Re: draft-cerveny-bmwg-ipv6-nd-02

joel jaeggli <[email protected]>
Newsgroups gmane.ietf.bmwg
Message-ID <[email protected]>
On 11/18/13, 4:33 AM, Bill Cerveny wrote:
> Hi Nalini,
> 
> See comments below:
> 
> On Nov 14, 2013, at 8:50 AM, Nalini Elkins
> <[email protected]
> <mailto:[email protected]>> wrote:
> 
>> Bill,
>>
>> As I commented at the BMWG meeting, IMHO a few things would be quite
>> valuable to benchmark for IPv6.  I do not know if these are in scope
>> of the charter.  We can certainly discuss further, if desired.
>>
>> 1.  The impact of extension headers on performance
>>      There has been quite a bit of discussion in v6ops and 6man about
>> "long" extension headers and ASIC size.  That is, if the header gets
>> too big, then it is routed slowly.   I, for one, would like to see
>> some kind of formal discussion and benchmarking of this.
> 
> See http://tools.ietf.org/html/rfc5180#section-5.3, "IPv6 Benchmarking
> Methodology", section "Traffic with Extension Headers". There may be
> value in a more in-depth discussion and benchmarking of extension
> headers and its impact on routers / intermediate nodes.

It's a probably mistaken generalization  to assume there's a recourse to
a "slow path". In many platforms it's perfectly reasonable to expect
fast-path or no-path.

>>
>> 2.  Router advertisements:
>>      Much "bad" stuff can be done with Router Advertisements.   See
>> UTube video: http://www.youtube.com/watch?v=TfsfNWHCKK0
>>      I believe he got this from : https://www.thc.org/thc-ipv6/  which
>> also has:
> 
> This was an interesting attack. I had replicated the behavior described
> in the YouTube video with Windows 7 and Windows 8 in VMs using
> flood_router6 in Nov. 2012. Sam Bowne had done a bit of research on this
> issue, including characterizing the behavior on multiple systems as well
> as confirming that Microsoft had mostly fixed the problem with patches
> in 2013.
> 
> A distinction with the flood_router6 Windows attack is that it didn't
> attack routers (intermediate nodes), as far as I know, and the attack
> could "only" be launched from the same "broadcast domain."
> 
> Bill
>>         - parasite6: icmp neighbor solitication/advertisement spoofer, puts you as man-in-the-middle, same
>>  as ARP mitm (and parasite)
>> 	- alive6: an effective alive scanng, which will detect all systems listening to this address
>> 	- dnsdict6: parallized dns ipv6 dictionary bruteforcer
>> 	- fake_router6: announce yourself as a router on the network, with the highest priority
>> 	- redir6: redirect traffic to you intelligently (man-in-the-middle) with a clever icmp6 redirect spoofer
>> 	- toobig6: mtu decreaser with the same intelligence as redir6
>> 	- detect-new-ip6: detect new ip6 devices which join the network, you can run a script to automatically scan these systems etc.
>> 	- dos-new-ip6: detect new ip6 devices and tell them that their chosen IP collides on the network (DOS).
>> 	- trace6: very fast traceroute6 with supports ICMP6 echo request and TCP-SYN
>> 	- flood_router6: flood a target with random router advertisements
>> 	- flood_advertise6: flood a target with random neighbor advertisements
>> 	- exploit6: known ipv6 vulnerabilities to test against a target
>> 	- denial6: a collection of denial-of-service tests againsts a target
>> 	- fuzz_ip6: fuzzer for ipv6
>> 	- implementation6: performs various implementation checks on ipv6
>> 	- implementation6d: listen daemon for implementation6 to check behind a fw
>> 	- fake_mld6: announce yourself in a multicast group of your choice on the net
>> 	- fake_mld26: same but for MLDv2
>> 	- fake_mldrouter6: fake MLD router messages
>> 	- fake_mipv6: steal a mobile IP to yours if IPSEC is not needed for authentication
>> 	- fake_advertiser6: announce yourself on the network
>> 	- smurf6: local smurfer
>> 	- rsmurf6: remote smurfer, known to work only against linux at the moment
>> 	- sendpees6: a tool by willdamn(ad)gmail.com <http://gmail.com>, which generates a neighbor solicitation requests with a lot of CGAs (crypto stuff ;-) to keep the CPU busy. nice.
>>         - thcping6: sends a hand crafted ping6 packet
>>  
>>  
>> Thanks,
>>
>> Nalini Elkins
>> Inside Products, Inc.
>> (831) 659-8360
>> www.insidethestack.com <http://www.insidethestack.com>
>>
>>  
>> _______________________________________________
>> bmwg mailing list
>> [email protected] <mailto:[email protected]>
>> https://www.ietf.org/mailman/listinfo/bmwg
> 
> 
> 
> _______________________________________________
> bmwg mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/bmwg
>

_______________________________________________
bmwg mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/bmwg
signature.asc (application/pgp-signature, 308 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.22 (Darwin)
Comment: GPGTools - http://gpgtools.org
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iEYEARECAAYFAlKMYR4ACgkQ8AA1q7Z/VrIXNACgiU1UScqqAm6uD2ECmoTPbkE5
vqIAn0VxytbCKTX7HXNVEb4cFqG+wBXO
=rrPR
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.