Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Full-disclosure] New report on Teredo security |
|---|---|
| Date: | Wed, 29 Nov 2006 03:25:00 +0000 |
Jim Hoagland wrote:
Hello all, For anyone that is interested, there is a new report available about Teredo security: http://www.symantec.com/avcenter/reference/Teredo_Security.pdf
One very simple solution (at least as far as I know ;) is to block, the in the paper mentioned, UDP port 3544 and the Teredo client can't reach any of the servers anymore for an initial contact, thus won't find relays to talk. If the user is willing + able to tweak those ports or other things they can also find their way out of your network over a HTTP-through-proxy or NSTX (IP over DNS) and various other models. There are enough covert channel possibilities, as such Teredo is not a thread per se. The big problem though is that it is there by default (at least on Vista and also on XP's that have IPv6 installed). Administrators should thus be made very aware of this; then again if they still are not aware of this problem they are probably completely ignorant of IPv6, and that was one of the reasons that this protocol exists in the first place ;) For (net)admins the solutions are: - Enable IPv6 and provide native IPv6 to their users, as then in Vista/XP Teredo is not used. - block UDP port 3544 Smart admins that don't want to enable their full network to do IPv6 yet (eg no firewall that supports it or no numbering plan, no upstream that can provide it etc), might simply opt to do IPv6 Route Advertisements anyway using 2001:db8::/32 (documentation) as a prefix. The router that advertises the prefix should then send ICMPv6 destination unreaches for everything, effectively blocking IPv6 connectivity and because of the RA, Vista's/XP's Teredo is disabled. Note that Vista/XP also try and do ISATAP and 6to4 automatically to get out of the NAT box. Greets, Jeroen
signature.asc
Description: OpenPGP digital signature
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Full-disclosure] Links smbclient command execution, Mikulas Patocka |
|---|---|
| Next by Date: | Re: [Full-disclosure] Sasser, Matthew Flaschen |
| Previous by Thread: | [Full-disclosure] New report on Teredo security, Jim Hoagland |
| Indexes: | [Date] [Thread] [Top] [All Lists] |