Download - Chema Alonso - Hachetetepe dospuntos slaac slaac [Rooted CON 2013]

Transcript
Page 1: Chema Alonso - Hachetetepe dospuntos slaac slaac [Rooted CON 2013]

Hachetetepé dos puntos SLAAC SLACC

Chema Alonso

[email protected]

Page 3: Chema Alonso - Hachetetepe dospuntos slaac slaac [Rooted CON 2013]

IPv6 is on your box!

Page 4: Chema Alonso - Hachetetepe dospuntos slaac slaac [Rooted CON 2013]

And it works!: ipconfig

Page 5: Chema Alonso - Hachetetepe dospuntos slaac slaac [Rooted CON 2013]

And it works!: route print

Page 6: Chema Alonso - Hachetetepe dospuntos slaac slaac [Rooted CON 2013]

And it works!: ping

Page 7: Chema Alonso - Hachetetepe dospuntos slaac slaac [Rooted CON 2013]

And it works!: ping

Page 8: Chema Alonso - Hachetetepe dospuntos slaac slaac [Rooted CON 2013]

LLMNR

Page 9: Chema Alonso - Hachetetepe dospuntos slaac slaac [Rooted CON 2013]

And it works!: Neightbors

Page 10: Chema Alonso - Hachetetepe dospuntos slaac slaac [Rooted CON 2013]

ICMPv6

• No ARP – No ARP Spoofing

– Tools anti-ARP Spoofing are useless

• Neighbor Discover uses ICPMv6 – NS: Neighbor Solicitation

– NA: Neighbor Advertisement

Page 11: Chema Alonso - Hachetetepe dospuntos slaac slaac [Rooted CON 2013]

NS/NA

Page 12: Chema Alonso - Hachetetepe dospuntos slaac slaac [Rooted CON 2013]

NA Spoofing

Page 13: Chema Alonso - Hachetetepe dospuntos slaac slaac [Rooted CON 2013]

NA Spoofing

Page 14: Chema Alonso - Hachetetepe dospuntos slaac slaac [Rooted CON 2013]

Demo 1: Mitm using NA Spoofing

Page 15: Chema Alonso - Hachetetepe dospuntos slaac slaac [Rooted CON 2013]

ICMPv6: SLAAC • Stateless Address Auto Configuration • Devices ask for routers • Routers public their IPv6 Address • Devices auto-configure IPv6 and Gateway

– RS: Router Solicitation – RA: Router Advertisement

Page 16: Chema Alonso - Hachetetepe dospuntos slaac slaac [Rooted CON 2013]

DNS Autodiscovery

Page 17: Chema Alonso - Hachetetepe dospuntos slaac slaac [Rooted CON 2013]

And it works!: Web Browser

Page 18: Chema Alonso - Hachetetepe dospuntos slaac slaac [Rooted CON 2013]

Windows Behavior

• IPv4 & IPv6 – DNSv4 queries A & AAAA

• IPv6 Only – DNSv6 queries A

• IPv6 & IPv4 Local Link – DNSv6 queries AAAA

Page 19: Chema Alonso - Hachetetepe dospuntos slaac slaac [Rooted CON 2013]

DNS64 & NAT64

Page 20: Chema Alonso - Hachetetepe dospuntos slaac slaac [Rooted CON 2013]

HTTP-s Connections

• SSL Strip – Remove “S” from HTTP-s links

• SSL Sniff – Use a Fake CA to create dynamicly Fake CA

• Evil FOCA does SSL Strip (so far)

Page 21: Chema Alonso - Hachetetepe dospuntos slaac slaac [Rooted CON 2013]

Demo 2: hachetetepé dos puntos SLAAC SLACC

Page 22: Chema Alonso - Hachetetepe dospuntos slaac slaac [Rooted CON 2013]

SLAAC D.O.S.

Page 23: Chema Alonso - Hachetetepe dospuntos slaac slaac [Rooted CON 2013]

Conclusions

• IPv6 is on your box – Configure it or kill it (if possible)

• IPv6 is on your network – IPv4 security controls are not enough

– Topera

Page 24: Chema Alonso - Hachetetepe dospuntos slaac slaac [Rooted CON 2013]

Conclusions

FEAR (the EVIL) FOCA!

Page 25: Chema Alonso - Hachetetepe dospuntos slaac slaac [Rooted CON 2013]

Thanks to • THC (The Hacking Choice)

– Included in Back Track – Parasite6 – Redir6 – Flood_router6 – …..

• Scappy

Page 26: Chema Alonso - Hachetetepe dospuntos slaac slaac [Rooted CON 2013]

…and some last words