lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <C1922D93.1D989%jim_hoagland@symantec.com>
Date: Tue, 28 Nov 2006 18:16:51 -0800
From: Jim Hoagland <jim_hoagland@...antec.com>
To: "full-disclosure@...ts.grok.org.uk" <full-disclosure@...ts.grok.org.uk>,
	Bugtraq <bugtraq@...urityfocus.com>
Subject: New report on Teredo security

Hello all,

For anyone that is interested, there is a new report available about Teredo
security:
  http://www.symantec.com/avcenter/reference/Teredo_Security.pdf

>>From the abstract:
Teredo is a platform-independent protocol developed by Microsoft, which is
enabled by default in Windows Vista.  Teredo provides a way for nodes
located behind an IPv4 NAT to connect to IPv6 nodes on the Internet.
However, by tunneling IPv6 traffic over IPv4 UDP through the NAT and
directly to the end node, Teredo raises some security concerns.  Primary
concerns include bypassing security controls, reducing defense in depth, and
allowing unsolicited traffic.  Additional security concerns associated with
the use of Teredo include the capability of remote nodes to open the NAT for
themselves, benefits to worms, ways to deny Teredo service, and the
difficulty in finding all Teredo traffic to inspect.

You can also read the blog announcing the report:
  http://tinyurl.com/ulk9o

I hope you find this interesting or useful.  I spent a couple months of
research exploring the topic.

Best,
  
  Jim

-- 
Jim Hoagland, Ph.D., CISSP
Principal Security Researcher
Advanced Threats Research
Symantec Security Response
www.symantec.com

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ