<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Christopher Werny on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/authors/christopher-werny/</link>
    <description>Recent content in Christopher Werny on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 17 Jul 2017 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/authors/christopher-werny/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>IPv6 RA Flags, RDNSS and DHCPv6 Conflicting Configurations Revisited</title>
      <link>https://insinuator.net/2017/07/ipv6-ra-flags-rdnss-and-dhcpv6-conflicting-configurations-revisited/</link>
      <pubDate>Mon, 17 Jul 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/07/ipv6-ra-flags-rdnss-and-dhcpv6-conflicting-configurations-revisited/</guid>
      <description>&lt;p&gt;As you may know, we published a &lt;a href=&#34;https://www.ernw.de/download/ERNW_Whitepaper_IPv6_RAs_RDNSS_DHCPv6_Conflicting_Parameters.pdf&#34;&gt;whitepaper&lt;/a&gt; discussing the behavior of different operating systems once they receive IPv6 configuration parameters from different sources two years ago. At that time, the results were quite a mess. We were curious whether the situation is still so “dire” like two years ago. We fired up the lab, updated the tested operating systems and performed the tests again.&lt;/p&gt;&#xA;&lt;p&gt;To summarize, at least in scenarios were only one router is involved, the results look way more consistent (even cross operating system) then two years ago. So we made progress on this front. Unfortunately, as soon as a second router is introduced into the segment it gets messy and the operating systems do show inconsistent behavior.&lt;/p&gt;</description>
    </item>
    <item>
      <title>One Step Closer –  RDNSS (RFC 8106) Support in Windows 10 Creators Update</title>
      <link>https://insinuator.net/2017/05/one-step-closer-rdnss-rfc-8106-support-in-windows-10-creators-update/</link>
      <pubDate>Mon, 08 May 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/05/one-step-closer-rdnss-rfc-8106-support-in-windows-10-creators-update/</guid>
      <description>&lt;p&gt;Good Afternoon,&lt;/p&gt;&#xA;&lt;p&gt;It is a pleasant surprise for many (us included) that Microsoft implemented support for the RDNSS (&lt;a href=&#34;https://tools.ietf.org/html/rfc8106&#34;&gt;RFC 8106&lt;/a&gt;) option in Router Advertisements beginning with the &lt;a href=&#34;https://blogs.technet.microsoft.com/windowsitpro/2017/04/05/whats-new-for-it-pros-in-the-windows-10-creators-update/&#34;&gt;Windows 10 Creators Update&lt;/a&gt;. Interestingly, I wasn’t able to find any official documents from Microsoft stating this. As we are involved in a lot of IPv6 related projects for our customers, the lack of RDNSS support for Windows and DHCPv6 for Android is a major pain point when implementing IPv6 in mixed client segments, as you need to implement both mechanisms to ensure that all clients do get the relevant network parameters. I won’t beat on the dead horse, but Microsoft’s decision is a huge step in the right direction and one can hope that one day Google finds a “compelling use case” to implement at least stateless DHCPv6 for Android.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some Notes from the Lab – BlackNurse in the IPv6 Era</title>
      <link>https://insinuator.net/2016/12/some-notes-from-the-lab-blacknurse-in-the-ipv6-era/</link>
      <pubDate>Mon, 05 Dec 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/12/some-notes-from-the-lab-blacknurse-in-the-ipv6-era/</guid>
      <description>&lt;p&gt;Since BlackNurse was released on 10th of November, we asked ourselves whether this problem does also apply to ICMPv6 traffic. To answer this question, Christian Tanck (one of our students) build a lab with several firewall appliances. Kudos to him for testing and the following blog post.&lt;/p&gt;&#xA;&lt;h3 id=&#34;intro&#34;&gt;Intro&lt;/h3&gt;&#xA;&lt;p&gt;&lt;img src=&#34;bl1.png&#34; alt=&#34;bl1&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;On 10^(th) of November, 2016 the &lt;a href=&#34;https://www.trusted-introducer.org/directory/teams/tdc-soc.html&#34;&gt;TDC Security Operations Center in Denmark&lt;/a&gt; published the BlackNurse Denial of Service Attack Report as an &lt;a href=&#34;http://soc.tdc.dk/blacknurse/blacknurse.pdf&#34;&gt;PDF download&lt;/a&gt; on their website and a &lt;a href=&#34;http://www.netresec.com/?page=Blog&amp;amp;month=2016-11&amp;amp;post=BlackNurse-Denial-of-Service-Attack&#34;&gt;blog post&lt;/a&gt; written by Erik Hjelmvik from NETRESEC. He was involved in the project by helping with the analysis of packet dumps, testing different systems, with ideas for test scenarios and at least inspired me with his blog post on how to build a test lab described later in this post. The attack on its own was discovered by the TDC analysts Kenneth B. Jørgensen and Lenny Hansson.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CVE-2016-1409 – IPv6 NDP DoS Vulnerability in Cisco Software</title>
      <link>https://insinuator.net/2016/05/cve-2016-1409-ipv6-ndp-dos-vulnerability-in-cisco-software/</link>
      <pubDate>Mon, 30 May 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/05/cve-2016-1409-ipv6-ndp-dos-vulnerability-in-cisco-software/</guid>
      <description>&lt;p&gt;Dear readers,&lt;/p&gt;&#xA;&lt;p&gt;As you may have already noticed, Cisco released an urgent &lt;a href=&#34;https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160525-ipv6&#34;&gt;security advisory&lt;/a&gt; describing an IPv6 Neighbor Discovery DoS Vulnerability in several flavors of Cisco’s operating systems. Currently IOS-XR, XE and NX-OS are affected while ASA and “classic” IOS are under investigation. At first glance, it might look like yet another IPv6 DoS vulnerability. Looking closer, Cisco is mentioning an unauthenticated, remote attacker due to insufficient processing logic for crafted IPv6 NDP packets that are sent to an affected device. Following the public discussion about the vulnerability, it seems that these packets will reach the, probably low rate-limited, &lt;a href=&#34;https://supportforums.cisco.com/document/93456/asr9000xr-local-packet-transport-services-lpts-copp&#34;&gt;LPTS&lt;/a&gt; filter/queue on IOS XR devices “crowding” out legitimate NDP packets resulting in a DoS for IPv6 traffic, or in general a high CPU load as these packets will be processed by the CPU. More details are currently not available, but this might indicate the affected systems aren’t doing proper message validation checks on NDP packets (in addition to the LPTS filter/queue problem).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Reflections on the IPv6-only WiFi Experience during Troopers</title>
      <link>https://insinuator.net/2016/03/reflections-on-the-ipv6-only-wifi-experience-during-troopers/</link>
      <pubDate>Fri, 25 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/reflections-on-the-ipv6-only-wifi-experience-during-troopers/</guid>
      <description>&lt;p&gt;Hello,&lt;/p&gt;&#xA;&lt;p&gt;Troopers is (unfortunately) over. It was a blast (but I may be biased ;-))! After things have settled, I want to take the opportunity to reflect my thoughts and impressions on the IPv6-only WiFi we had deployed during the conference. To make sure that everybody is on the same page let’s start at the beginning.&lt;/p&gt;&#xA;&lt;p&gt;In the last couple of years we had provided Dual-Stack connectivity on the main “Troopers” SSID but also had an additional IPv6-only SSID. This year we decided to spice things up and made the “Troopers“ SSID IPv6-only (with NAT64) while providing Dual-Stack connectivity on the “Legacy“ SSID. We wanted to get a feeling how many clients and applications can work properly in an IPv6-only environment. We intentionally didn’t announce it vastly beforehand, hoping that attendees would just connect to the main SSID without noticing anything. We were aware that some applications might expose issues but, as I said , we wanted to get a feeling to which degree problems actually occured.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Multicast Based IPv6 Neighbor Spoofing / Response Behavior on Cisco Devices</title>
      <link>https://insinuator.net/2016/03/multicast-based-ipv6-neighbor-spoofing-/-response-behavior-on-cisco-devices/</link>
      <pubDate>Tue, 01 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/multicast-based-ipv6-neighbor-spoofing-/-response-behavior-on-cisco-devices/</guid>
      <description>&lt;p&gt;Dear readers,&lt;/p&gt;&#xA;&lt;p&gt;today we want to examine the behavior of Cisco devices when they receive spoofed IPv6 Neighbor Advertisement packets from an untrusted system pretending to be the default router for the local segment. We start with a quick refresher how Cisco devices behave in the legacy (IPv4) world when they receive a spoofed broadcast ARP packet containing the IP address of the device but with a different MAC address, followed by a discussion of the corresponding behavior in the IPv6 world.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Observations from the Cisco Live Europe 2016 Wifi Infrastructure</title>
      <link>https://insinuator.net/2016/02/observations-from-the-cisco-live-europe-2016-wifi-infrastructure/</link>
      <pubDate>Tue, 16 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/observations-from-the-cisco-live-europe-2016-wifi-infrastructure/</guid>
      <description>&lt;p&gt;Good Evening,&lt;/p&gt;&#xA;&lt;p&gt;Enno and I spent the first day on Cisco Live Europe in Berlin today attending the “Advanced Practical Knowledge for Enterprise Deploying IPv6” technical breakout held by &lt;a href=&#34;https://twitter.com/bckcntryskr&#34;&gt;Tim Martin&lt;/a&gt; and &lt;a href=&#34;https://www.ciscolive.com/online/connect/speakerDetail.ww?PERSON_ID=B87EDE562B1002BDCC3504AD38E52492&#34;&gt;Jim Bailey&lt;/a&gt;. It was a good breakout session, and thanks again Tim for the honorable mention of our work in your slides! We really appreciate it. Like &lt;a href=&#34;https://www.insinuator.net/2015/01/observations-from-the-cisco-live-europe-wifi-infrastructure/&#34;&gt;last year&lt;/a&gt;, we were curious how the Wifi network was setup this year as I face a corresponding task for &lt;a href=&#34;https://www.troopers.de/troopers16/&#34;&gt;Troopers&lt;/a&gt; in March, with some &lt;a href=&#34;https://www.insinuator.net/2016/02/tr16-ipv6-security-summit-teaser-building-a-reliable-and-secure-ipv6-wifi-network/&#34;&gt;major changes&lt;/a&gt; in comparison to the last years. The Wifi infastructure in Berlin looked very similar to the one from last year in Milan, we had the “standard” Cisco Live SSID as well as an IPv6-only (with NAT64 as translation mechanism) SSID. The standard SSID looked identical to last year with the exception that now the &lt;a href=&#34;http://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/8-0/IPV6_DG.html#pgfId-76925&#34;&gt;RA Throttling&lt;/a&gt; feature on the WLC was active from the beginning! Neither the M nor the O flag are set which means that my client has to use the legacy protocol to resolve AAAA records. As I am running Windows, it does not support &lt;a href=&#34;https://tools.ietf.org/html/rfc6106&#34;&gt;RA option 25 &lt;/a&gt; but the option wasn’t included in the RAs anyway. The preference was configured to the default “medium”. One thing I noticed, but haven’t had a chance to ask &lt;a href=&#34;https://twitter.com/ayourtch&#34;&gt;Andrew Yourtchenko&lt;/a&gt;, was that for the legacy (IPv4) connection they use HSRPv2 as an FHRP protocol (indicated by the MAC address &lt;a href=&#34;http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipapp_fhrp/configuration/xe-3s/fhp-xe-3s-book/fhp-hsrp-v2.html&#34;&gt;00:00:0c:9f:f0:01&lt;/a&gt; I received from the gateway) but for IPv6 I received Router Advertisements from two different MAC addresses (which both belong to Cisco, so I don’t think anyone sent spoofed RAs).  I am curious about the reasoning for this approach 🙂&lt;br&gt;&#xA;What i also encountered was that the Peer-to-Peer Blocking feature was apparently not enabled on the SSID as I was able to enumerate approx. 1600 active clients at the time. No worries, I haven’t done anything else, just was curious whether the feature was activated or not…&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR16 IPv6 Security Summit Teaser: Basic IPv6 Attacks &amp; Defenses Workshop</title>
      <link>https://insinuator.net/2016/02/%23tr16-ipv6-security-summit-teaser-basic-ipv6-attacks-defenses-workshop/</link>
      <pubDate>Sat, 13 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/%23tr16-ipv6-security-summit-teaser-basic-ipv6-attacks-defenses-workshop/</guid>
      <description>&lt;p&gt;Dear Readers,&lt;/p&gt;&#xA;&lt;p&gt;It’s me again with another teaser for an upcoming workshop at the &lt;a href=&#34;https://www.troopers.de/ipv6-security-summit/&#34;&gt;IPv6 Security Summit&lt;/a&gt;. This one is a classic! If you happen to deploy IPv6 in your environment in the near future, but didn’t had the time to think about the security implications, this &lt;a href=&#34;https://www.troopers.de/events/ipv6-security-summit-2016/614_basic_ipv6_attacks__defenses_hands-on_workshop/&#34;&gt;workshop&lt;/a&gt; is the right place to start.&lt;/p&gt;&#xA;&lt;p&gt;We will start the workshop with a quick refresher of the core behavior of IPv6 to make sure that every attendee is on the same page. Before we start discussing and demonstrating various IPv6 attacks, we dive into (a little more abstract) topic of why IPv6 security actually isn’t that easy to implement. We will continue with IPv6 attacks targeted at the local link. Rafael and I will introduce commonly used IPv6 attack tools as well as performing various attacks in a dedicated lab environment. Every attendee is encouraged to participate in these exercises.  We will provide you with the necessary tools; you just have to bring a laptop with (ideally) Linux installed. We will prepare some virtual machines including VMware Player in case your corporate laptop runs Windows.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Multiple Address Family OSPFv3</title>
      <link>https://insinuator.net/2016/02/multiple-address-family-ospfv3/</link>
      <pubDate>Wed, 10 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/multiple-address-family-ospfv3/</guid>
      <description>&lt;p&gt;Dear Readers,&lt;/p&gt;&#xA;&lt;p&gt;today I want to talk about OSPFv3. I won’t cover the glory details of &lt;a href=&#34;http://tools.ietf.org/html/rfc5340&#34;&gt;OSPFv3&lt;/a&gt;, there are smarter guys than me out there who did that &lt;a href=&#34;http://packetlife.net/blog/2010/mar/2/ospfv2-versus-ospfv3/&#34;&gt;already&lt;/a&gt; 😉 and there are great resources to familiarize yourself with the protocol. However, it should be noted that OSPFv3 is not only OSPF for IPv6, OSPFv3 brought some major enhancements compared to OSPFv2. Wouldn’t it be cool to benefit from the enhancements in the IPv4 world as well?&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR16 IPv6 Security Summit Teaser: First-Hop-Security on HP Network Devices</title>
      <link>https://insinuator.net/2016/02/%23tr16-ipv6-security-summit-teaser-first-hop-security-on-hp-network-devices/</link>
      <pubDate>Tue, 09 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/%23tr16-ipv6-security-summit-teaser-first-hop-security-on-hp-network-devices/</guid>
      <description>&lt;p&gt;Hello Everybody,&lt;/p&gt;&#xA;&lt;p&gt;Today I want to give you a little teaser about my upcoming talk at the &lt;a href=&#34;https://www.troopers.de/ipv6-security-summit/&#34;&gt;IPv6 Security Summit&lt;/a&gt; about &lt;em&gt;First-Hop-Security&lt;/em&gt; on HP devices. In the past I presented on about First-Hop-Security in the &lt;a href=&#34;https://www.troopers.de/events/troopers13/363_securing_ipv6_in_the_cisco_space/&#34;&gt;Cisco&lt;/a&gt; realm and in &lt;a href=&#34;https://www.troopers.de/events/troopers15/482_ipv6_first_hop_security_in_virtualized_environments/&#34;&gt;virtualized e&lt;/a&gt;nvironments. Until recently, Cisco was mostly the only vendor who had a sufficient implementation of various IPv6 security features on their access-layer switches, but HP closed the gap considerably and it’s time to have an in-depth look at their implementation of those features.&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR16 IPv6 Security Summit Teaser: Building a Reliable and Secure IPv6 WiFi Network</title>
      <link>https://insinuator.net/2016/02/%23tr16-ipv6-security-summit-teaser-building-a-reliable-and-secure-ipv6-wifi-network/</link>
      <pubDate>Mon, 08 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/%23tr16-ipv6-security-summit-teaser-building-a-reliable-and-secure-ipv6-wifi-network/</guid>
      <description>&lt;p&gt;Hi everyone,&lt;/p&gt;&#xA;&lt;p&gt;some of you may have seen my last &lt;a href=&#34;https://www.insinuator.net/2016/02/dhcpv6-option-52-on-cisco-dhcpv6-server/&#34;&gt;blog post&lt;/a&gt; about the preparation of the Troopers network. Today I want to give you a little teaser on what to expect for the &lt;a href=&#34;https://www.troopers.de/events/ipv6-security-summit-2016/672_case_study_building_a_secure_ipv6_guest_wifi_network/&#34;&gt;talk&lt;/a&gt; I will present during the IPv6 Security Summit. As the title implies, it’s not only about building a secure IPv6 WiFi, but also a reliable one. One might think that there aren’t many differences in comparison to IPv4, but the heavy reliance on multicast of IPv6 does have implications for Wi-Fi networks in general.&lt;/p&gt;</description>
    </item>
    <item>
      <title>DHCPv6 Option 52 on Cisco DHCPv6 Server</title>
      <link>https://insinuator.net/2016/02/dhcpv6-option-52-on-cisco-dhcpv6-server/</link>
      <pubDate>Sat, 06 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/dhcpv6-option-52-on-cisco-dhcpv6-server/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;I am currently preparing the &lt;a href=&#34;https://www.troopers.de&#34;&gt;Troopers&lt;/a&gt; network in a lab environment to ensure that we all will have a smooth Wi-Fi experience during Troopers. I wanted to spice things up a little bit for the Wi-Fi deployment (more on that in a following blogpost) and get rid of IPv4 wherever possible. Our Wi-Fi infrastructure consists of typical Cisco Access Points (1602) and a 2504 Wireless LAN Controller. Beginning with WLC image 8.0 it is finally supported to establish the CAPWAP tunnel between the AP and the WLC over IPv6, which is awesome and I wanted to implement it right away.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Practical IPv6 Troubleshooting while Setting up the Troopers Network</title>
      <link>https://insinuator.net/2015/03/practical-ipv6-troubleshooting-while-setting-up-the-troopers-network/</link>
      <pubDate>Mon, 09 Mar 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/03/practical-ipv6-troubleshooting-while-setting-up-the-troopers-network/</guid>
      <description>&lt;p&gt;Hello Everyone,&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.troopers.de/troopers/&#34;&gt;Troopers&lt;/a&gt; is right around the corner and as I am responsible for the whole conference network I wanted to make sure that everything is working as expected. I went to the venue on Friday because of two things I wanted/needed to setup. Compared to last year’s setup we had a couple of changes in regards to the provider connection (resulting in some changes for our network setup). First, we now have a rather big pipe for the uplink and more importantly (well that depends on the point of view ;)) there is a native IPv6 connection. Before that I had to tunnel all IPv6 traffic from the venue to one of our gateways and to forward it out (as native IPv6) from there. As this step isn’t necessary anymore, and the staff on the venue isn’t that experienced with IPv6, I had in mind to setup and verify that IPv6 is working as desired. The router used over there is a &lt;a href=&#34;http://routerboard.com/CCR1036-12G-4S&#34;&gt;Mikrotek Routerboard&lt;/a&gt;. As I haven’t worked with these devices before, I was curious whether everything works as it should ;).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Observations from the Cisco Live Europe Wifi Infrastructure</title>
      <link>https://insinuator.net/2015/01/observations-from-the-cisco-live-europe-wifi-infrastructure/</link>
      <pubDate>Tue, 27 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/observations-from-the-cisco-live-europe-wifi-infrastructure/</guid>
      <description>&lt;p&gt;Given that Enno and I are network geeks, and that I am responsible for setting up the &lt;a href=&#34;https://www.troopers.de/&#34;&gt;Troopers&lt;/a&gt; Wifi network I was curious which components might be used at Cisco Live and which IPv6 related configuration was done for the Wifi network to ensure a reliable network and reduce the chatty nature of IPv6. Andrew Yourtchenko (&lt;a href=&#34;https://twitter.com/ayourtch&#34;&gt;@ayourtch&lt;/a&gt;) already did an amazing job last year at Cisco Live Europe explaining in detail (at the time session &lt;a href=&#34;http://d2zmdbbm9feqrf.cloudfront.net/2014/eur/pdf/BRKEWN-2666.pdf&#34;&gt;BRKEWN-2666&lt;/a&gt;) the intricacies of IPv6 in Wifi networks, and how to optimize IPv6 for these networks. He was also a great inspiration for me when setting up the &lt;a href=&#34;https://www.troopers.de/media/filer_public/22/9d/229d97ec-f2de-4dac-a533-6651a493f231/troopers14-case_study-building_a_secure_ipv6_guest_wifi_network-christopher_werny.pdf&#34;&gt;Troopers Wifi network&lt;/a&gt; a couple of weeks later. Thank You!&lt;/p&gt;</description>
    </item>
    <item>
      <title>North American IPv6 Summit 2014</title>
      <link>https://insinuator.net/2014/10/north-american-ipv6-summit-2014/</link>
      <pubDate>Tue, 14 Oct 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/10/north-american-ipv6-summit-2014/</guid>
      <description>&lt;p&gt;Hello everyone,&lt;/p&gt;&#xA;&lt;p&gt;I know I am a bit late with this post, but I was speaking on the &lt;a href=&#34;http://www.rmv6tf.org/na-ipv6-summit/2014-na-ipv6-summit&#34;&gt;North American IPv6 Summit&lt;/a&gt; in Denver three weeks ago. The focus of my talk was on &lt;em&gt;&lt;a href=&#34;https://www.ernw.de/download/TROOPERS_IPv6SecSummit_ERNW_IPv6_Structural_Deficits.pdf&#34;&gt;Why IPv6 Security is hard – Structural Deficits of IPv6 &amp;amp; Their Implications&lt;/a&gt;&lt;/em&gt; (slightly modified/updated from the &lt;a href=&#34;https://www.troopers.de/troopers14/troopers14-ipv6-security-summit-2014/index.html&#34;&gt;Troopers IPv6 Security Summit&lt;/a&gt;).  We consider the NA IPv6 Summit as one of the most important IPv6 events at all and we were happy to contribute to the overall success. The conference was organized for the 7^(th) time by the &lt;a href=&#34;http://www.rmv6tf.org/&#34;&gt;Rocky Mountain IPv6 Task Force&lt;/a&gt; and took place in the Grand Hyatt Denver (37th floor ;-)). Luckily the weather was perfect, and the view of the landscape from the conference rooms was just amazing. I really enjoyed the time in Denver, as the organizer sdid all they could to treat the speaker well J. The talks were of mix of regular research or case-study type talks and some sponsored talks ranging from deployment experience, security and statistics to SDN (Yes, I said it ;)) and the Internet of Things (I said it again ;)). The line-up was nicely put together.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Microsoft Windows Update over IPv6 (or not?)</title>
      <link>https://insinuator.net/2014/05/microsoft-windows-update-over-ipv6-or-not/</link>
      <pubDate>Wed, 21 May 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/05/microsoft-windows-update-over-ipv6-or-not/</guid>
      <description>&lt;p&gt;Hello everyone,&lt;/p&gt;&#xA;&lt;p&gt;I recently stumbled over a &lt;a href=&#34;http://technet.microsoft.com/en-us/network/hh994905.aspx&#34;&gt;document&lt;/a&gt; from Microsoft which lists all services/applications that support IPv6. Most of the content wasn’t new for me, but one item caught my attention. &lt;em&gt;Windows Update&lt;/em&gt;. I haven’t heard before that Windows Update can be done over IPv6 (but this could just be me not looking hard enough ;)), so I was eager to test it out seeing if this is really the case. I was also curious why Microsoft referenced this &lt;a href=&#34;http://blogs.msdn.com/b/b8/archive/2012/06/05/connecting-with-ipv6-in-windows-8.aspx&#34;&gt;document&lt;/a&gt; in the respective column.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Configuring IPv6 Snooping and DHCPv6 Guard on Cisco IOS</title>
      <link>https://insinuator.net/2014/01/configuring-ipv6-snooping-and-dhcpv6-guard-on-cisco-ios/</link>
      <pubDate>Thu, 30 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/configuring-ipv6-snooping-and-dhcpv6-guard-on-cisco-ios/</guid>
      <description>&lt;p&gt;Hi everyone,&lt;/p&gt;&#xA;&lt;p&gt;Some of you may already know (the ones who are following Enno on &lt;a href=&#34;https://twitter.com/Enno_Insinuator&#34;&gt;Twitter&lt;/a&gt;) that Enno and I had our lab day in preparation for the &lt;a href=&#34;https://www.troopers.de/troopers14/troopers14-ipv6-security-summit-2014/index.html&#34;&gt;IPv6 Security Summit&lt;/a&gt; at &lt;a href=&#34;https://www.troopers.de&#34;&gt;Troopers&lt;/a&gt;.  We had a brand new and shiny Cat4948E as our lab device to do some testing of the current generation of Cisco’s IPv6 First Hop Security (FHS) mechanisms. The Catalyst was running the latest image available (15.1(2)SG3).&lt;/p&gt;&#xA;&lt;p&gt;In this small blog post, we will take a look at the configuration and behavior of IPv6 Snooping and DHCPv6 Guard. So let’s start with IPv6 Snooping:&lt;/p&gt;</description>
    </item>
    <item>
      <title>t2’13 Infosec Conference</title>
      <link>https://insinuator.net/2013/11/t213-infosec-conference/</link>
      <pubDate>Sun, 17 Nov 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/11/t213-infosec-conference/</guid>
      <description>&lt;p&gt;Hey everybody,&lt;/p&gt;&#xA;&lt;p&gt;I am little bit late to the party, but I had the pleasure to present a talk about VoIP based toll fraud incidents (more on this in a following blogpost, for the moment my slides can be found &lt;a href=&#34;https://www.ernw.de/download/T2_VoIP_TollFraud_cwerny_v1.0.pdf&#34;&gt;here&lt;/a&gt;) at the annual &lt;a href=&#34;http://t2.fi/&#34;&gt;t2 security conference&lt;/a&gt; in Helsinki. The conference took place from 24th to 25th October in the Radisson Blu Royal hotel. I must say that it was a blast. Tomi (the host) took really good care of all speakers, and I really liked the spirit of the conference, very similar to &lt;a href=&#34;https://www.troopers.de&#34;&gt;Troopers&lt;/a&gt;. It is not an commercial event, seats are limited to 100 and it is all about delivering a &lt;a href=&#34;http://t2.fi/schedule/2013/&#34;&gt;great set of talks&lt;/a&gt; to the audience and having a good time during and after the conference. Sure the conference has some sponsors and tickets are sold, but Tomi doesn’t do it to earn money. His only intention is to cover the cost for setting up this great event.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A First Glance – RA Guard Support in Hyper-V 3.0</title>
      <link>https://insinuator.net/2012/07/a-first-glance-ra-guard-support-in-hyper-v-3.0/</link>
      <pubDate>Tue, 24 Jul 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/07/a-first-glance-ra-guard-support-in-hyper-v-3.0/</guid>
      <description>&lt;p&gt;Last week I read about the new networking features of the integrated vSwitch of Hyper-V 3.0. I was quite surprised that RA Guard will be natively supported and was curious about implementation and functionality. If you don’t know how RA Guard  works, I recommend reading our previous blog posts &lt;a href=&#34;http://www.insinuator.net/2011/01/ipv6-security-part-1-ra-guard-the-theory-3/&#34;&gt;here&lt;/a&gt;, &lt;a href=&#34;http://www.insinuator.net/2011/03/ipv6-security-part-2-ra-guard-%E2%80%93-lets-get-practical/&#34;&gt;here&lt;/a&gt;, &lt;a href=&#34;http://www.insinuator.net/2011/03/ipv6-security-%E2%80%92-the-story-continues/&#34;&gt;here&lt;/a&gt;, &lt;a href=&#34;http://www.insinuator.net/2011/05/yet-another-update-on-ipv6-security-some-notes-from-the-ipv6-kongress-in-frankfurt/&#34;&gt;here&lt;/a&gt; and &lt;a href=&#34;http://www.insinuator.net/2012/03/the-story-continues-another-ipv6-update/&#34;&gt;here&lt;/a&gt;, or have a look at our workshop at &lt;a href=&#34;http://www.troopers.de/archives/troopers12/agenda/advanced-ipv6-security-workshop/&#34;&gt;Troopers12&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;I downloaded Windows Server 2012 RC to do some practical testing. Since my girlfriend was working the whole weekend, I had plenty of time to play around with all that stuff without risking trouble 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Story Continues – Another IPv6 Update</title>
      <link>https://insinuator.net/2012/03/the-story-continues-another-ipv6-update/</link>
      <pubDate>Fri, 30 Mar 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/03/the-story-continues-another-ipv6-update/</guid>
      <description>&lt;p&gt;TROOPERS12 came to an end last week on Friday; needless to say it was an awesome  event. 😉&lt;br&gt;&#xA;The first two days offered workshops on various topics. On Monday Enno, &lt;a href=&#34;http://mhsec.de/&#34;&gt;Marc “Van Hauser” Heuse&lt;/a&gt; and I gave a one day workshop on “Advanced IPv6 Security”.  I think attendees as well as trainers had a real good time during and after the workshop fiddling around with IPv6. Especially Marc had quite some fun as he discovered that we provided “global” IPv6 Connectivity for the conference network, and according to one of his tweets, TROOPERS12 was the first security conference he visited, offering this kind of connectivity.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Groundhog Day: Don’t Pay Money for Some Else’s Calls, Still</title>
      <link>https://insinuator.net/2012/02/groundhog-day-dont-pay-money-for-some-elses-calls-still/</link>
      <pubDate>Fri, 24 Feb 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/02/groundhog-day-dont-pay-money-for-some-elses-calls-still/</guid>
      <description>&lt;p&gt;Hi everyone,&lt;br&gt;&#xA;it’s me again with another story of a toll fraud incident at one of our customers (not the same as &lt;a href=&#34;http://www.insinuator.net/2012/02/dont-pay-money-for-someone-elses-calls-again/&#34; title=&#34;Don’t Pay Money for Someone Else’s Calls, Again&#34;&gt;the last time&lt;/a&gt; of course ;-)).&lt;br&gt;&#xA;The story began basically like the last one: We received a call with an urgent request to help investigating a toll fraud issue. Like the last time I visited the site in order to get an idea on what was going on exactly. The customer has a VoIP deployment consisting of the whole UC Suite Cisco offers: Call Manager, Unity Connection for the voice mailboxes, Cisco based Voice-Gateways and of course, IP phones.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Don’t Pay Money for Someone Else’s Calls, Again</title>
      <link>https://insinuator.net/2012/02/dont-pay-money-for-someone-elses-calls-again/</link>
      <pubDate>Thu, 02 Feb 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/02/dont-pay-money-for-someone-elses-calls-again/</guid>
      <description>&lt;p&gt;One of our customers called us recently and asked for some support in investigating a toll fraud issue they encountered in one of their sites. Their telecommunications provider had contacted them informing them that they had accumulated a bill of 30.000€ over the last ten days.&lt;/p&gt;&#xA;&lt;p&gt;Without knowing anything more specific, I drove to the affected site to get the whole picture.&lt;/p&gt;&#xA;&lt;p&gt;They have a VoIP deployment based on Cisco Unified Communications Manager (CUCM, aka Call Manager) as Call Agent. The CUCM is connected via a H.323 trunk to a Cisco 2911 ISR G2 which is acting as a voice gateway. The ISR has a primary rate ISDN (PRI) Interface which is connected to the PBX of the telco. Furthermore they use a feature called Direct-inward Dial (DID) or Direct Dial-in (DDI) which is offered by Telco’s to enable calling parties to dial directly to an extension on a PBX or voice gateway.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
