We’re regularly asked to review IPv6 address plans from different organizations
and I’d like to share some reflections from such a process currently happening.
I’ve discussed a few aspects of IPv6 address planning before; those readers
interested please see
this post which
contains some references.
The organization in question is headquartered in Germany, has ~60K employees and
a number of subsidiaries in European countries. They belong to a “traditional
industry sector” (so they’re not an “Internet company”, even though they – as
the majority of large organizations right now – strive to be one in a few years
;-).
Starting a post, in 2019, with a mention of sth being “IPv4-only” somewhat hurts
;-), but here we go. Recently Manel Rodero
from Barcelona asked me the
following question on
Twitter:
In this post I’ll try to discuss some inherent aspects of that question and ofc
I’ll try to provide a response to it, too ;-).
Let’s first think about the main IPv6-related risks (= threats put into a
context of relevance) in an “environment [that] is only IPv4”. While some of
you might scratch your heads “what IPv6 threats could there be in an IPv4
setting?” I’m tempted to scratch my head: “what could be the reasons to run an
university network without IPv6 these days, or to use BIND?” (which I have a
strong opinion on, see here or
here). But I
disgress. More seriously the main reason for the question can be broken down to:
Some years ago Christopher wrote two posts
(2016,
2015)
about the IPv6-related characteristics of the WiFi network at Cisco Live
Europe. To somewhat continue this tradition and for mere technical interest I
had a look at some properties of this year’s setting.
There were two SSIDs of interest: a dual-stacked one (“CiscoLive2019”) and one
with v6-only plus NAT64 (“CL-NAT64”). For some background on the underlying
infrastructure components you might look at this
thread
by Nicolas Darchis from the NOC or
at this tweet
from Dominik Pickhardt. Some stats on
IPv6 usage at CLEUR can be
found here.
As some of you might recall we’ve introduced a dedicated “Active Directory
Security Track” at last year’s Troopers. For
Troopers19 we’ve expanded it to two days (as the SAP Security Track was
discontinued), and in the following I’ll provide a list of talks in the track.
Vincent Le Toux: You “try” to detect mimikatz
Abstract: This is 2019 and you still “try” to detect mimikatz. “Try”, because
after many years, this post exploitation tool continues to be successful.
As a contributor to mimikatz and also a blue team guy, I’m asking myself why
antivirus vendors are unable to catch it after many years.
How can a tool be blocked if nobody does not know what this tool is doing?
Because surprisingly, it is known only for credential collection but mimikatz is
a lot more.
To mitigate the lack of antivirus vendor, should we buy new fancy EDR tool or
try a technical approach? Apply a Framework? Rely on Compliance? Use a SIEM to
collect logs and apply correlation? In sumarry, can we detect mimikatz?
In this presentation we will try to understand why mimikatz has such power and
especially some weakness related to credential gathering and active directory
will be exposed.
While thinking about the agenda of the upcoming
Troopers NGI IPv6 Track I realized that quite a lot
of IPv6-related topics have been covered in the last years by various IPv6
practitioners (like my colleague
Christopher Werny) or researchers (like my
friend Antonios Atlasis). In a kind of
shameless self plug I then decided to put together of list of IPv6 talks I
myself gave at several occasions and of publications I (co-) authored. Please
find this list below (sorted by years); you can click on the titles to access
the respective documents/sources.
I hope some of this can be of help for one or the other among you in the course
of your own IPv6 efforts.
Cheers,
Last week Will “harmj0y” Schroeder published an
excellent technical article titled
“Not A Security Boundary: Breaking Forest Trusts”
in which he lays out how a highly critical security compromise can be achieved
across a forest boundary, resulting from a combination of default AD (security)
settings and a novel attack method. His post is a follow-up to the DerbyCon talk
“The Unintended Risks of Trusting Active Directory” which he had given together
with Lee Christensen and
Matt Nelson at DerbyCon (video
here). They
will also discuss this at the upcoming Troopers
Active Directory Security Track (details on some more talks, including
Sean Metcalf’s one, can be found in
this post
or
this one).
This is the first post discussing talks of the Active Directory Security Track
of this year’s Troopers which took place
last week in Heidelberg (like in the last nine years ;-). It featured, amongst
others, a new track focused on Microsoft AD and its security properties &
implications.
This was
the agenda.
The idea for this special track was born out of two considerations:
we had noted there’s a lot of stuff going on in the space, both on the offense
and on the defense side. And in pretty much every incident analysis & response
project we were brought in recently Active Directory played a huge role…
already in the early phase of the CfP several interesting submissions came in
(maybe due to the fact that some big guns of the field had voiced
verykindwordsinthepast)… and creating
an extra track simply relieved us from the burden to make a tough choice
between those.
As this was the first Troopers since its creation where I didn’t have any
official roles and out of personal interest (in a very distant past I happened
to be the co-author of the first German book on
Windows NT4 Security)
I decided to spend the majority of conference day 2 in the AD track. In
hindsight I’m tempted to say that the track was a huge success: brilliant talks,
pretty much always a packed room, and quite good discussions after the talks.
(yes, of course I’m biased, what makes you think that?).
At Troopers18 there will be a new special track on
Microsoft Active Directory and its security aspects, similar to the SAP security
track which we established some years ago. The AD security track will feature,
amongst others, the following talks.
Sean Metcalf: Active Directory Security. The Journey
Abstract: This talk is a journey into the challenges most organizations
encounter while trying to secure their ‘castle’. The attacker has to be right
only once, right? Not exactly. We will walk through effective security
strategies that will stymie and frustrate attackers and better protect the
Active Directory environment.
Looking at IPv6 deployment graphs like
this one it
becomes clear that IPv6 still is not widely deployed in enterprise space (the
reason for the apparent oscillation in that curve is the difference between
working days – where people use their office computers – and weekend where they
preferably use their smartphones or their home equipment connected by means of
broadband networks).
There’s a number of good reasons for this (in a nutshell: the overall IPv6
architecture is oriented around, and benefits, the decoupling of mostly
autonomous, self-organized endpoints from a well-managed/provider-managed
network infrastructure which isn’t exactly the operations model many large
enterprise organizations have in mind for their networks. also you might have a
look at
these slides
from RIPE74 to understand some of the reluctance to deploy IPv6 in certain
companies).
A while ago I wrote a short paper laying out options for an enterprise
organization to get global IPv6 address space from the RIPE NCC, discussing the
advantages and disadvantages of different approaches. As I think the topic may
be of interest for others, too, I’ve distilled an anonymized version. It can be
found here. I hope
some of you find it useful.