Re: IPv6

From: roy lo (roylo@sr2c.com)
Date: 12/21/02

  • Next message: roy lo: "Re: IPv6"
    Date: Fri, 20 Dec 2002 23:53:34 -0500
    From: roy lo <roylo@sr2c.com>
    To: Steven Bairstow <sab139@psu.edu>
    
    

    I think it was used to perform the attack, I have heard this type of
    attack from a friend of mine before awhile ago.

    Steven Bairstow wrote:

    >Do you mean that IPv6 tunneling was turned on as part of the compromise? Or that it was used to perform the attack?
    >
    >
    >
    >>Recently one of the Honeynet Project's Solaris Honeynets was compromised.
    >>What made this attack unique was IPv6 tunneling was enabled on the system,
    >>with communications being forwarded to another country. The attack and
    >>communications were captured using Snort, however the data could not be
    >>decoded due to the IPv6 encapsulation.
    >>
    >>This made me consider, this activity could be used as a means of
    >>"covert" communications or activity. Many IDS systems, and potentially
    >>many sniffers, have difficulty decoding IPv6 activity. Was wondering if
    >>others had seen this activity, and the implications it may have to the IDS
    >>community?
    >>
    >>lance
    >>
    >>
    >
    >
    >
    >

    -- 
    Roy Lo  
    Freelance Consultant 
    E-mail -  roylo@sr2c.com
    Sun Certified Network Administrator (SCNA)
    Sun Certified System Administrator (SCSA)
    Cisco Certified Network Associate (CCNA) 
    


    Relevant Pages

    • Re: IPv6
      ... Do you mean that IPv6 tunneling was turned on as part of the compromise? ... Or that it was used to perform the attack? ... >with communications being forwarded to another country. ...
      (Focus-IDS)
    • Re: hyperthreading on OSR507 w/mp4
      ... One way is deliberate covert communications between two processes. ... The second way is a potential 1-way covert channel: an attack process ... compiler would change it enough to break the attack program. ...
      (comp.unix.sco.misc)
    • Re: Jewish Attitudes to Dresden Bombing
      ... was called upon to attack Dresden; this was considered a target of the first ... become the main centre of communications for the defence of Germany on the ... the morale of the Germans and their support for the war. ... casualties in Dresden for more Allied/Jewish/enemy casualties later because ...
      (soc.culture.jewish.moderated)
    • Re: [Full-disclosure] 0day: PDF pwns Windows
      ... The recent incident of Estonia Under *Russian Cyber Attack*? ... cyberwarfare theater as country against country as the purpose of such ... warfare would LIKELY be to disconnect/disrupt communications. ... botnet would only serve as cover while the real attack happens. ...
      (Full-Disclosure)
    • Re: WPA broken?
      ... Wi-Fi Protected Access are vulnerable to an attack that ... could compromise certain communications in less than 15 minutes, ... two researchers plan to tell attendees next week at the PacSec ...
      (alt.internet.wireless)

  • Quantcast