Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPv6, NTP and SHODAN

    Scheduled Pinned Locked Moved Off-Topic & Non-Support Discussion
    7 Posts 3 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • KOMK
      KOM
      last edited by

      Interesting.

      http://arstechnica.com/security/2016/02/using-ipv6-with-linux-youve-likely-been-visited-by-shodan-and-other-scanners/

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        If you have a public IP address on the Internet, you've likely been visited by dozens, hundreds, or thousands of scanners… snooze. :-)

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • DerelictD
          Derelict LAYER 8 Netgate
          last edited by

          Generally outbound traffic like web browsing uses a random, temporary address, too.

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • KOMK
            KOM
            last edited by

            But the gist of what they were saying was that the assigned IPv6 space is so large, nobody could run a scan and hit everything in their lifetime.  Not even close, so you had a slight measure of protection from that.  The SHODAN NTP servers allowed them to get addresses that were actually in use.

            1 Reply Last reply Reply Quote 0
            • jimpJ
              jimp Rebel Alliance Developer Netgate
              last edited by

              Eh, there are some interesting topics on scanning IPv6 around. Using other data like web logs, mail logs, etc is one way. Some of those logs make their way into google which leads to more exposure, etc. Relying on security through obscurity (or hiding among billions of billions of addresses) is a poor security model anyhow, I wouldn't consider that any measure of protection.

              Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • KOMK
                KOM
                last edited by

                While I agree 100% in principle, assuming all other protection measures are in place I would rather be a grain of sand on the beach than a stone in the aquarium.

                1 Reply Last reply Reply Quote 0
                • jimpJ
                  jimp Rebel Alliance Developer Netgate
                  last edited by

                  I suppose, but I'd rather head off anyone eager to tout that as a security measure in this day and age, too many people already thought NAT was a security measure in IPv4. Sure it might have helped or been part of a larger strategy, but it's not something that should be relied upon.

                  If devices use privacy addressing or hop addresses the collected data will only be useful during a small window anyhow.

                  Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                  Need help fast? Netgate Global Support!

                  Do not Chat/PM for help!

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.