<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Extension Headers on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/extension-headers/</link>
    <description>Recent content in Extension Headers on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Sun, 11 Jan 2015 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/extension-headers/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>How To Configure Snort to Stop IPv6 Evasion Attacks</title>
      <link>https://insinuator.net/2015/01/how-to-configure-snort-to-stop-ipv6-evasion-attacks/</link>
      <pubDate>Sun, 11 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/how-to-configure-snort-to-stop-ipv6-evasion-attacks/</guid>
      <description>&lt;p&gt;This is a guest post from &lt;a href=&#34;https://twitter.com/AntoniosAtlasis&#34;&gt;Antonios Atlasis&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Hi all,&lt;/p&gt;&#xA;&lt;p&gt;during our BlackHat US 2014 talk titled “&lt;a href=&#34;https://www.ernw.de/download/Atlasis_Rey_BHUSA_2014_IPv6_Evasion_of_HighEnd_IPS_Devices_web.pdf&#34;&gt;&lt;em&gt;Evasion of High-End IPS Devices in the Age of IPv6&lt;/em&gt;&lt;/a&gt;”, among others we discussed a Snort preprocessor rule (116:456) which, when enabled (not the case by default), triggers an alert when an IPv6 datagram with nine (9) or more IPv6 Extension Headers is used (such a header was used by us to evade Snort). However, we mentioned that:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Atomic Fragments vs. Fragmentation in the IPv6 “Real World”</title>
      <link>https://insinuator.net/2014/08/atomic-fragments-vs.-fragmentation-in-the-ipv6-real-world/</link>
      <pubDate>Thu, 21 Aug 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/08/atomic-fragments-vs.-fragmentation-in-the-ipv6-real-world/</guid>
      <description>&lt;p&gt;This is a guest post by &lt;a href=&#34;http://www.secfu.net/about-me/&#34;&gt;Antonios Atlasis&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Continuing the &lt;a href=&#34;http://www.insinuator.net/2014/08/packet-too-big-messages-and-atomic-fragments/&#34;&gt;discussion&lt;/a&gt; about the IPv6 Atomic Fragments &lt;a href=&#34;http://lists.si6networks.com/pipermail/ipv6hackers/2014-August/001638.html&#34;&gt;started&lt;/a&gt; at the &lt;a href=&#34;http://lists.si6networks.com/listinfo/ipv6hackers/&#34;&gt;IPv6 hacker’s mailing list&lt;/a&gt; and the &lt;a href=&#34;http://www.ietf.org/id/draft-gont-v6ops-ipv6-ehs-in-real-world-00.txt&#34;&gt;freshly proposed draft RFC&lt;/a&gt; regarding &lt;a href=&#34;http://www.ietf.org/internet-drafts/draft-gont-6man-deprecate-atomfrag-generation-00.txt&#34;&gt;the deprecation of the generation of IPv6 Atomic Fragments&lt;/a&gt;, we decided to check very quickly what is the current situation regarding the acceptance or the rejection of Atomic fragments in the “real world”. Thanks to Rafael Schaefer and the RISC lab at ERNW, we got some first measurements really fast.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Evading IDPS by Combining IPv6 Extension Headers and Fragmentation “Features” – The Story of My Life…</title>
      <link>https://insinuator.net/2014/08/evading-idps-by-combining-ipv6-extension-headers-and-fragmentation-features-the-story-of-my-life/</link>
      <pubDate>Sat, 09 Aug 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/08/evading-idps-by-combining-ipv6-extension-headers-and-fragmentation-features-the-story-of-my-life/</guid>
      <description>&lt;p&gt;This is a guest post from &lt;a href=&#34;http://www.secfu.net/about-me/&#34;&gt;Antonios Atlasis&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;In the “&lt;a href=&#34;http://www.insinuator.net/2014/05/a-novel-way-of-abusing-ipv6-extension-headers-to-evade-ipv6-security-devices/&#34;&gt;A Novel Way of Abusing IPv6 Extension Headers to Evade IPv6 Security Devices&lt;/a&gt;” blogpost I described a way to evade a high-end commercial IDPS device, the Tipping Point IDPS (TOS Tipping Point, Package 3.6.1.4036 and vaccine 3.2.0.8530 digital), by abusing a minor detail at the IPv6 specification. As I promised at the end of that blogpost, this is not the end. In this blogpost I am going to describe several new and different ways of evading another popular IDPS, an open-source one this time, &lt;a href=&#34;http://suricata-ids.org/&#34;&gt;Suricata&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Novel Way of Abusing IPv6 Extension Headers to Evade IPv6 Security Devices</title>
      <link>https://insinuator.net/2014/05/a-novel-way-of-abusing-ipv6-extension-headers-to-evade-ipv6-security-devices/</link>
      <pubDate>Mon, 26 May 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/05/a-novel-way-of-abusing-ipv6-extension-headers-to-evade-ipv6-security-devices/</guid>
      <description>&lt;p&gt;(Or How the Smallest Detail Can Make a Difference)&lt;/p&gt;&#xA;&lt;p&gt;This is a guest post from &lt;a href=&#34;http://www.secfu.net/&#34;&gt;Antonios Atlasis&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;As it is well known to the IPv6 enthusiasts, one of the most significant changes that IPv6 brings with it, apart from supporting a really huge address space, is the improved support for Extensions and Options, which is achieved by the usage of IPv6 Extension headers. According to &lt;a href=&#34;http://www.rfc-editor.org/rfc/rfc2460.txt&#34;&gt;RFC 2460&lt;/a&gt;, “&lt;em&gt;changes in the way IP header options are encoded allows for more efficient forwarding, less stringent limits on the length of options, and greater flexibility for introducing new options in the future&lt;/em&gt;.” So, by adding IPv6 Extension headers, according to the designers of the protocol, flexibility and efficiency in the IP layer is improved.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers13 IPv6 Security Summit – First Presentations Available</title>
      <link>https://insinuator.net/2013/03/troopers13-ipv6-security-summit-first-presentations-available/</link>
      <pubDate>Mon, 11 Mar 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/03/troopers13-ipv6-security-summit-first-presentations-available/</guid>
      <description>&lt;p&gt;We had a great day today at the &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-ipv6-security-summit-2013/index.html&#34;&gt;Troopers IPv6 Security Summit&lt;/a&gt;. Good conversations, quite some technical discussion and a prevailing overall will to improve actual IPv6 network security.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.ernw.de/download/IPv6%20Extension%20Headers%20-%20New%20Features,%20and%20New%20Attack%20Vectors.pdf&#34;&gt;Here&lt;/a&gt; are the slides of Antonios Atlasis’ great talk on extension headers and &lt;a href=&#34;https://www.ernw.de/download/IPv6%20Extension%20Headers%20-%20New%20Features,%20and%20New%20Attack%20Vectors.py&#34;&gt;these&lt;/a&gt; are some of his accompanying Python/Scapy scripts. My own presentation on high secure IPv6 networks can be found &lt;a href=&#34;https://www.ernw.de/download/ERNW_TR13_High_Secure_Networks_v1_0web.pdf&#34;&gt;here&lt;/a&gt;. The slides of the &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-ipv6-security-summit-2013/troopers13-ipv6-security-summit-2013-workshop-overview-of-the-real-world-capabilities-of-major-commercial-security-products/index.html&#34;&gt;real-world capabilities workshop&lt;/a&gt; will not be published yet as we first have to discuss some stuff with a vendor.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Security Problems Related to Extension Headers &amp; Fragmentation</title>
      <link>https://insinuator.net/2013/03/ipv6-security-problems-related-to-extension-headers-fragmentation/</link>
      <pubDate>Mon, 04 Mar 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/03/ipv6-security-problems-related-to-extension-headers-fragmentation/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.mh-sec.de/&#34;&gt;Marc Heuse&lt;/a&gt; – who happens to give &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-ipv6-security-summit-2013/troopers13-ipv6-security-summit-2013-workshop-penetration-testing-in-ipv6-networks/index.html&#34;&gt;this workshop&lt;/a&gt; at the &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-ipv6-security-summit-2013/index.html&#34;&gt;Troopers IPv6 Security Summit&lt;/a&gt; next week – just sent &lt;a href=&#34;http://lists.si6networks.com/pipermail/ipv6hackers/2013-March/000972.html&#34;&gt;this email&lt;/a&gt; (subject: “Remote system freeze thanks to Kaspersky Internet Security 2013”) to the &lt;a href=&#34;http://lists.si6networks.com/listinfo/ipv6hackers/&#34;&gt;IPv6 hackers mailing list&lt;/a&gt;, describing how a system running a certain flavor of Kaspersky security products can be remotely frozen when receiving IPv6 packets with a specific combination of extension headers and fragmentation (which in turn can be easily generated by his &lt;a href=&#34;www.thc.org/thc-ipv6&#34;&gt;IPv6 protocol attack suite&lt;/a&gt;).&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Extension Headers: New Features, and New Attack Vectors</title>
      <link>https://insinuator.net/2013/02/ipv6-extension-headers-new-features-and-new-attack-vectors/</link>
      <pubDate>Sun, 17 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/ipv6-extension-headers-new-features-and-new-attack-vectors/</guid>
      <description>&lt;h3 id=&#34;this-is-a-guest-post-from-antonios-atlasis&#34;&gt;This is a guest post from &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-ipv6-security-summit-2013/troopers13-ipv6-security-summit-2013-presentations/index.html#extension_headers&#34;&gt;Antonios Atlasis&lt;/a&gt;&lt;/h3&gt;&#xA;&lt;p&gt;IPv6 introduces a lot of new features and consequently, a lot of new capabilities. Obviously, the most significant of them is the huge address space that it offers. However, this is not the only one. IPv6 also introduces the use of the IPv6 Extension Headers. The IPv6 header has been considerably simplified in comparison with IPv4 one. On the other hand, the IPv6 Extension Headers, not only do the “job” of most of the fields which were removed from the main header, but, additionally, they add many more. However, any new “technology” creates new attack opportunities and a “new” protocol, such as IPv6 could not be an exception, especially since its design and implementation is more complicated than it’s predecessor.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
