TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

IPv6 networks do apparently get probed

54 点作者 goranmoomin6 个月前

5 条评论

OptionOfT6 个月前
This reminds me of AWS&#x27;s solution for everybody selecting the first 2 availability zones which made the 3rd one to be under-used, and the first 2 over-used.<p>So they introduced AZ IDs <a href="https:&#x2F;&#x2F;docs.aws.amazon.com&#x2F;AWSEC2&#x2F;latest&#x2F;UserGuide&#x2F;using-regions-availability-zones.html#az-ids" rel="nofollow">https:&#x2F;&#x2F;docs.aws.amazon.com&#x2F;AWSEC2&#x2F;latest&#x2F;UserGuide&#x2F;using-re...</a> which create a per-account randomized mapping of region to actual availability zone.<p>And it&#x27;s logical that we do so. We clean up, we put things in corners, we sort things. So I suppose many people set static IPv6 addresses at the bottom of their &#x2F;64?
justsomehnguy6 个月前
ISP gives me &#x2F;24 and I configure my router at .1: I do nothing.<p>ISP gives me &#x2F;64 and I configure my router at ::1: <i>in WarCraft I orcs voice</i> We are under attack!<p>There is really no difference between setting <i>anything</i> on &quot;::3, ::5, ::7, ::a, ::b, ::c, ::f&quot; for IPv6 and for .1, .2, .3, .10, .11 on IPv4. Using these addresses do not lower you security in any way <i>compared to IPv4</i>.<p>The real difference is what with IPv4 you can just scan the whole &#x2F;24 in seconds, while with IPv6... it&#x27;s not seconds at least.
评论 #42165824 未加载
k_roy6 个月前
&gt; One of the things that I take away from this is that I may not want to put servers on these low IPv6 addresses in the future. Certainly one should have firewalls and so on, even on IPv6, but even then you may want to be a little less obvious and easily found<p>And my takeaway here is that &quot;Security through Obscurity&quot; isn&#x27;t actually that secure is it?<p>&gt; Certainly one should have firewalls and so on<p>Just because every device has a public IP doesn&#x27;t mean every device is available publicly. Your public little IPv6 network still goes through a router and that device can control the flow of traffic, through routing and firewalling.<p>This whole read really just feels like someone discovering IPv6 for the first time and fundamentally not understanding basic networking.
评论 #42162155 未加载
评论 #42162099 未加载
评论 #42180397 未加载
评论 #42162385 未加载
antisocialist6 个月前
Not if you disable your IPv6 stack.<p>Or you can be smart and &quot;easily&quot; address such probing attacks in your FW rules... <a href="https:&#x2F;&#x2F;nvd.nist.gov&#x2F;vuln&#x2F;detail&#x2F;CVE-2024-50252" rel="nofollow">https:&#x2F;&#x2F;nvd.nist.gov&#x2F;vuln&#x2F;detail&#x2F;CVE-2024-50252</a>
评论 #42164047 未加载
评论 #42163842 未加载
echoangle6 个月前
Here’s an RFC on the topic: <a href="https:&#x2F;&#x2F;datatracker.ietf.org&#x2F;doc&#x2F;html&#x2F;rfc7707" rel="nofollow">https:&#x2F;&#x2F;datatracker.ietf.org&#x2F;doc&#x2F;html&#x2F;rfc7707</a>