[ipv6hackers] IPv6 smurf amplifiers (Fwd: New Version Notification for draft-gont-6man-ipv6-smurf-amplifier-02.txt)
Fernando Gont
fgont at si6networks.com
Thu Jan 24 11:41:38 CET 2013
Folks,
FYI, just published: "Security Implications of IPv6 Options of Type
10xxxxxx"
URL:
<http://www.ietf.org/internet-drafts/draft-gont-6man-ipv6-smurf-amplifier-02.txt>
Any comments will be appreciated.
Thanks!
Best regards,
Fernando
-------- Original Message --------
From: internet-drafts at ietf.org
To: fgont at si6networks.com
Subject: New Version Notification for
draft-gont-6man-ipv6-smurf-amplifier-02.txt
Date: Thu, 24 Jan 2013 02:24:21 -0800
A new version of I-D, draft-gont-6man-ipv6-smurf-amplifier-02.txt
has been successfully submitted by Fernando Gont and posted to the
IETF repository.
Filename: draft-gont-6man-ipv6-smurf-amplifier
Revision: 02
Title: Security Implications of IPv6 Options of Type 10xxxxxx
Creation date: 2013-01-24
WG ID: Individual Submission
Number of pages: 11
URL:
http://www.ietf.org/internet-drafts/draft-gont-6man-ipv6-smurf-amplifier-02.txt
Status:
http://datatracker.ietf.org/doc/draft-gont-6man-ipv6-smurf-amplifier
Htmlized:
http://tools.ietf.org/html/draft-gont-6man-ipv6-smurf-amplifier-02
Diff:
http://www.ietf.org/rfcdiff?url2=draft-gont-6man-ipv6-smurf-amplifier-02
Abstract:
When an IPv6 node processing an IPv6 packet does not support an IPv6
option whose two-highest-order bits of the Option Type are '10', it
is required to respond with an ICMPv6 Parameter Problem error
message, even if the Destination Address of the packet was a
multicast address. This feature provides an amplification vector,
opening the door to an IPv6 version of the 'Smurf' Denial-of-Service
(DoS) attack found in IPv4 networks. This document discusses the
security implications of the aforementioned options, and formally
updates RFC 2460 and RFC 4443 such that this attack vector is
eliminated. Additionally, it describes a number of operational
mitigations that could be deployed against this attack vector.
The IETF Secretariat
More information about the Ipv6hackers
mailing list