[00:00.000 --> 00:05.900] ...update with Joe Klein, who is going to try to compress two hours worth of data into 55 minutes. [00:09.600 --> 00:10.140] Thank you. [00:10.220 --> 00:12.100] Now I'll have to talk as fast as Mako. [00:12.320 --> 00:13.280] Yes, I like it. [00:14.400 --> 00:19.660] So, I can't see any of you out there, but how many people are working with IPv6? [00:19.860 --> 00:20.440] Can I see hands? [00:22.040 --> 00:23.320] Okay, now leave this up. [00:23.780 --> 00:27.440] Now how many think that they're not running IPv6? [00:29.120 --> 00:32.720] Yeah, okay, you'll hear about some fun things. [00:33.480 --> 00:36.180] Okay, what we're going to talk about is the problem with IPv4. [00:36.600 --> 00:42.240] An IPv6 rethink, why IPv6 is re-engineered to add some additional features. [00:43.720 --> 00:45.180] Where's the IPv6 now? [00:45.320 --> 00:47.500] Some technical details, and I'll show you some fun traces. [00:48.320 --> 00:51.780] And what you should know, and some fun things about security. [00:53.080 --> 00:59.500] Okay, one of the problems with the Internet today is that we have only so many people on the Internet. [00:59.760 --> 01:11.280] We've seen a 400% growth of the Internet in the last 10 years, which is only accounting for about 26% of the population of the Earth. [01:12.220 --> 01:16.840] Right now the current size of the Internet, how many addresses are allocated is right there. [01:17.360 --> 01:21.780] So you can see it's willfully short, being able to support everybody. [01:22.640 --> 01:32.140] This is the maximum size of the IPv6 network once you take out multicast and broadcast network addresses and other things. [01:33.400 --> 01:38.900] So, right now we have approximately 363 days left of IPv4 addresses. [01:39.420 --> 01:39.720] Woohoo! [01:40.000 --> 01:41.320] Get yours now soon, yes. [01:43.040 --> 01:47.140] So, we're going to talk about what happens when that runs out. [01:48.020 --> 01:51.440] Websites right now, about 204 million websites. [01:51.760 --> 01:56.620] That's approximately per website, approximately 177 users per website. [01:56.620 --> 02:05.080] So, if you're going to put a new website online, and you want to attract a bunch of users, they have to have the same protocol across the Internet to get to you, don't they? [02:05.540 --> 02:05.580] Hmm. [02:07.700 --> 02:21.020] Okay, right now, according to... for online gizmos, several of the major consulting groups have stated that we should see approximately... was it 50 billion devices within the next 10 years. [02:21.800 --> 02:28.100] If you're anything like me, I have more than two devices, which is the average per user. [02:28.200 --> 02:28.780] I mean, think about it. [02:28.880 --> 02:30.160] Most of us have a phone. [02:30.360 --> 02:31.400] That is day of service. [02:35.720 --> 02:39.760] They're estimating that the average user will have 10 IP addresses. [02:40.780 --> 02:43.760] Personally, I have 26 at my own home. [02:44.320 --> 02:46.540] But, you know, I'm a little bit of an anomaly. [02:48.460 --> 02:58.740] So, what it looks like is to be able to reach out and provide data services to everybody on the earth, we're going to really have to rethink this addressing scheme. [02:58.900 --> 02:59.620] It's just not working. [03:01.820 --> 03:06.340] Okay, the problem was really recognized by IETF back in 92. [03:06.660 --> 03:14.000] What they did was they did some estimates, and they said, we're going to run out of IPv4 addresses in 2008 to 2012. [03:14.920 --> 03:20.740] A lot of this, by the way, everybody's always talking about, so when is IPv6 going to be here? [03:20.880 --> 03:22.140] When is IPv6 going to be here? [03:22.940 --> 03:24.760] This has been a long process. [03:25.100 --> 03:39.980] It required not only thinking about the problem, learning from where the current IPv4 network was, creating the specifications, getting vendors to actually support those specifications, doing testing, and actually implementing the technology out there. [03:40.340 --> 03:42.040] And you're going to see we're pretty far along. [03:42.420 --> 03:52.660] As a stopgap measure, over the last 15 years, what we've seen is we've seen implementation of other technologies, like CIDR blocks. [03:52.820 --> 03:56.760] Remember, we used to have Class A, Class B, Class C. [03:57.000 --> 03:59.360] What we did was we ended up supporting CIDRs. [03:59.400 --> 04:03.820] We ended up supporting DHCP, which is a good thing for anybody that administers large networks. [04:04.820 --> 04:06.240] We ended up implementing NAT. [04:06.400 --> 04:07.100] NAT is bad. [04:07.800 --> 04:13.740] We also ended up implementing RFC 1918, which turned out to have its own challenges. [04:15.580 --> 04:25.140] Has anybody had to implement communications between two RFC 1918 addresses, when you have two companies coming together, two organizations together? [04:25.620 --> 04:27.520] Okay, did you pull your... oh, you still have hair. [04:27.680 --> 04:28.080] That's good. [04:28.660 --> 04:29.460] Yeah, yeah. [04:29.560 --> 04:39.840] I almost pulled my hair out trying to implement four systems, four networks all coming together and doing the IP mapping, the static, the dynamic, what ports were going to be supported. [04:40.220 --> 04:41.620] Yeah, it's pretty maddening. [04:42.480 --> 04:43.400] Future of the Internet. [04:43.840 --> 04:47.960] Without additional addresses, what we're seeing is it's becoming more complex. [04:48.700 --> 04:54.080] There are networks, as an example in India, which are seven levels deep of NAT. [04:55.520 --> 04:56.000] Okay. [04:56.280 --> 04:56.740] Woo! [04:57.120 --> 04:57.500] Yes! [04:59.500 --> 05:01.980] So, do you think voice over IP works on that? [05:02.260 --> 05:03.320] How about peer to peer? [05:04.000 --> 05:04.480] Not. [05:06.440 --> 05:07.400] It's becoming... [05:07.400 --> 05:13.980] It's really stunting the growth of the IPv6, the Internet in general, without IPv6 at this point. [05:14.360 --> 05:19.280] One of the big problems we're seeing is the routing table, the actual backbone infrastructure. [05:20.540 --> 05:29.660] For each range of addresses, we have to map it to what's referred to as an AS number, so that providers can figure out how to route big blocks of information. [05:30.140 --> 05:32.620] Unfortunately, those blocks are no longer large. [05:32.620 --> 05:34.180] They keep on getting smaller. [05:35.060 --> 05:40.660] And because of that, all that has to be stored in the routing infrastructure. [05:41.180 --> 05:43.580] And these tables are gigantic right now. [05:44.900 --> 05:55.080] Within the next two, three years, there has been projections we may see Internet blackouts because the routers aren't large enough in some cases to support this particular type of routing, with V4. [05:57.400 --> 05:59.860] So, just be aware of it from a continuity standpoint. [06:00.200 --> 06:02.340] Now, we like our Internet to be able to get to wherever. [06:04.020 --> 06:06.420] Finding out that the routers can't handle it is kind of a drag. [06:07.820 --> 06:10.000] Okay, let's talk about NAT is evil. [06:11.140 --> 06:21.340] Okay, originally designed RFC 1931, specifically to deal with the address depletion and scalability. [06:22.760 --> 06:27.300] And also, until the new Internet protocol came out, this was kind of a stop gap. [06:27.620 --> 06:29.200] Okay, it's been around for a long time. [06:29.560 --> 06:32.660] Unfortunately, a lot of vendors were out there going, NAT! [06:32.840 --> 06:33.040] NAT! [06:33.200 --> 06:34.560] It's for security and privacy! [06:34.860 --> 06:35.120] Yes! [06:35.560 --> 06:36.380] Well, it's not. [06:36.580 --> 06:37.500] We're going to talk about why. [06:38.100 --> 06:39.820] It destroys end-to-end connectivity. [06:40.380 --> 06:45.620] In the early days, those of us that have been around before NAT, it was nice to... [06:45.620 --> 06:46.000] Yes! [06:46.180 --> 06:47.220] He laughs in the front. [06:47.460 --> 06:47.580] Yes! [06:49.960 --> 06:55.220] Those of us that remember that, we knew that there weren't a lot of gateways in between us and them. [06:55.340 --> 06:58.700] We knew that the data wasn't being modified, you know, in transit. [06:58.700 --> 07:01.760] So, it was kind of nice. [07:02.540 --> 07:08.180] Therefore, if we wanted to do encryption, we not only had the IP address, we also had the encryption method to do validation. [07:08.380 --> 07:09.800] We really can't do that today with NAT. [07:12.100 --> 07:19.180] Because of NAT, it required a redo of pieces of IPsec, layer 3 VPNs. [07:20.040 --> 07:22.500] Also breaks hundreds of applications. [07:22.700 --> 07:24.040] FTP had to be rewritten. [07:25.000 --> 07:27.480] Anybody trying to do voice over IP across the NAT? [07:27.480 --> 07:28.980] If you pulled out your hair... [07:28.980 --> 07:29.060] Oh! [07:29.280 --> 07:29.760] Same guy. [07:29.940 --> 07:30.340] Yes, okay. [07:30.480 --> 07:31.240] Your hair is still there. [07:31.420 --> 07:33.280] So, you haven't gone to the deep part of it yet. [07:33.480 --> 07:34.060] Well, maybe you have. [07:35.620 --> 07:37.140] It also breaks a lot of encryption. [07:37.600 --> 07:43.540] So, because of that, we've been forced to rely on layer 7 encryption instead of layer 3 encryption. [07:44.280 --> 07:46.220] Therefore, things have become more complex. [07:46.720 --> 07:53.240] Programmers have pushed a lot of things up the stack to try to deal with authentication and, you know, trustworthiness of connectivity. [07:53.560 --> 07:54.460] And it's hard. [07:54.600 --> 08:03.160] I mean, the web talks, as far as at most conferences, it's usually how to hack the web, not, you know, what are the cool things we can do at layer 3. [08:05.560 --> 08:13.400] So, and also because of this, NAT has added lots of time, lots of effort, lots of additional changes in software. [08:14.160 --> 08:15.640] So, don't go Rambo on me. [08:16.020 --> 08:18.400] Okay, I don't use Postal anymore because I heard that was offensive. [08:20.160 --> 08:21.440] But NAT's really not needed. [08:21.600 --> 08:23.040] We're going to talk about why NAT's evil. [08:23.040 --> 08:32.340] Okay, for a protocol that is supposed to provide security and privacy, do you think maybe you should be able to bypass it? [08:32.420 --> 08:33.460] No, you probably shouldn't. [08:33.620 --> 08:37.340] Well, here's a few protocols that bypass our NAT firewalls. [08:38.080 --> 08:40.460] It turns our firewalls into Swiss cheese. [08:40.820 --> 08:41.380] Wonderful. [08:41.760 --> 08:42.020] Okay. [08:42.020 --> 08:54.560] And then because the routing company said, it's too hard to manage NAT, let's create a new protocol that allows devices to modify the firewalls and routers. [08:54.800 --> 08:55.280] Yes. [08:56.040 --> 09:01.060] So, we created a few additional techniques to do that. [09:01.380 --> 09:01.640] Okay. [09:01.980 --> 09:05.320] And then there's techniques that go, NAT, we're going to ignore it. [09:05.400 --> 09:12.120] No, by the way, while we're doing it, it makes the firewall, it makes it very, very hard to use a firewall to do what it's supposed to do. [09:13.180 --> 09:17.800] Things like Teredo will pretty much get through most... [09:18.440 --> 09:23.840] It's an IPv6 over UDP over IPv4 tunneling technology. [09:24.080 --> 09:25.380] We have SSL tunnels. [09:25.600 --> 09:32.660] We have all these other tunnels that have really, if you're in the defense or the offensive side and security, offensive, love it. [09:32.860 --> 09:33.440] It's great. [09:33.440 --> 09:34.900] Those of us that are pen-testers. [09:35.060 --> 09:36.960] From the defensive standpoint, it's a bear. [09:37.260 --> 09:38.900] That's why all offensive people always win. [09:41.060 --> 09:44.540] It's really also forced us from a privacy standpoint. [09:44.860 --> 09:45.100] Come on. [09:45.260 --> 09:48.160] Web cookies give up the address internally, right? [09:48.540 --> 09:55.680] And there are techniques using Flash and PDFs and Microsoft Word that give up the internal IPv4 addresses. [09:55.680 --> 10:01.220] So from a privacy and anything else, NAT's pretty much failed. [10:01.540 --> 10:08.380] So pretty much give up the issue that NAT is really a security or privacy issue. [10:09.460 --> 10:11.880] IPv6 has something better and we'll talk about it in a minute. [10:12.940 --> 10:16.860] So what happened was that the engineer's ITF... [10:16.860 --> 10:21.020] I participated a little bit in this whole process. [10:21.020 --> 10:41.520] And what we did was really thought, how do we implement a technology, the layer 3 technology, that we can take all the lessons learned from before, bring them forward, and fix a lot of problems from an administration standpoint, so we don't have to do NAT to NAT and a lot of the other crazy stuff. [10:42.160 --> 10:50.280] So what happened was that IPv6 was formed, as you can see from the addresses, that's an IPv4 address, and that's an IPv6 address. [10:50.280 --> 10:51.800] A lot larger, yes. [10:53.660 --> 10:55.100] It's now a global standard. [10:55.280 --> 11:03.900] They add things like auto-discovery and auto-configuration, so I can plug a device in a network and actually talk to the stuff on the network right away, which is nice. [11:04.760 --> 11:07.640] The peer-to-peer model is really easy. [11:07.820 --> 11:09.440] Neighbor-discovery to find things. [11:09.600 --> 11:22.020] And self-forming networks, I was able to lay in 50 machines and a wireless network that once the WPA key was set, all the devices talked to each other in less than an hour. [11:22.760 --> 11:24.680] So it was pretty cool. [11:25.500 --> 11:28.500] We also had things like build-in IPsec. [11:28.740 --> 11:31.680] Mobility for IP has pretty much... [11:31.680 --> 11:33.920] IPv4 has kind of failed because it's very difficult. [11:34.100 --> 11:35.340] The address space is too small. [11:35.620 --> 11:47.600] Now it's so large that somebody could take and continue a voice-over IP connection, as an example, and go from place to place, and still maintain that connection, which is very cool. [11:47.940 --> 11:52.200] We've added multicasting, which we tried to do in v4, but the carriers kind of shut us down. [11:52.640 --> 11:53.760] We're starting to see that. [11:53.860 --> 11:54.920] And also extension headers. [11:55.040 --> 11:58.400] Extension headers allow us to add new features that we haven't thought of. [12:00.200 --> 12:03.460] IPv6 is more like a linked list, those of us that have done programming. [12:05.080 --> 12:06.800] And we're going to talk about how that works. [12:07.060 --> 12:12.400] So really, IPv6 provides really edge-to-edge connectivity for whatever's out there. [12:12.400 --> 12:15.760] Now, here's a question for you, those of you that use NAT. [12:16.120 --> 12:18.980] Do you know what all the devices are that are on your network? [12:20.020 --> 12:20.500] Really? [12:23.080 --> 12:23.980] Probably not. [12:24.260 --> 12:26.380] Last, I know that the U.S. [12:26.480 --> 12:35.860] government did a paper came out that stated that about 90% of the devices were non-seeable because they were behind NATs. [12:35.860 --> 12:48.500] And some of the pen-tests I've done in the past, I've discovered that, you know, internal employees have said, hey, let's throw NAT up because we need some more IP addresses or we're doing this skunks work project over here. [12:48.720 --> 12:54.000] So therefore, if that system was compromised or the systems behind you were compromised, it's hard to do incident handling. [12:54.160 --> 12:54.980] It's hard to do anything else. [12:55.120 --> 12:57.020] Again, from the pen-tester standpoint, win. [12:59.640 --> 13:02.400] Okay, so let's talk about what the current solution is. [13:02.400 --> 13:05.220] This is a big takeaway from this presentation. [13:06.860 --> 13:09.260] NAT versus the IPv6 solution. [13:09.480 --> 13:12.440] So we basically deal with security and privacy. [13:13.500 --> 13:16.140] We deal with security, address discovery. [13:17.220 --> 13:24.160] Okay, everybody knows what the RFC 1918 addresses are, 10.192, things like that. [13:24.440 --> 13:26.040] The address space is pretty small. [13:26.240 --> 13:30.240] We can brute force that in a few hours, most of us using Nmap or whatever. [13:31.380 --> 13:42.160] And IPv6, because the address range are actually broken up, where one part of the address is the network, the second part of the address is the local segment, the local network. [13:42.600 --> 13:55.880] So what we have is from a protocol called Unique Local Addressing, ULA, that allows us to break it up and say, hmm, I can have two of the 16th networks and I can have two of the 64th addresses per network. [13:56.200 --> 13:59.980] So trying to brute force this is very difficult, and I've got a slide for that in a minute. [14:01.160 --> 14:10.580] Okay, and also from a privacy standpoint, again, RFCs are relatively easy to discover on connection. [14:10.880 --> 14:14.300] You know, I'm on one network and there's another person that's on the same subnet. [14:15.800 --> 14:17.240] IPv6 is real hard to discover. [14:17.380 --> 14:19.420] It's 2 to 64th potential addresses. [14:19.860 --> 14:22.440] Makes it kind of difficult to find stuff out there. [14:23.400 --> 14:29.560] Several papers are out that this should make worms very difficult to discover devices. [14:30.800 --> 14:50.060] Also, from the inbound connection, if you don't have that device connected to DNS, as an example, I assume some of you've, you know, legally done the NMAP scan across the IP range on the outside of an organization to see what devices that they have loaded. [14:50.620 --> 14:52.560] The address space is relatively small. [14:53.000 --> 14:56.120] Again, on IPv6, it's extremely large. [14:56.720 --> 14:59.220] Very hard to discover things if it's not in DNS. [14:59.540 --> 15:01.600] Now for outbound, this is another good takeaway. [15:02.920 --> 15:10.680] If I'm making a connection from my browser, what I'm doing is I'm sharing exactly the same address out with me and everybody else. [15:10.820 --> 15:13.180] Unfortunately, that address is also bound to a port. [15:13.400 --> 15:16.340] So there's good ways of identifying that information. [15:17.260 --> 15:20.960] On IPv6, we have something called temporary addresses. [15:21.360 --> 15:28.640] What temporary addresses allow me to do is take my interface that's connected to the Internet and have it create random addresses for me. [15:28.920 --> 15:41.080] So every time I make a call out to the browser, I can say every five minutes, every hour, every seven hours, change my IP address, but keep on, you know, letting me do the web queries or whatever. [15:41.360 --> 15:44.820] So on a single network, you could basically... [15:45.400 --> 15:47.800] It makes it very hard for an attacker to find that address. [15:49.460 --> 15:50.340] That's pretty cool. [15:53.060 --> 15:59.280] So also, from a home user standpoint, most home users are getting one routable network. [15:59.900 --> 16:03.760] This is the amount of devices you'll be able to put on that routable network. [16:04.660 --> 16:07.020] I don't even have that amount of systems, okay? [16:07.360 --> 16:12.300] So I think this might be sufficient for, you know, small businesses and home users. [16:14.480 --> 16:16.060] This is what the address looks like. [16:18.140 --> 16:22.940] This is equivalent of an IPv6 address at the top to the IPv4. [16:23.080 --> 16:24.000] That's a slash 24. [16:24.380 --> 16:27.960] And from a scanning standpoint, about two seconds. [16:28.460 --> 16:29.840] You want a decent network. [16:29.840 --> 16:31.260] We take... [16:32.160 --> 16:33.540] Do a slash 16. [16:33.860 --> 16:34.340] Takes... [16:34.340 --> 16:35.580] Over 60 seconds. [16:35.840 --> 16:36.620] A slash 8. [16:36.980 --> 16:38.560] We do about 26. [16:38.700 --> 16:43.440] And there are tools out there that claim they can do the whole Internet in about 71 minutes. [16:45.120 --> 16:45.640] So... [16:46.240 --> 16:49.220] What do you think the equivalent of IPv6 is? [16:50.000 --> 16:51.380] Well, again, let's repeat. [16:51.820 --> 16:53.920] Network is assigned on the left-hand side. [16:54.140 --> 16:55.600] Subnet's on the right-hand side. [16:56.080 --> 16:59.480] So if I'm just doing a subnet, 146 years. [16:59.760 --> 17:04.400] Okay, if anybody gets a pen-test project to scan that network, I'm in on it, man. [17:04.580 --> 17:05.380] I'll be there. [17:05.800 --> 17:06.140] Okay? [17:07.060 --> 17:12.600] But really, if you get the bigger one, which is even more fun that you want to scan the whole Internet and brute force it... [17:13.740 --> 17:14.140] Yes! [17:14.800 --> 17:15.200] Okay? [17:15.360 --> 17:18.900] So if anybody can, you know, find a gig like this, give me a call. [17:19.020 --> 17:19.600] This would be fun. [17:20.440 --> 17:22.920] I think we're taking care of many years from now. [17:24.540 --> 17:25.980] So, where is this thing? [17:26.080 --> 17:31.600] A lot of us, people I've talked to here and regularly talk to, they state, you know, where is this IPv6 Internet? [17:31.840 --> 17:34.840] Well, 2005 is when we started really seeing growth. [17:35.140 --> 17:40.160] It's 2006, 2007, 2008, 2009. [17:40.480 --> 17:41.540] Sorry, I don't have 2010. [17:42.540 --> 17:48.660] Right now, we're claiming about 6% of the AS, which is carriers and providers out there. [17:48.660 --> 17:53.820] About 0.25% of web traffic is IPv6. [17:54.380 --> 17:58.520] 2% of the clients have IPv6 connectivity to the Internet. [17:58.880 --> 18:09.540] And devices that have Internet access, they're capable of doing IPv6, are between 4 and 600 million devices. [18:10.540 --> 18:11.760] Ooh, I put K down there. [18:12.140 --> 18:13.120] You didn't catch that. [18:14.320 --> 18:15.040] Okay? [18:15.480 --> 18:16.780] Talked about this last time. [18:16.780 --> 18:20.180] The only thing I added from last time, if you look at the right-hand side, is tunnels. [18:20.800 --> 18:22.520] The whole capability of doing tunnels. [18:24.280 --> 18:29.780] IETF came up with this concept that we have islands of IPv6 through seas of IPv4. [18:30.520 --> 18:33.400] So we have to create tunnels so the two islands can talk. [18:34.780 --> 18:42.940] Well, until we get to the point where we have seas of IPv6 and we have tunnels of IPv4, islands of IPv4, that have to communicate. [18:43.120 --> 18:44.960] We're actually going through that transition right now. [18:44.960 --> 18:49.380] These are all the operating systems that support it and support the tunneling themselves. [18:49.680 --> 18:52.900] Notice all the IPv6 support and defaults. [18:53.240 --> 19:00.580] Since last time, the real things I've put on here is VMware and Citrix now supports it in cloud computing. [19:00.720 --> 19:01.740] You have to enable the service. [19:02.420 --> 19:09.200] Microsoft 7 by default and 2008 Service Pack 2, you cannot turn IPv6 off. [19:09.460 --> 19:09.760] Woo-hoo! [19:09.760 --> 19:12.000] So I want to see you secure that. [19:12.360 --> 19:12.460] Yeah. [19:13.740 --> 19:19.120] Embedded systems, there's actually IPTV is starting to roll out which supports IPv6. [19:20.240 --> 19:29.680] And also the iPhone, if you're via wire, Wi-Fi, and the G phone, the Android, 2.2 supports by default. [19:29.920 --> 19:34.700] So when you're browsing the web, there's a good chance you could be browsing v6 but not know it. [19:35.760 --> 19:38.200] Have you secured your v6 system today? [19:39.000 --> 19:39.080] Hmm. [19:40.320 --> 19:41.920] So let's talk about the precedence. [19:42.020 --> 19:43.340] This is another big takeaway. [19:44.440 --> 19:49.780] In the IPv4 world, when we turned on the power, we went, yay, I got an IPv4 address, right? [19:49.940 --> 19:53.280] Well, we've had some complexity to the boot up sequence. [19:53.660 --> 19:59.580] Right now, when I boot a system up, first it checks and says, can I talk to an IPv6 network? [20:00.120 --> 20:04.960] If it fails, it then says, ooh, what tunnels do I have? [20:05.200 --> 20:15.600] And then we'll go down the tunnel list and try to connect to all the tunnels, including things like Terdo, which is IPv6 over UDP over IPv4. [20:15.860 --> 20:25.300] And we also have a new one that Microsoft had as a special benefit to those of us in the security field, which is IPv6 over HTTPS over IPv4. [20:25.760 --> 20:28.500] Woohoo, okay, I want to see you guys secure that one. [20:28.560 --> 20:29.060] That'll be fun. [20:30.380 --> 20:35.560] And then we have a lot of other tunnel providers, like GoGoNet, HENet, 6SX. [20:36.000 --> 20:49.640] If you want to get Internet at home or just experiment with it, you can go to these three providers and they give you real good examples of how to configure your routers and your computers to support IPv6. [20:49.680 --> 20:54.120] And all of them give anonymous accounts, not just named accounts, so that's kind of cool. [20:55.040 --> 20:59.020] So then the last thing that happens is you end up with IPv4 turned on. [21:00.100 --> 21:03.200] So does anybody see potential badness involved in there? [21:03.980 --> 21:04.520] Yeah. [21:06.360 --> 21:11.220] Let's talk about what's actually happening. [21:11.340 --> 21:15.720] When I enable an interface, the device actually gets an address called colon colon one. [21:16.140 --> 21:19.060] I saw somebody running around here, 127.0.0.1. [21:19.060 --> 21:19.920] Okay. [21:20.100 --> 21:21.280] That's the small network. [21:21.420 --> 21:23.340] You now have to replace that with colon colon one. [21:24.080 --> 21:25.120] That's a bigger network. [21:26.340 --> 21:37.540] For the device itself, if you remember correctly, a lot of commands we have to do ping minus, you know, I for interface or whatever to say which interface we want to ping or whatever to go out on. [21:38.020 --> 21:39.180] IPv6 made it easier. [21:39.180 --> 21:40.360] They now have a... [21:40.360 --> 21:49.740] After the address, you put a percentage sign, IDX, and the IDX is replaced with the interface name, like ETH0, as an example. [21:50.000 --> 21:54.800] So it allows you to kind of steer where your packets are going, which is a lot simpler. [21:56.120 --> 21:59.880] The next thing that happens, you end up with a IPv6 address. [22:00.080 --> 22:05.940] This special address, FE80, when you turn on machines, that's a locally routable address. [22:06.220 --> 22:12.480] It's only routable on your local subnet, which all devices talk by default with V6. [22:13.220 --> 22:25.890] By default, it will take your MAC address, create a... take the UI 64, shove FFEF in between that, and that then provides you the address. [22:26.800 --> 22:37.140] You also end up using, from a layer 2 standpoint, you end up with a broadcast address of 3333FF, and then the last part of your MAC address. [22:37.620 --> 22:39.000] So that's kind of cool. [22:39.880 --> 22:42.760] This works on most of the UNIXes, Linux, whatever. [22:43.840 --> 22:45.300] Microsoft has changed it up. [22:45.460 --> 22:52.140] They actually randomized the address on the last 64 bits, which is kind of interesting. [22:52.480 --> 22:58.880] The other thing that happens is not only do you get a unicast address, you also get a multicast address. [22:58.880 --> 23:04.900] So those of you that have to secure firewalls, you've got to start thinking of multicast addresses too. [23:05.820 --> 23:18.020] We end up with what is referred to as a solicit multicast, which it generates the FFO2 column column 1, FF, and your MAC address, the last digits of your MAC address. [23:18.320 --> 23:26.980] So those of you that have done pings to FFO2 column column 1, this is actually what it's talking to, is all those devices. [23:26.980 --> 23:29.300] Then it actually binds to the interface. [23:30.400 --> 23:31.540] So that's the boot up. [23:31.860 --> 23:38.940] If you want to see this taking place, here's the commands under Linux, here's the command under Windows, and I'm going to have to go quickly on this. [23:39.900 --> 23:46.340] Remember, every device gets on IPv6, typically gets a link local address. [23:46.620 --> 23:55.220] If you're using ULA, unique local address in your organization, you get a ULA address, and then you can get one or more global addresses for inbound and outbound. [23:55.660 --> 24:02.860] So by default, a Linux box can have four unicast and multicast addresses, not one. [24:03.860 --> 24:05.400] That's a bigger attack space, isn't it? [24:06.240 --> 24:06.840] Yes! [24:07.360 --> 24:08.160] Shake your heads, yes. [24:13.200 --> 24:23.460] Okay, the second thing it does is, has anybody ever put more than one device on your network, and all of a sudden the second device goes, you know, address conflict, or the first device has address conflict? [24:23.660 --> 24:24.220] That's kind of a drag. [24:24.620 --> 24:31.340] IPv6 actually fixed that with what's referred to as the DAD protocol, detection address, or duplicate address detection. [24:31.660 --> 24:34.400] It actually goes through and says, hey, I'm this address. [24:34.620 --> 24:35.440] Does anybody have it? [24:35.440 --> 24:39.620] And if anybody replies, it goes, it changes the address and does it again. [24:40.500 --> 24:41.700] Tries another address. [24:41.980 --> 24:47.600] If it doesn't, nobody replies, it then goes, yay, and starts communicating on that particular address. [24:49.880 --> 24:51.440] Let me show you... [24:58.890 --> 25:03.890] That's an ICMP packet that's sent out for that function. [25:04.290 --> 25:10.990] Those of you in the front that came up and weren't afraid, you know, for me to see you, probably can see this. [25:11.070 --> 25:12.770] Those in the back, you'll have to watch the video, I guess. [25:13.950 --> 25:17.070] So as you can see here, you have the IPv6 address. [25:17.290 --> 25:19.850] Something really cool is the traffic and flow label. [25:21.150 --> 25:29.530] This allows both the local host to assign, hey, this is important traffic, and then the network to assign, this is important traffic. [25:29.650 --> 25:34.150] These are both QoS tables, or QoS indicators. [25:34.490 --> 25:36.030] We also have the next header. [25:36.330 --> 25:38.150] This is where the link list comes in. [25:38.150 --> 25:42.210] Each of the additional headers after this will have a next header item. [25:42.770 --> 25:47.430] I've seen packets that have next header, next header, up to 15. [25:48.650 --> 25:51.890] Mmm, can your IDS go 15 levels deep? [25:52.470 --> 25:53.270] Mmm, it's hard to think about. [25:55.910 --> 25:56.550] Okay. [25:57.130 --> 26:03.410] And then we see that, again, in this ICMP packet, the ICMP addresses have changed also. [26:03.410 --> 26:05.410] The types have changed. [26:06.250 --> 26:07.830] There's a lot more of them, a lot more features. [26:12.000 --> 26:15.160] And if you want more details on this, we'll talk about it later. [26:15.440 --> 26:17.140] But I'm kind of running out of time already. [26:17.980 --> 26:19.500] To actually see... [26:20.600 --> 26:22.520] IPv6 has removed the ability... [26:23.440 --> 26:25.160] ARP is pretty much gone. [26:25.520 --> 26:26.800] This is the new ARP. [26:26.800 --> 26:28.460] It's now at layer 3, not layer 2. [26:29.740 --> 26:32.520] These are the commands to actually see what's in your ARP. [26:32.660 --> 26:34.540] Or what would be your ARP cache. [26:34.720 --> 26:37.200] This is actually referred to as a neighbor discovery cache now. [26:38.700 --> 26:40.240] And I'm going fast on this. [26:40.800 --> 26:41.200] So... [26:44.980 --> 26:46.400] Currently, you have... [26:46.400 --> 26:51.120] Just like you have in v4, you have multiple ways that you can boot a system and assign an address. [26:51.120 --> 26:53.140] Some people create static addresses. [26:53.620 --> 26:57.320] Some people use DHCP for it. [26:57.400 --> 26:59.180] IPv6 adds a few more features. [26:59.440 --> 27:00.940] You can end up with a static address. [27:01.280 --> 27:04.580] You can end up with a stateless audio configuration address. [27:04.740 --> 27:08.620] That stateless auto configuration address is usually two lines in a router. [27:08.920 --> 27:13.380] That can assign an IPv6 range to every device on that network. [27:13.620 --> 27:14.660] Very, very easy. [27:14.980 --> 27:16.480] Very quick to configure. [27:16.480 --> 27:21.840] And even with that, you can provide some real granularity. [27:22.020 --> 27:24.600] You can say, hey, I'll provide you... [27:24.600 --> 27:26.520] The router can say, hey, I'll provide you the DNS. [27:26.960 --> 27:31.440] Or, hey, go refer to the DNS server over here. [27:31.600 --> 27:35.160] Or go refer to the DHCP server and do something over here. [27:35.700 --> 27:38.000] And then the device, if it can't... [27:38.000 --> 27:43.600] If the router doesn't give up the information, it goes and looks at the DHCP v6 stuff. [27:44.280 --> 27:50.180] What this really means is you can end up with backup, network routing functions. [27:50.440 --> 28:01.120] So, if your DHCP server goes down or you're in a disaster and you're trying to bring up the network quickly, you can lay in a big cloud of devices in just minutes, which is pretty cool. [28:02.740 --> 28:03.260] Okay. [28:03.600 --> 28:05.240] So, some of the things I should know. [28:06.280 --> 28:09.820] What type of IPv6 does your ISP provide? [28:09.820 --> 28:09.900] All right. [28:11.120 --> 28:14.660] I sat down and this is a question I get all the time. [28:14.860 --> 28:19.120] Which is, okay, my provider says, we're going to provide you IPv6. [28:19.620 --> 28:22.640] And I always ask, so what do you mean by that? [28:22.780 --> 28:24.540] What really is being supported? [28:24.740 --> 28:30.960] Well, from a true IPv6 perspective, everything in green is what you should be getting. [28:32.040 --> 28:35.620] Unfortunately, a lot of carriers are giving you the things in white. [28:37.400 --> 28:39.060] So, that's kind of a drag. [28:39.880 --> 28:42.300] Things like the ISP will give you a router. [28:42.660 --> 28:44.840] And that router will actually be tunneled. [28:45.060 --> 28:47.460] So, you're not really getting an IPv6 connection. [28:48.360 --> 28:53.680] It's basically IPv6 in your network tunneled over their router over IPv4. [28:54.520 --> 29:02.640] So, therefore, accessing web servers and things like that, because you're tunneling, it always slows down connections, it causes other problems. [29:03.280 --> 29:04.360] Real problem. [29:04.620 --> 29:07.040] Also, methods of connecting. [29:07.420 --> 29:08.840] Again, carriers change that. [29:09.540 --> 29:10.180] DNS. [29:10.700 --> 29:14.400] Some carriers only support IPv4 quad A records. [29:14.780 --> 29:21.540] So, you can only talk... you may get an IPv6 network, but you can only talk on IPv4. [29:21.720 --> 29:23.260] So, that's kind of a bit of a drag. [29:23.260 --> 29:36.320] The stuff in green, you should be able to get single... you should be able to get IPv4 addresses across the IPv4 infrastructure and IPv6 addresses across an IPv6 infrastructure at minimum. [29:38.040 --> 29:39.000] Routing protocols. [29:39.340 --> 29:41.700] Some of the providers don't provide routing protocols. [29:41.900 --> 29:44.380] Some of them block mobility, which is kind of a drag. [29:44.380 --> 30:11.360] And some of them don't support IPv6 IPsec VPNs, or the new multicast security, where we can actually send out one packet, say, from an iPhone, and Twitter everybody and say, hey, go take a look at my video stream that I've got right now, and then millions of people can go to a rendezvous point and actually pull that data from a single outbound data stream from an iPhone. [30:11.780 --> 30:13.180] It's kind of cool technology. [30:14.720 --> 30:16.500] And we talked about the size. [30:16.680 --> 30:27.820] There's a survey that .2% of the Internet, the 1 million websites, that are the top 1 million websites, support IPv6, for those of you in the business. [30:28.340 --> 30:34.360] There's a lot of really good work out there for you guys to upgrade to IPv6, especially in the next 36 months. [30:35.360 --> 30:39.580] Because that's the sweet spot where people are going to try to implement IPv6. [30:40.560 --> 30:44.300] especially on their web servers, mail servers, blah, blah, blah. [30:45.660 --> 30:49.480] Okay, software companies, we're getting exactly the same thing from the software companies. [30:49.700 --> 30:55.880] They're saying things like, yeah, because our operating system supports it, we don't have to support IPv6. [30:55.880 --> 30:57.920] It's magically supported. [30:58.520 --> 31:01.780] Unfortunately, a lot of the program libraries are still being updated. [31:02.020 --> 31:09.080] Things like certain things in Java, certain things in Python, Ruby, things like that haven't been upgraded. [31:09.420 --> 31:14.060] A lot of people use current applications or using these old libraries, not the newer libraries. [31:14.060 --> 31:16.480] Therefore, they can't truly support IPv6. [31:16.720 --> 31:20.220] So what you end up with is, you end up with applications. [31:21.040 --> 31:22.920] This is hint of vulnerabilities. [31:23.680 --> 31:34.880] You have applications that are receiving 128-bit addresses and they're only configured to support 32-bit addresses. [31:35.400 --> 31:37.080] There wouldn't be any problems there. [31:37.180 --> 31:39.080] You guys ever heard buffer overflows, right? [31:39.080 --> 31:39.680] Yeah. [31:42.380 --> 31:43.700] We also have validation. [31:43.980 --> 31:46.880] A lot of companies are saying, we totally support IPv6. [31:46.880 --> 31:49.720] And what you'll find out is they're self-validated. [31:49.860 --> 31:50.980] They're claiming it themselves. [31:51.340 --> 31:56.460] I want to mention that there's some second-party and third-party validation. [31:56.460 --> 32:00.020] We have IPv6 ready, which is supported by the IPv6 forum. [32:00.240 --> 32:05.440] They do a great job to tell you that systems are standard and interoperable. [32:05.440 --> 32:12.800] You also have NIST that has a new standards and testing facility. [32:13.140 --> 32:16.660] And also, the DOD has something called the APL and JITIC. [32:16.820 --> 32:20.340] That's Joint Interoperability Testing Center. [32:20.940 --> 32:26.360] They've done some real serious testing, not just of standards and interoperability, as you see at the bottom. [32:26.680 --> 32:28.700] They've also done performance and security. [32:28.860 --> 32:34.440] It's nice that you get a device that supports IPv6, but if it only moves one byte a minute, it's kind of a drag. [32:34.440 --> 32:40.500] So be aware that even the software vendors have a lot of catching up to do. [32:41.260 --> 32:43.460] So buyer beware, especially if it's... [32:45.340 --> 32:52.720] Unless it's been third-party tested or second-party tested, buyer beware for products that are claiming to do IPv6. [32:54.480 --> 32:55.880] Some good checkpoints. [32:56.580 --> 32:59.700] A lot of people say, hey, am I running IPv6 on this device? [33:00.040 --> 33:01.760] Here's two good checkpoints for that. [33:01.760 --> 33:04.160] Does my network support IPv6? [33:04.340 --> 33:05.540] You set up a network at home. [33:06.380 --> 33:07.480] What things are missing? [33:07.680 --> 33:09.300] These will actually give you checks on that. [33:10.740 --> 33:12.740] Site support for IPv6. [33:13.360 --> 33:17.640] Say that you're going to a client or your own company. [33:17.740 --> 33:19.500] You want to see what services are missing. [33:19.780 --> 33:21.180] This will give you a list of those. [33:21.820 --> 33:23.460] Test your domain, which is really good. [33:24.060 --> 33:26.600] Test to make sure your DNS servers are configured correctly. [33:26.600 --> 33:27.660] And also speed test. [33:27.800 --> 33:30.920] This is one of two speed test companies that do IPv6. [33:31.200 --> 33:32.520] Most of them are only IPv4. [33:32.740 --> 33:36.280] So it kind of doesn't give real information out there for both protocols. [33:36.980 --> 33:38.600] Now for people certification. [33:38.940 --> 33:43.940] Hurricane Electric at this URL provides a free IPv6 certification. [33:44.840 --> 33:49.540] They have a training component and then a lab component. [33:49.540 --> 33:51.220] And then you get a test. [33:51.880 --> 33:52.940] It's all free. [33:53.200 --> 33:54.340] You go onto their website. [33:54.800 --> 34:01.340] It will basically teach you the basics of administering an IPv6 network very quickly. [34:01.920 --> 34:03.980] Most people can finish it in a day. [34:04.360 --> 34:06.540] So it's pretty decent. [34:06.760 --> 34:09.180] We also have technology testing. [34:09.340 --> 34:10.680] We have the self-testing link. [34:10.900 --> 34:12.620] We have the IPv6 ready link. [34:12.680 --> 34:14.380] And the DoD JITIC link. [34:14.880 --> 34:18.380] Again, do the products actually support IPv6? [34:21.890 --> 34:23.710] Well, I am talking like Maco. [34:24.630 --> 34:25.550] I'm almost done. [34:26.430 --> 34:26.890] Early. [34:27.270 --> 34:27.370] Ooh. [34:28.570 --> 34:30.210] So let's talk about the security side. [34:30.430 --> 34:37.210] In the IPv6 world, or in the IPv4 world, we just went, eh, we're going to throw stuff out there and we're going to trust everybody, right? [34:37.570 --> 34:40.030] And then we went, crap, we can't trust everybody. [34:40.190 --> 34:41.810] People are attacking our networks and such. [34:42.230 --> 34:51.110] The IETF has created RFC 3756 to kind of provide some granularity on what should be trusted and what shouldn't be trusted. [34:52.330 --> 35:02.870] First level is what they call the home and corporate Internet, or intranet, which is we trust all nodes on our network that won't attack other nodes. [35:03.150 --> 35:06.190] And we also trust our routers. [35:06.670 --> 35:11.030] Maybe not today with malware, but this is the standard. [35:11.030 --> 35:12.970] So they have some definitions for that. [35:13.410 --> 35:20.290] We also have the wired and wireless networks, which is we trust the router, but we don't trust the nodes in the environment. [35:20.450 --> 35:23.730] And they have some granularity on what those controls need to be. [35:24.130 --> 35:27.810] And then we have the HOPE network, or the DEFCON network. [35:28.330 --> 35:29.670] Are you guys on this network? [35:29.790 --> 35:31.390] Do you really trust this network? [35:31.570 --> 35:32.230] I don't! [35:35.450 --> 35:38.430] This is basically where nobody trusts anybody. [35:38.430 --> 35:43.330] We just, you know, know that there's an IP layer that gets us a global address, and that's good enough. [35:44.730 --> 35:51.610] So this trust level, if you think about it in your own environment, most corporations like the first one. [35:52.190 --> 35:58.130] Unfortunately, you're starting to be forced to move to the second one because there's, you know, being attacked and such like this. [35:58.130 --> 36:06.970] We in the hacker community have been dealing with the third one for many years, and have had a lot of lessons learned at different conferences and thinking through this process. [36:07.250 --> 36:12.310] So there's a lot of lessons learned that the corporations can actually get from conferences like this. [36:14.070 --> 36:14.370] Okay. [36:15.210 --> 36:20.030] IPv6 vulnerabilities don't just exist at the network layer. [36:21.490 --> 36:31.270] There is an example, if I say at layer 2, hey, I'm a IPv4 packet. [36:32.550 --> 36:38.790] And then at layer 3, I go, just kidding, and I actually send data out that's an IPv6 packet. [36:39.970 --> 36:41.390] What do your routers do? [36:41.930 --> 36:43.110] Do they flip over? [36:43.250 --> 36:44.490] It's pretty entertaining, by the way. [36:44.710 --> 36:45.890] What do your hosts do? [36:46.970 --> 36:52.370] These are known problems that the providers have been fixing. [36:52.550 --> 36:55.750] Unfortunately, some of the older operating systems still have problems here. [36:56.370 --> 37:03.950] We also have layer 3 and layer 4 spoofing and other problems based on how vendors have implemented IPv6. [37:04.730 --> 37:11.210] Realize today there are over 500 RFCs that define IPv6. [37:12.010 --> 37:17.230] A lot of organizations don't go deep enough to implement a lot of the features that provide security. [37:17.370 --> 37:19.710] They provide the interoperability, but they don't provide the security. [37:20.110 --> 37:22.470] And because of that, they've left themselves open. [37:22.790 --> 37:26.630] And then IPv6 can't provide application layer security. [37:26.810 --> 37:31.330] And, you know, web attacks are web attacks, whether they're across IPv4 or IPv6. [37:31.950 --> 37:41.150] Unfortunately, with this capability of doing buffer overflows from addresses and other things, it can actually increase the exposure of a lot of networks. [37:43.210 --> 37:44.150] There we go. [37:45.570 --> 37:46.910] Okay, public attack tools. [37:47.090 --> 37:49.150] Public attack tools have been around for a while. [37:49.350 --> 37:54.570] Matter of fact, does anybody know when the first attack against a IPv6 network was? [37:54.570 --> 37:55.910] Any hands? [37:57.510 --> 37:58.010] Okay. [37:59.210 --> 37:59.810] 2001. [38:00.390 --> 38:02.050] It was a device that was connected. [38:02.330 --> 38:04.910] It had a tunneling protocol called 6 to 4. [38:05.190 --> 38:08.870] It was connected into a network that was an IPv4 network. [38:09.170 --> 38:11.050] 6 to 4 went out the firewall. [38:11.250 --> 38:19.310] The attacker actually implemented IPv6, turned on the tunnels, and had full access to those devices for a while. [38:19.310 --> 38:19.790] Interesting. [38:20.610 --> 38:31.570] Once this information got out, what we saw was other people started saying, hey, we've also been attacked by IPv6 tunnels, and here's an example of this. [38:31.810 --> 38:33.550] So it goes back to early 2001. [38:33.910 --> 38:39.250] By 2005, we were seeing malware and viruses using it for back channels. [38:39.690 --> 38:47.290] Several of the tools literally checked to see if you had IPv6, and then we'd go to an IPv6 IRC channel. [38:49.690 --> 38:57.810] So, wow, so tunneled over IPv6, does your IDS's support that, and do your firewalls block the tunnels? [38:58.090 --> 38:58.730] Well, no. [38:59.010 --> 39:05.090] I mean, some organizations have had exposures of, you know, five to six years of back channels. [39:05.530 --> 39:08.630] The whole APT, I hate to use that, advanced persistent threat. [39:10.350 --> 39:14.610] This has actually been seen as an advanced persistent threat by some organizations. [39:16.350 --> 39:27.170] As of just the last couple years, some of the malware testing I've done, we're also finding about a third of the malware is trying to talk IPv6, and if it can find a tunnel, it's going to talk that. [39:27.170 --> 39:34.570] So, if you have not put up your IPv6 defenses, this is a good time, you've been warned. [39:37.130 --> 39:41.050] And interestingly enough, all these tools, again, are open source. [39:41.310 --> 39:42.430] They've been out there for a while. [39:42.570 --> 39:43.770] We have everything from scanning. [39:45.010 --> 39:48.750] The real challenge with the scanning, by the way, is finding devices on a network. [39:50.150 --> 39:52.210] Those are very difficult. [39:52.610 --> 39:56.270] So, if you can find one address, then you can use these tools to scan one address. [39:56.550 --> 40:00.150] But we're really used to saying, give me a range of addresses and scanning it. [40:00.230 --> 40:03.010] As we talked about before, you really can't scan that big range. [40:04.010 --> 40:11.790] We have covert channels, bouncers, denial of service, packets, zombies, just all kind of fun things. [40:11.790 --> 40:13.830] And there's a lot more almost every day. [40:14.090 --> 40:21.870] I have an archive of IPv6 tools that I'm going through and looking at the code and finding all kind of fun things. [40:22.010 --> 40:31.870] By the way, some of the IPv6 code that's out there that can be used for pen-testing or security testing have back doors so your IDSs can pick them up. [40:32.250 --> 40:37.410] They have code actually written into them so you can tag it and say, oh, it's this code. [40:37.610 --> 40:39.810] It's this particular tool that's being used on my network. [40:41.170 --> 40:43.410] And usually it's something like dead beef. [40:44.730 --> 40:45.690] Makes me laugh. [40:47.130 --> 40:52.930] So the question I get all the time is, is IPv6 more secure or less secure? [40:53.210 --> 40:57.170] Well, it's a bigger tool kit for both defense and offense. [40:57.650 --> 41:06.370] And those in the defensive world that have to defend networks, they're not aware of it because typically we're always playing catch up on the defense side. [41:07.770 --> 41:09.410] It's bigger vulnerabilities. [41:11.150 --> 41:14.350] Some of the defenses have now been added. [41:14.630 --> 41:16.870] The whole privacy address is very cool. [41:17.190 --> 41:24.710] It allows you to have your internal users generate addresses that are non-traceable and only outbound addresses, which is kind of nice. [41:25.730 --> 41:28.610] We also have the things like send in CGA. [41:29.550 --> 41:31.390] CGA is a cryptographic address. [41:31.650 --> 41:44.130] So if I have a piece of crypto material that, like a PGP key that uniquely identifies me, I can also validate that other people in my network have the same crypto material through some algorithms. [41:44.130 --> 41:46.390] So that's pretty cool. [41:46.670 --> 41:48.570] We can't do that with V4 at this point. [41:48.770 --> 41:54.910] We also have the neighbor discovery includes IPsec with this CGA capability. [41:54.910 --> 42:00.130] So now we can provide better link security, local network security. [42:00.350 --> 42:09.910] So devices that only authorized devices are on that system, on that particular network, can gain access to a global address or something that's routable. [42:09.910 --> 42:11.090] Does this sound like anything? [42:11.230 --> 42:12.670] Has anybody heard of a knack? [42:13.450 --> 42:13.670] Hmm. [42:13.910 --> 42:17.670] Could this be like a way that open source knack could be developed? [42:18.250 --> 42:18.590] Hmm. [42:19.070 --> 42:19.870] Something to look into. [42:21.250 --> 42:23.130] We have the unique local addresses. [42:23.630 --> 42:27.430] An organization can have an address space that's the whole size of the whole Internet. [42:28.010 --> 42:29.990] You can have a 32-bit address space. [42:30.210 --> 42:35.070] So the guy that, you know, hasn't lost his hair yet from pulling this stuff out. [42:35.810 --> 42:39.810] This allows two organizations to come together and to be broken up. [42:39.810 --> 42:41.610] And still have routability between those. [42:41.790 --> 42:43.950] It's just then some firewall and routing rules. [42:44.250 --> 42:44.690] And you're done. [42:45.170 --> 42:47.290] Very little configuration changes. [42:48.290 --> 42:50.030] We also have added... [42:50.790 --> 42:52.070] IPsec has been extended. [42:53.250 --> 42:56.030] To support the way it was supposed to work with. [42:56.170 --> 42:58.310] Today we deal with host to gateway. [42:58.910 --> 43:01.770] Which we have, you know, a lot of organizations do host to gateway. [43:02.010 --> 43:03.270] And then you can access the network. [43:03.630 --> 43:04.650] With gateway to gateway. [43:04.650 --> 43:06.610] Where you have a tunnel of two devices. [43:06.970 --> 43:11.810] And everybody here is protected by the IPsec tunnel between the two gateways. [43:12.310 --> 43:20.350] Well, with IPv6, because we don't have NAT anymore, we can do host to host IPsec connections. [43:20.930 --> 43:22.210] It's actually pretty cool. [43:22.490 --> 43:29.530] Microsoft has implemented some very cool things in that to allow you very quickly to set up host to host connections. [43:29.530 --> 43:38.850] So, as an example, I, as a user on this network, can terminate a connection to my corporate network on their connection. [43:38.990 --> 43:52.390] And because of the capability of the link list tunnels, the link list headers, I can then have an additional authentication into an additional connection on the other side. [43:52.390 --> 43:57.490] So I can have, you know, multiple levels, multiple access gateways essentially on the network. [43:57.650 --> 43:58.690] Which we really didn't have before. [43:58.830 --> 44:04.310] We had one access gateway and then we prayed that, you know, somebody couldn't figure out how to break out of that network access. [44:05.550 --> 44:06.830] Some of the new features. [44:07.930 --> 44:15.970] Once you take IPsec and add it into a bigger network, you end up with something called server enclave domain isolation. [44:16.330 --> 44:20.010] It's the ability to have what is referred to as black networks. [44:20.010 --> 44:28.630] In other words, say that I have a financial institution and I have two very critical devices that connect to two or three other devices. [44:28.930 --> 44:35.750] I can actually draw a circle and create an IPsec authentication boundary around those. [44:36.230 --> 44:37.710] Making it unscannable. [44:38.950 --> 44:42.030] And you only see IPsec ports. [44:42.410 --> 44:43.110] That's it. [44:43.230 --> 44:44.390] You can't see anything else. [44:45.490 --> 44:46.450] That's pretty cool. [44:46.450 --> 44:54.490] And then you can create layers of these particular IPsec tunnels to reduce your risk on attacks of specific systems. [44:54.710 --> 44:56.670] So authentication becomes very critical here. [44:56.850 --> 45:04.250] But SETI looks like it's going to provide the ability to do policy based network flows. [45:05.210 --> 45:06.530] Or access controls. [45:07.090 --> 45:10.110] We also have a new one that just came out called Calypso. [45:10.110 --> 45:14.710] Which is common architecture, label, IPv6 security options. [45:15.110 --> 45:17.230] It's one more of those crazy option headers. [45:17.650 --> 45:22.830] It can actually say, you know, this data is sensitive to my financial institution. [45:22.830 --> 45:25.210] It should never go out the gateway to the Internet. [45:26.350 --> 45:32.250] Or it should never go to the accounting office because it's a different type of financial transaction. [45:32.850 --> 45:35.230] Or it should never go to your engineering office. [45:35.230 --> 45:37.810] You can actually configure your routers to do this. [45:38.150 --> 45:38.730] Which is pretty cool. [45:39.410 --> 45:40.150] 10 minutes. [45:41.950 --> 45:43.250] New attack vectors. [45:43.890 --> 45:44.730] Automatic tunneling. [45:45.150 --> 45:46.570] 16 types of tunnels. [45:47.150 --> 45:48.470] Let's show you an example. [45:56.180 --> 45:56.700] Okay. [45:56.960 --> 45:58.800] Those of you that are close enough. [45:59.580 --> 46:00.100] Yes. [46:00.780 --> 46:03.260] See that somebody is trying to do a quad A look up. [46:03.580 --> 46:04.540] The DNS right here. [46:05.120 --> 46:07.220] So they're IPv6 enabled. [46:07.480 --> 46:09.840] And they're trying to go out and get an IPv6 address. [46:09.840 --> 46:11.780] They get an IPv6 address. [46:12.520 --> 46:13.540] Blah, blah, blah. [46:14.040 --> 46:14.900] Oh, look. [46:15.220 --> 46:20.320] They must have been protected by the firewall because I don't see any IPv6 connectivity, right? [46:20.860 --> 46:23.640] I don't see IPv6 addresses moving back and forth. [46:23.880 --> 46:25.100] Well, this is actually Terado. [46:25.780 --> 46:32.140] Let's take this UDP packet because we know that it's IPv6 over UDP over IPv4. [46:36.540 --> 46:38.000] And where is it? [46:39.300 --> 46:40.260] Decode as [46:47.540 --> 46:49.920] Terado. [46:55.040 --> 46:55.920] What do you think? [46:56.620 --> 46:57.420] Is that cool? [46:58.420 --> 47:01.460] Oh, by the way, this has been going on for the last six years. [47:05.700 --> 47:11.540] Because I actually wrote the recommendation that hit NIST or that hit U.S. cert on this. [47:12.720 --> 47:25.040] This particular tunneling type, if you've not upgraded your operating system, if somebody can figure out what your IPv6 address is, this also becomes a tunnel directly through you with no firewalling. [47:25.240 --> 47:34.440] Terado does not support host-based firewalling, only network-based firewalling if your network can support it for inbound or outbound. [47:34.440 --> 47:43.140] Microsoft has added a feature that it denies inbound initiated requests, but recognize this can be a real problem for an organization. [47:43.900 --> 47:44.600] So, anybody frightened? [47:44.720 --> 47:46.980] Anybody running back to a network and going, oh, crap! [47:49.500 --> 47:52.940] Let's take a look at the packet itself because I have a minute or two to do that. [47:53.280 --> 47:54.980] We have our IPv4. [47:54.980 --> 47:55.040] server. [47:56.460 --> 47:59.820] We have a port. [48:00.160 --> 48:06.600] By the way, when we're talking ports, has anybody put a web server on any other port besides port 80? [48:07.340 --> 48:07.900] N443? [48:09.320 --> 48:09.880] Okay. [48:10.360 --> 48:13.080] Do you think Terado could actually have its port changed? [48:15.160 --> 48:19.460] A lot of the current security methods that are recommended is you just block this port. [48:22.240 --> 48:22.720] When? [48:25.920 --> 48:26.400] Okay. [48:26.680 --> 48:28.180] We have the port itself. [48:28.680 --> 48:31.000] Then we have the Terado tunneling protocol. [48:31.280 --> 48:35.540] And then we have IPv6 here. [48:37.400 --> 48:41.100] And then as we go a little bit further down, we can actually see the payload. [48:47.400 --> 48:49.100] So, now we can look at the webpage. [48:49.100 --> 48:50.380] Life is good. [48:53.100 --> 48:55.500] This is similar with most of the tunneling techniques. [48:55.900 --> 48:58.120] We also have neighbor discovery and auto configuration. [48:58.460 --> 49:01.960] Most people do not turn on any security on these by default. [49:02.200 --> 49:04.480] Therefore, it's very easy to access this. [49:04.680 --> 49:08.860] I've used this particular technique on ShmooCon, Black Hat, and DEFCON. [49:09.080 --> 49:15.660] And I found about 50% of the devices who want to talk to me via IPv6 because I go, hey, I'm an IPv6 router. [49:15.660 --> 49:19.800] And everybody that was talking IPv4 goes, hey, I want to talk to you. [49:20.140 --> 49:22.500] Because that's the precedent, IPv6 first. [49:22.920 --> 49:24.880] So, this can definitely be a problem. [49:25.440 --> 49:30.540] The end-to-end model requires some additional thinking and education on how to do this. [49:30.760 --> 49:32.000] There's a lot of complexities. [49:32.320 --> 49:36.940] There's also a lack of security guidelines, policies, training, and tools out there. [49:37.500 --> 49:43.900] Some of our scanning tools can't do anything from a v6 except for a single address and only unicast. [49:44.160 --> 49:46.400] So, we have some real challenges with this. [49:46.660 --> 49:50.160] So, by default, the defenders are behind the curb again. [49:50.360 --> 49:50.720] Yes! [49:51.220 --> 49:54.100] So, those of you in the pen-test world, look into this. [49:54.180 --> 49:54.720] This is fun. [49:57.600 --> 49:58.640] Okay, any questions? [49:59.540 --> 50:00.640] I'm done early. [50:00.780 --> 50:02.240] This is actually a two-hour presentation. [50:02.240 --> 50:09.740] We typically go through all the packets and present all the packets and give examples of how it's used. [50:10.100 --> 50:10.920] Any questions? [50:12.920 --> 50:13.920] Well, I'll be around. [50:14.020 --> 50:16.220] You can see my IPv6 address from Google. [50:16.380 --> 50:16.760] Yeah. [50:17.280 --> 50:19.060] I'll be around if you have any questions. [50:19.480 --> 50:21.000] I'd like to ask a question, please. [50:21.240 --> 50:21.520] Please. [50:21.740 --> 50:22.060] Yes! [50:22.400 --> 50:23.540] Yes, I'm in the central aisle. [50:23.700 --> 50:24.020] Thank you. [50:24.460 --> 50:24.940] Thank you! [50:25.460 --> 50:27.080] I happen to run a... [50:27.080 --> 50:28.580] do a little retrocomputing. [50:28.680 --> 50:30.320] I happen to run a Gopher server on the Internet. [50:30.320 --> 50:32.020] I was wondering if you could... [50:32.560 --> 50:33.240] Thank you! [50:34.780 --> 50:45.580] I was wondering if you could talk a little bit more about the future of a retro thing like Gopher as well as what the change of IPv6 will hold for some of these older technologies. [50:45.780 --> 50:46.060] Thank you. [50:46.820 --> 50:50.240] Wow, that was exactly the same question I got at the last presentation. [50:50.240 --> 51:06.100] The IETF and the community has defined a protocol that allows us to transfer at the TCP layer the ability for IPv4 devices still to talk to IPv6 devices. [51:06.500 --> 51:13.860] It's a little bit complex because you have to create the equivalent NATing tables or tables for the systems to connect. [51:13.860 --> 51:18.640] But it does allow you to extend the older technologies for who knows when. [51:19.020 --> 51:23.080] Unfortunately, the real challenge is that that's been deprecated by the IETF. [51:23.480 --> 51:25.540] Therefore, it's supposed to be no longer supported. [51:26.000 --> 51:29.620] Fortunately, Cisco has been nice enough to continue support on that protocol. [51:30.860 --> 51:39.100] It's basically... again, it transfers the packets at layer 4, TCP or UDP, back and forth between V4 and V6. [51:40.820 --> 51:54.360] This is kind of going to be like the old telephones, the old telephone switches where originally in the turn of the last century, we only had three or four digit addresses, phone numbers. [51:54.660 --> 52:01.080] And then we had to go to seven so that we could have routability within the whole country. [52:01.280 --> 52:04.180] And then we had to go more to have routability on the earth. [52:04.180 --> 52:11.740] A lot of those old technologies had to be replaced to support this new technology of routability or addressability. [52:12.380 --> 52:16.900] So recognize some of those devices are going to have a limited life. [52:17.320 --> 52:22.220] And you can extend the life with some of these gateway technologies. [52:22.520 --> 52:28.180] Another one that I've used is if you set up a SQUID proxy. [52:28.180 --> 52:31.580] You can have the outside of... if it's HTTP. [52:32.340 --> 52:36.020] You can have the outside boundary being IPv4 and IPv6. [52:36.180 --> 52:38.700] And the inside boundary can be IPv4 only. [52:38.900 --> 52:42.980] Do all your DNS queries through the Apache... or the SQUID server. [52:43.360 --> 52:46.480] And it allows you to do pretty much the same thing. [52:46.660 --> 52:54.840] It pretty much takes HTTP, removes it from IPv6, shoves it in an IPv4 packet and passes it along to the other system. [52:55.660 --> 53:01.780] Upgrades, I've not heard of Gopher or any of that technology being upgraded to IPv6 at this point. [53:02.300 --> 53:03.760] What about some other technologies? [53:04.060 --> 53:07.040] Like FTP is an old and variable file transfer system. [53:07.360 --> 53:09.220] You mentioned a little bit about it being rewritten. [53:09.420 --> 53:10.600] Can you tell a little more about that, please? [53:10.940 --> 53:11.680] The rewrite. [53:12.540 --> 53:19.200] What we had is we went from active only, where when I make a connection into the device, I was able to communicate with it. [53:19.200 --> 53:33.260] We had to then create passive, which forced us to not allow direct connection to it and had some additional handshakes required to be able to start an FTP connection. [53:33.540 --> 53:41.380] Fortunately, protocols like FTP, SSH, HTTP, HTTPS, most of the major protocols have already been upgraded. [53:41.380 --> 53:50.460] The question then is, is the provider of your operating system or your network devices also support that upgraded technology? [53:50.840 --> 53:53.720] Fortunately, most of the network vendors have taken care of that. [53:54.080 --> 53:55.700] Are we down to one minute? [53:57.140 --> 54:00.040] So, if you have any additional questions, you can... [54:00.040 --> 54:01.300] Thank you very much. [54:01.460 --> 54:01.780] Thank you. [54:01.940 --> 54:03.580] Next, there's one other person. [54:03.580 --> 54:04.600] Okay. [54:05.100 --> 54:10.280] I read on the webpage that the HOPE network is already running, but I only got a legacy IP address. [54:10.820 --> 54:12.780] So, why is there no 4.6 here? [54:12.940 --> 54:14.040] And what do you do against it? [54:14.320 --> 54:14.980] I don't know. [54:19.240 --> 54:20.600] Honestly, I have... [54:21.380 --> 54:26.040] I'm using Merido and Terido to do an outbound. [54:26.040 --> 54:34.440] And I also have GogoNet, which GogoNet is UDP over IPv6 over UDP or TCP over IPv4. [54:34.660 --> 54:38.620] So, I can still reach the IPv6 Internet through even this network. [54:39.340 --> 54:42.220] But a lot of organizations, a lot of... [54:42.220 --> 54:48.820] Matter of fact, Black Hat and DEFCON, ShmooCon, some of the other cons around, still don't do v6 themselves at the con. [54:49.060 --> 54:53.120] So, a request to HOPE, IPv6 in two years. [54:53.940 --> 54:54.420] Okay. [54:54.460 --> 54:59.500] For me, it's the first conference in the last two years, which doesn't have Internet, but only for fear, so... [54:59.500 --> 54:59.880] Yeah. [55:00.160 --> 55:00.920] Can you excuse me? [55:01.120 --> 55:03.300] At this point, I was cut off. [55:03.460 --> 55:04.680] The pink card came up. [55:04.880 --> 55:07.360] So, if anybody else has questions, I'll be in the back. [55:07.700 --> 55:08.920] And if anybody... [55:08.920 --> 55:16.440] If we can get more than 10 or 15 people to want to hear more, we can reserve the Monroe Room to have a longer discussion. [55:16.680 --> 55:17.100] Okay? [55:17.100 --> 55:17.140] Okay? [55:17.480 --> 55:17.520] Thank... [55:17.520 --> 55:18.140] Thank you.