TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Black Hills InfoSec

Securely Deploying IPv6 in 2020 Part 1: Internet Facing Perimeter

BHIS · 2020-05-11 · Read original ↗

ATT&CK techniques detected

4 predictions
T1557.001Name Resolution Poisoning and SMB Relay
85%
“##te6 ”. after that high - level introduction, let ’ s talk about security which is where the action really needs to be. i would like to break this down into four important topics, ipv6 addressing and scope, internet control message protocol ( icmpv6 ), and perimeter network secu…”
T1572Protocol Tunneling
82%
“friends at my local isp and i said, “ hey guys, i want an ipv6 address block ”. and they said, “ we don ’ t carry ipv6 ”. ( cue the “ you just lost your pacman game ” music … ) i am fortunate enough to have a small static ipv4 allocation, so i thought to myself “ it ’ s time to t…”
T1572Protocol Tunneling
67%
“the first thing i did as soon as that tunnel came up? ”. it ’ s pretty simple, i installed and configured dns, because who in their right mind wants to remember an ipv6 address. not too difficult with a debian linux to do so : “ apt install bind9 ” will do it but you probably wan…”
T1095Non-Application Layer Protocol
32%
“= > realm local - ff04 = > admin local - ff05 = > site local - ff08 = > organization local - ff0e = > global - ff0f = > reserved / unused internet control message protocol version 6 ( icmpv6 ) before i start these discussions, we cannot avoid talking about icmpv6 without which ip…”

Summary

Joff Thyer // Introduction If there is anything that the start of 2020 has taught us, it is that Internetworking services are in higher demand than ever before.  IPv4 is […]

The post Securely Deploying IPv6 in 2020 Part 1: Internet Facing Perimeter appeared first on Black Hills Information Security, Inc..