] We're going to go into the details of that in a minute. [23:48.560 --> 23:56.260] We also have IPv4 ISP that they put the transition mechanism on your local network. [23:56.260 --> 24:01.420] They'll literally give you a router that has the transition mechanism pre-configured. [24:01.500 --> 24:02.740] You drop it on your network. [24:02.940 --> 24:05.780] Your internal network is completely v6. [24:06.060 --> 24:07.760] They handle all the backend. [24:08.020 --> 24:12.660] We then have very few vendors that support v4 and v6. [24:13.180 --> 24:17.600] And in just two countries, we have v6 only environments. [24:17.880 --> 24:26.580] By the way, this is a note not tearing down any company, but all the major carriers and cable companies have projects to upgrade their infrastructure. [24:27.240 --> 24:34.600] And if you call any of them, they'll say, yes, we can support IPv6, but we can't give you a firm date. [24:34.600 --> 24:36.620] Or, you know, it's a future event. [24:36.760 --> 24:38.300] Or, it's on our road map. [24:38.300 --> 24:40.380] We're not going to show you, kid, what it looks like. [24:41.260 --> 24:43.300] Or, customers aren't asking for it. [24:43.380 --> 24:47.480] So, please, go ask them and make note that you've asked them for it. [24:48.720 --> 24:55.480] A lot of them have chosen not to actually implement this technology and could cause some problems long-term. [24:56.640 --> 24:59.640] So, now we've determined the ISPs. [25:00.020 --> 25:02.060] Here's one set of mechanisms. [25:03.160 --> 25:10.360] Most of the operating systems we had on those two other tables support transition mechanisms by default. [25:10.740 --> 25:13.680] We have a transition mechanism by the name of 6-4. [25:13.720 --> 25:19.040] That is, IPv6 riding over IPv4 packets using Protocol 41. [25:19.040 --> 25:21.500] We have Isotap. [25:22.180 --> 25:24.720] And we have Terado and Merado. [25:24.880 --> 25:28.300] Yes, you can put Terado on your BSD. [25:28.880 --> 25:33.180] And it's very easy to install and a lot of Linux installs. [25:34.200 --> 25:38.140] Those are the endpoints, the protocols and configurations. [25:38.900 --> 25:41.060] Notice that there's a lot of endpoints that are public. [25:44.570 --> 25:45.130] Okay. [25:45.390 --> 25:47.710] We have the other mechanism where we can use tunnels. [25:47.710 --> 25:58.490] Here's three really good companies that support North America, give you addresses, either provide support for NAT or not. [25:58.650 --> 26:02.030] Mobility, reverse DNS, IRC, NIC handles. [26:02.290 --> 26:06.530] If you go to each of their websites, a lot of times they'll give you the configurations. [26:06.530 --> 26:14.270] If you're running Linux, UNIX, Solaris, OSX, you can configure it very, very easily. [26:14.270 --> 26:17.210] If you go to their websites, they tell you how to do it. [26:17.310 --> 26:25.950] And if it's a Microsoft box, you can download a little piece of binary and support that one specific address or a whole network. [26:28.050 --> 26:37.030] By the way, this is commercial versions, free home user version, and they have a very nice anonymous version. [26:38.570 --> 26:40.730] So let's take a look at some of the common vulnerabilities. [26:40.950 --> 26:42.910] Again, V6 is a good environment. [26:43.810 --> 26:48.890] Unfortunately, a lot of the vendors that we do business with kind of forgot to tell us that they turned it on. [26:49.230 --> 26:55.590] Has anybody ever run into wireless access points turned on by default because the vendors thought it was a great idea? [26:56.790 --> 26:58.230] They did it to us again! [27:00.810 --> 27:10.790] Here's the seven issues that I've identified over the last five years of doing assessments, testing, talking to people. [27:11.130 --> 27:23.610] First, IT and security management is unaware of the risk that things like Territo allow us to tunnel through a NAT firewall and it has its own problems. [27:23.610 --> 27:28.590] And a lot of times they're not willing to fund any IPv6 so we can ensure our tools are there. [27:30.650 --> 27:34.090] Network administrators and security administrators don't know they're there. [27:34.510 --> 27:38.210] How many of you do any auditing assessments, panteration testing? [27:38.870 --> 27:42.370] Okay, do you guys do like Sorbanes-Oxley or HIPAA or whatever? [27:42.850 --> 27:44.990] What happens if you miss a protocol? [27:45.490 --> 27:47.630] Is that assessment valid or not? [27:49.610 --> 27:52.230] Have you guys been testing for IPv6? [27:52.230 --> 27:55.290] Has your auditors been testing for IPv6? [27:55.550 --> 27:55.830] Oops! [27:56.550 --> 27:58.150] Could be a problem, couldn't it? [27:59.590 --> 28:04.690] A lot of our firewalls aren't capable of fully supporting IPv6. [28:05.470 --> 28:08.370] So we have to look for those. [28:08.670 --> 28:12.870] We have to have the ability to shut it down, enable it, and configure it properly. [28:13.930 --> 28:17.970] Over the last few years we've seen a lot of firewalls that kind of got there. [28:17.970 --> 28:23.110] A lot of the vendors are telling us they're V6 compliant, compatible. [28:23.270 --> 28:26.470] They're using lots of words, but a lot of them haven't been third-party tested. [28:26.470 --> 28:28.390] So you need to do some research on that. [28:29.070 --> 28:30.610] The IDS's and IPS's. [28:30.650 --> 28:32.450] How many of us depend on those? [28:32.850 --> 28:33.290] Yes! [28:34.310 --> 28:46.270] Lance Spitzner actually announced on a list in 2002 that a Snort didn't detect an IPv6 packet attacking, successfully attacking a Solaris box. [28:46.570 --> 28:50.490] One of the people in the next message said, Ooh, I went back a year. [28:50.750 --> 28:54.210] And I noticed that my IDS, I had to go through packet traces. [28:54.630 --> 28:58.690] My IDS didn't detect IPv6. [28:58.750 --> 29:00.330] And yes, I2 was compromised. [29:00.530 --> 29:02.290] That's all the way back to 2001. [29:04.450 --> 29:07.710] Please, make sure your IDS's and firewalls support IPv6. [29:08.490 --> 29:10.450] You can see them, you can properly process them. [29:11.750 --> 29:13.150] Security product industry. [29:13.150 --> 29:16.470] For the last five years I've been interviewing all the product vendors. [29:17.110 --> 29:19.710] Most of them are the same as the ISPs. [29:20.230 --> 29:20.610] We'll get there. [29:20.710 --> 29:21.870] Nobody's asking for it. [29:22.450 --> 29:23.470] Demand it today. [29:23.470 --> 29:24.790] We really don't have the time. [29:24.990 --> 29:26.610] We don't want another wireless scenario. [29:27.530 --> 29:29.110] Also, unpatched systems. [29:29.490 --> 29:37.090] The vulnerability specifically to the protocol and implementation of the protocol has been increasing this year. [29:37.250 --> 29:39.010] It's doubled since last year. [29:39.250 --> 29:45.730] So over the next two, three years we should start seeing a lot of vulnerabilities. [29:45.730 --> 29:47.670] Get out there and patch those systems. [29:49.430 --> 29:51.770] So, here's the answer to your question. [29:52.150 --> 29:54.210] So, can I compromise the system? [29:54.390 --> 29:57.990] Well, if we have a lab system. [29:58.490 --> 30:00.770] And we have our target across the Internet. [30:01.190 --> 30:04.270] And we attempt to do it on v4. [30:04.470 --> 30:06.330] We have good firewalls, right? [30:07.210 --> 30:09.530] We have IDS's to detect those things. [30:10.230 --> 30:17.230] Unfortunately, most environments by default do not install the v6 firewall. [30:17.730 --> 30:26.190] That's the number one vulnerability we've detected is people implement firewalls and v6 isn't on on their hosts on their systems. [30:26.390 --> 30:32.150] In fact, we were just talking with a group that I came up with that their systems weren't enabled. [30:33.750 --> 30:35.890] So, if you can see that we did a ping. [30:36.970 --> 30:37.970] And it dropped. [30:38.270 --> 30:39.130] We did a traceroute. [30:39.270 --> 30:39.730] It dropped. [30:40.030 --> 30:44.270] But if you take a look at the traceroute, we were able to get all the way into the system. [30:44.410 --> 30:45.650] Then we ran an Nmap scan. [30:45.970 --> 30:48.170] Port 80, 113, 135. [30:49.010 --> 30:50.910] Does anybody know what operating system that would be? [30:51.790 --> 30:52.130] Hmm. [30:53.030 --> 30:53.390] Hmm. [30:54.370 --> 31:00.690] Do you want to notice, remember earlier I mentioned the hexadecimal, decimal issue? [31:00.990 --> 31:02.730] Take a look at that little table there. [31:04.090 --> 31:06.290] And take a look at the IPv6 address. [31:06.290 --> 31:09.470] You see a 44, F7, 120, D. [31:09.790 --> 31:11.610] And then you see it repeat itself, don't you? [31:12.430 --> 31:18.650] Wow, if we take that v6 address and map it to v4, which is a decimal address, what do we get? [31:18.650 --> 31:22.790] We get a 68, 247, 18, 13. [31:23.350 --> 31:28.710] Hmm, that might be a problem if somebody wanted to scan a network range that we already know. [31:29.430 --> 31:31.890] This is a default 6 to 4. [31:32.050 --> 31:38.730] Again, most of the operating systems you guys are running already have v6, 6 to 4 enabled. [31:40.210 --> 31:42.150] So that's where the problem really comes in. [31:42.290 --> 31:43.310] We're seeing it a lot. [31:43.510 --> 31:45.510] Some tools to make it a little bit easier. [31:45.510 --> 31:58.690] Unfortunately, I'm writing a penetration tester defense class right now, due in September, which we're going to go through these tools and actually test them for the students and everything. [31:58.930 --> 32:02.350] This is just a very short tool list, so you can start doing something today. [32:03.850 --> 32:08.290] IP lookup, web-based, at least you can check to see v4, v6. [32:08.290 --> 32:17.030] The best thing here is the capability of looking at a v6 address and determining, does it say that this machine is an apple? [32:17.190 --> 32:19.150] Is it pre-configured as a 6 to 4? [32:19.330 --> 32:26.650] It does all that calculation for you very quickly and also allows you to test ICMP v6 pings. [32:27.690 --> 32:28.690] Some more tools. [32:29.010 --> 32:31.690] Another tool is the 6 to 4, 4 to 6 gateways. [32:32.010 --> 32:37.790] Bring up your browser, fire it up, and from a v4 Internet you can see a v6 website. [32:37.790 --> 32:40.870] From a v6 Internet you can see a v4 address. [32:40.890 --> 32:45.430] That way you can test your servers and things like that to see if those are open. [32:48.310 --> 32:57.110] The Nmap, FIDOR's wonderful tool, very limited, so if you have expectations you're going to do something with this, it's not going to work. [32:57.350 --> 32:59.550] Well, remember that slash 64 address? [33:00.110 --> 33:10.330] If you were to start this tool starting to scan, it would take about 5,000 years with the current technology to scan that whole range. [33:10.330 --> 33:15.850] So this tool only really provides one scanning, one address at a time. [33:16.150 --> 33:19.670] It only provides lists, pings, and full connect scans. [33:19.690 --> 33:21.030] So that can be a real problem. [33:21.270 --> 33:24.910] Also, you can't do a v4 and a v6 scan at the same time. [33:25.490 --> 33:28.110] Therefore, you're going to have to think about that when we're scanning. [33:28.950 --> 33:30.690] Again, you don't know what the range is. [33:30.690 --> 33:33.810] There are some additional techniques, so you'll have to learn to find those. [33:33.810 --> 33:40.870] And over the next few months, I'll be announcing each of the different techniques across the different conferences. [33:41.510 --> 33:45.890] A great tool once you have v6 on your network and you want to play. [33:46.950 --> 33:54.110] This toolkit helps you exploit misconfigured network devices that are currently running v6. [33:54.310 --> 33:59.350] Everything from, wow, redirect all your network traffic to me. [33:59.830 --> 34:00.790] It's kind of handy. [34:01.530 --> 34:02.390] Smurf tools. [34:03.330 --> 34:05.590] Remember we talked about the too big, the fragmentation. [34:06.170 --> 34:10.130] Hey, router, all my packets should be real small. [34:11.050 --> 34:12.130] Kind of problematic. [34:12.510 --> 34:15.050] So this is another really good set of tools. [34:17.710 --> 34:18.530] Okay, demo. [34:18.650 --> 34:19.770] Anybody interested in a demo? [34:20.430 --> 34:21.950] Maybe real live examples? [34:22.470 --> 34:22.990] Yeah. [34:23.350 --> 34:23.710] Okay. [34:23.710 --> 34:29.110] So, I have this little thing that maybe fits in my hand. [34:29.230 --> 34:40.230] And I went to this website, ipv6.whatismyv6.com in case anybody wants to write that down and put it onto their little tiny devices they may have in their hands or other things. [34:42.250 --> 34:44.290] It came back with an IPv6 address. [34:44.790 --> 34:49.010] And we said, ha, this was connected to our wireless LAN. [34:50.130 --> 34:52.890] And we said, hmm, this is interesting. [34:52.890 --> 34:54.810] This little portable device has this. [34:54.990 --> 34:57.450] I wonder what's going on. [34:57.510 --> 34:58.470] So we then took a look. [34:58.630 --> 35:03.210] And we found out that the 6-4 was enabled and routing already. [35:04.430 --> 35:05.790] We didn't even know this. [35:06.410 --> 35:09.310] It came to us from the store by default like this. [35:09.570 --> 35:13.150] We also had the ISATAP, the automatic tunneling pseudo. [35:13.370 --> 35:18.110] I don't have the second slide where it says tunnel adapter automatic tunneling pseudo. [35:18.110 --> 35:20.710] There's another address that's provided there. [35:21.930 --> 35:24.930] So we unplugged it and we found this information. [35:25.830 --> 35:27.090] So we restarted the phone. [35:27.210 --> 35:28.670] We said, ah, must be a mistake. [35:29.010 --> 35:30.110] Turned off the Wi-Fi. [35:30.490 --> 35:31.190] Guess what? [35:31.270 --> 35:32.450] We ended up with another address. [35:32.450 --> 35:35.350] We ended up with the default gateway on that handset. [35:35.690 --> 35:39.250] So we said, hmm, 2002 is a 6-4. [35:40.230 --> 35:46.950] We also found the ISATAP having the FE80, which meant it had two routable addresses out to the Internet. [35:47.810 --> 35:49.290] Had exactly the same gateway. [35:49.690 --> 35:51.470] So we tried the browser. [35:51.650 --> 35:56.590] And lo and behold, we were able to access a V6 network. [35:57.650 --> 35:59.150] So that could be a real problem. [36:00.030 --> 36:06.390] So then we said, hmm, what can we do with the addresses now that we can resolve a quality record? [36:06.690 --> 36:09.990] Well, just like we did before, we took the V4 addresses. [36:09.990 --> 36:12.030] We mapped it to V6 addresses. [36:12.210 --> 36:13.110] We mapped them to V4. [36:13.350 --> 36:19.170] We ended up with two ranges of IPv4 addresses for a provider. [36:19.170 --> 36:20.230] That was pretty amazing. [36:20.410 --> 36:21.750] And it had the same gateway. [36:22.290 --> 36:30.950] By the way, the 192.88.99.1 is a default gateway within V6 for one of the transition mechanisms. [36:31.570 --> 36:33.590] So we said, hey, can we trace route to it? [36:34.010 --> 36:36.310] Look, we can trace route to this phone. [36:36.410 --> 36:38.150] By the way, this was two years ago. [36:40.490 --> 36:48.270] I had to do my due diligence and make sure that people weren't hurt and informed them that they had problems. [36:48.270 --> 36:49.930] And they said, thank you very much. [36:50.250 --> 36:53.670] And, well, what can I say? [36:54.390 --> 36:55.130] You have questions? [36:55.130 --> 36:55.670] Yeah. [36:56.510 --> 36:58.050] So that's not . [36:59.050 --> 37:02.030] So is that really automatically assigned to a full address? [37:02.290 --> 37:06.550] Or is that something that your eyes keep giving you out through a value? [37:07.170 --> 37:10.330] In the case of... [37:10.330 --> 37:11.090] In the case of this phone. [37:11.290 --> 37:11.650] Yeah. [37:11.730 --> 37:14.490] In the case of this particular phone, do you see the FFFE? [37:15.030 --> 37:17.550] That's actually a self-assigned address. [37:17.750 --> 37:18.010] No, right. [37:18.090 --> 37:20.390] But the second address here, the 2002 full address? [37:26.550 --> 37:28.090] No, no. [37:28.200 --> 37:29.090] That's not a one at the end. [37:29.610 --> 37:30.040] Right. [37:30.040 --> 37:38.590] So, doesn't that mean that the phone doing 64, but your ISP doing 64 and then giving you the address of the router? [37:39.240 --> 37:39.680] Yes. [37:39.900 --> 37:45.110] With this transition mechanism, the ISP was actually providing the first 64 to create a global address. [37:45.110 --> 37:47.460] My local system was creating the other 64. [37:48.900 --> 37:49.340] Okay. [37:49.720 --> 37:51.980] So we said, hmm, we can trace route to it. [37:52.040 --> 37:52.940] What else can we do? [37:53.040 --> 37:53.820] Can we port scan? [37:53.960 --> 37:59.780] Well, two and a half years ago, one and a half years ago, and three months ago, we couldn't port scan V4 at all. [38:00.520 --> 38:03.550] And we had, hmm, very handy ports open. [38:03.720 --> 38:05.960] And again, we all know what the operating system is. [38:07.680 --> 38:14.630] Amazingly enough, after I provided this presentation back to the provider two weeks ago, things have changed. [38:16.200 --> 38:18.070] They changed the default gateway. [38:18.070 --> 38:25.070] They disabled the DNS quad A record, so I can't browse on my handy device. [38:25.980 --> 38:26.540] Kind of a drag. [38:27.070 --> 38:30.500] And all of a sudden, I'm getting IPv4 showing all filtered ports. [38:31.040 --> 38:33.540] Um, tried to end map. [38:33.860 --> 38:35.660] And here's some of the problems we found. [38:35.960 --> 38:37.780] Um, this was a device we owned. [38:37.920 --> 38:43.110] When we end mapped it, all of a sudden the data transmission failures on the device itself. [38:43.110 --> 38:44.180] We weren't able to transmit. [38:44.500 --> 38:53.180] And the battery life, it was amazing how the battery life, we kept on plugging it in and it ran out of power within about two hours. [38:53.400 --> 38:53.840] Kind of cool. [38:54.200 --> 38:55.940] And it got really hot. [38:56.240 --> 39:02.570] We had to reset it so that it reconfigured itself, so it cooled down enough and got data again. [39:02.900 --> 39:04.570] This might be a problem. [39:07.420 --> 39:07.980] Okay. [39:08.420 --> 39:09.590] Insert bad stuff here. [39:09.720 --> 39:10.940] You guys are very creative. [39:11.540 --> 39:13.280] Mmm, yeah, okay. [39:15.220 --> 39:17.720] So, which operating system we were running? [39:19.440 --> 39:20.000] Yes. [39:20.940 --> 39:22.380] Level 5 and Level 6. [39:22.660 --> 39:25.090] And by the way, we've tested other operating systems. [39:25.260 --> 39:27.220] We've informed the other operating system vendors. [39:27.220 --> 39:36.520] And, uh, again, I'm trying to practice, um, do the right thing and, um, not expose. [39:36.520 --> 39:38.050] But there's others that have it. [39:38.880 --> 39:39.660] So, wow. [39:39.740 --> 39:41.130] Which phones do we know? [39:41.440 --> 39:44.130] This is only a small list of some of the phones we found. [39:44.340 --> 39:44.860] No, we... [39:44.860 --> 39:46.440] Blackberry Curve doesn't do it. [39:46.610 --> 39:50.040] And the, uh, Sharp Sidekick, although it would have been fun. [39:50.760 --> 39:51.160] Okay. [39:51.550 --> 39:52.400] Which provider? [39:52.660 --> 39:53.220] Anybody know? [39:54.180 --> 39:55.460] Other providers, too. [39:55.980 --> 39:56.380] Okay. [39:56.720 --> 39:57.860] So, to end it. [40:05.860 --> 40:06.820] It's been a pleasure. [40:07.460 --> 40:09.640] Uh, get hold of me if you have any questions. [40:10.080 --> 40:10.380] Thank you. [40:10.980 --> 40:11.080] Applause. [40:11.080 --> 40:11.520] Thank [40:23.250 --> 40:23.430] you. [40:23.430 --> 40:24.990] Thanks for being with Mr. President. [40:26.310 --> 40:26.490] Say hi. [40:26.690 --> 40:27.130] Uh... [40:27.750 --> 40:28.190] Blackfinity? [40:28.690 --> 40:29.790] The email of the phone? [40:30.430 --> 40:31.030] Back from here. [40:31.330 --> 40:31.490] Sir. [40:31.490 --> 40:31.750] All right, sir.