IPv4 - mapped address considered harmful

From: Eduardo Segura (esegura@exa.unicen.edu.ar)
Date: 04/10/03

  • Next message: Einecker, Leah: "RE: Proof of Concept Tool on Web Application Security"
    Date: Thu, 10 Apr 2003 10:39:22 -0300
    From: Eduardo Segura <esegura@exa.unicen.edu.ar>
    To: pen-test@securityfocus.com
    
    

    "IPv4-Mapped Addresses on the Wire Considered Harmful"
    "draft-itojun-v6ops-v4mapped-harmful-01.txt"

    Available at:
    http://www.ietf.org/internet-drafts/draft-itojun-v6ops-v4mapped-harmful-01.txt

    This document describes posible vulnerabilities in IPv4 mapping.
    Does anyone know of penetration tests that use this? The author of the
    document suggests some scenarios, but I'd like to know if someone out
    there is conducting research on this.

    Eduardo.

    --------------------------------------------------------------
    Costs are climbing and complaints are rising
    as SPAM overloads your e-mail servers and Inboxes
    SurfControl E-mail Filter puts the brakes on spam & viruses
    and gives you the reports to prove it.
    http://www.securityfocus.com/SurfControl-pen-test2
    Download a free trial and see just
    what's going in and out of your organization.
    --------------------------------------------------------------


  • Next message: Einecker, Leah: "RE: Proof of Concept Tool on Web Application Security"

    Relevant Pages

    • Re: Firewall Testing Software
      ... Generate the packet against the ruleset you would like ... to test using Nemesis and watch the reply thru Tcpdump ... as SPAM overloads your e-mail servers and Inboxes ... SurfControl E-mail Filter puts the brakes on spam & viruses ...
      (Pen-Test)
    • Re: Firewall Testing Software
      ... are some open source/freeware tools that can help: ... There are also a number of other packet creation tools that can aid you in ... as SPAM overloads your e-mail servers and Inboxes ... SurfControl E-mail Filter puts the brakes on spam & viruses ...
      (Pen-Test)
    • Re: BIND/DNS Version check
      ... > version of BIND/DNS running on the server.. ... as SPAM overloads your e-mail servers and Inboxes ... SurfControl E-mail Filter puts the brakes on spam & viruses ...
      (Pen-Test)
    • Re: http fingerprinting
      ... Jeremiah Grossman gave a presentation at Seattle Blackhat 03 that may shed ... identifiers. ... as SPAM overloads your e-mail servers and Inboxes ... SurfControl E-mail Filter puts the brakes on spam & viruses ...
      (Pen-Test)
    • Re: http fingerprinting
      ... > As far as I know there is a paper/thesis on one tool called HMAP.pl. ... For Apache servers, you can use wh_fingerprint: ... as SPAM overloads your e-mail servers and Inboxes ... SurfControl E-mail Filter puts the brakes on spam & viruses ...
      (Pen-Test)