Get to grips with IPv6 security issues, warns expert

Problems arriving sooner than you think.

Sysadmins need to start looking at the security implicatiosn of IPv6, a security consultant has warned.

For many IT managers, the next version of the Internet Protocol seems like a far-off concern. But the technology will make its way into corporate IT systems sooner than many people realise, forcing IT departments to confront potential security vulnerabilities, Van Hauser, a security consultant and the founder of hacking group The Hacker's Choice, has warned.

Companies need to prepare themselves for IPv6, even if they don't have plans to upgrade their networks, said Hauser as he discussed security vulnerabilities during a presentation at the Hack In The Box Security Conference (HITB) in Kuala Lumpur, Malaysia.

"Most people think there's no IPv6 now, so where's the problem?" Hauser said. "The thing is if you install any Unix operating system now it comes with IPv6 enabled." Microsoft's Vista operating system will also have support for IPv6 enabled.

And that means sysadmins need to be prepared to address security issues in the new protocol. "It has the same vulnerabilites as IPv4. When you thought with IPv6 everything will change in regards to security this is not really the case," Hauser said.

Among the vulnerabilities that IPv6 and IPv4 share is the ability of a hacker to launch a man-in-the-middle attack, Hauser said. In this type of attack, a hacker is able to monitor or insert packets being sent back and forth between two parties, without either one realising that the network link between them has been compromised by a third party.

To secure against vulnerabilities in IPv6, companies must use IPSec on their networks, Hauser said. "If you use IPSec, most of the problems go away," he said. However, even then networks will not be completely secure. "It's not that easy. If you do encryption and authentication, it doesn't mean that security is okay," Hauser said. "It just narrows down the number of people who can do something."


Comment

What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.

Characters remaining: 500

Related Security news

Black hole discovery could boost quantum computers

String theory of gravity connected to entanglement

Onapsis to launch ERP vulnerability testing suite

The software searches for vulnerabilities, looks for compliance problems and creates reports

Women are better at protecting corporate secrets

Defcon social engineering contest finds most people give up secrets to strangers

Facebook introduces new security measures to kick out spammers

Users will be able to use IP info to confirm if their account has been hacked in to and reset passwords



Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

IT Manager's guide to buying an anti-spam solution

With these ten critical questions as your guide, you can cut through the marketing hype and zero in on the key features and benefits that should guide your decision.

Download Whitepaper

Unleashing cloud performance

While cloud services aim to eliminate cost and complexity from the world of enterprise IT, the unintended consequences of these services may do exactly the opposite if not carefully planned for.

Download Whitepaper

Online PC backup

This paper looks at the need for laptop and desktop data protection and, based upon recent IDC research, the key requirements firms should consider in evaluating enterprise-level online PC backup solutions.

Download Whitepaper

Protecting your business, customers, and the bottom line

Download this whitepaper to find out more about how you can protect your business from malware.

Download Whitepaper

Techworld UK - Technology - Business

Oracle Video

Enabling agile and intelligent businesses

 Changing markets, competitive pressures and evolving customer needs are placing increasing pressure on IT to deliver greater flexibility and speed. Explore truly flexible SOA foundations with this Oracle video.

Watch
AMD LGF

AMD Opteron™ Resource Centre

Set the foundations for higher speed processing, low energy consumption whilst delivering flexibility and value to your organisation.

Learn More

Win an iPad

How do you view and share technology related content and information? Tell us in our 2010 Media Usage Survey and you could win an iPad.

Complete the survey here

Site Map

IDG Network

* *