官术网_书友最值得收藏!

IPv6

Although IPv4 seems to permit a large address space, freely available IP addresses were exhausted several years ago, forcing the employment of NAT to increase the number of available addresses. A more permanent solution has been found in the adoption of an improved IP addressing scheme, IPv6. Although it constitutes less than five percent of internet addresses, its usage is increasing, and penetration testers must be prepared to address the differences between IPv4 and IPv6. In IPv6, the source and destination addresses are 128 bits in length, yielding 2128 possible addresses, that is, 340 undecillion addresses!

The increased size of the addressable address space presents some problems for penetration testers, particularly when using scanners that step through the available address space looking for live servers. However, some features of the IPv6 protocol have simplified discovery, especially the use of ICMPv6 to identify active link-local addresses.

It is important to consider IPv6 when conducting initial scans for the following reasons:

  • There is uneven support for IPv6 functionality in testing tools, so testers must ensure that each tool is validated to determine their performance and accuracy in IPv4, IPv6, and mixed networks.
  • Because IPv6 is a relatively new protocol, the target network may contain misconfigurations that leak important data; testers must be prepared to recognize and use this information.
  • Older network controls (firewalls, IDS, and IPS) may not detect IPv6. In such cases, penetration testers can use IPv6 tunnels to maintain covert communications with the network, and exfiltrate the data undetected.
主站蜘蛛池模板: 苍梧县| 宿松县| 洛宁县| 彩票| 台北县| 南城县| 南郑县| 罗平县| 博白县| 商水县| 盖州市| 凭祥市| 汶川县| 铜山县| 南丹县| 湾仔区| 车险| 宣武区| 涞源县| 宁波市| 永平县| 西丰县| 庐江县| 吴桥县| 竹北市| 英吉沙县| 高碑店市| 沽源县| 普宁市| 获嘉县| 修武县| 双江| 张家界市| 竹溪县| 同仁县| 马鞍山市| 新源县| 新昌县| 西乌珠穆沁旗| 宿州市| 灌阳县|