Network World
Wednesday, January 7, 2009
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Community

Navigation

Flow in how Microsoft Spec'ed Teredo

0

All,

Actually there are two problems. The first is RFC 4380, written by C. Huitema, from Microsoft has design flaws as noted by the news item above.

The second problem is implementation. At BlackHat 2007, Jim Hoagland spoke on "Vista Network Attack Surface Analysis and Teredo Security Implications" (https://www.blackhat.com/presentations/bh-usa-07/Hoagland/Presentation/bh-usa-07-Hoagland.pdf).
In that speak, he discussed that testing performed demonstrated that implementation of Teredo in Vista was in fact not to RFC 4380 spec. In addition, he discovered several interesting security flaws in that implementation. The flaws included: The ability to more easily identify a specific endpoint, endpoints allows scanning and inbound traffic, Teredo bypassed the host firewall, and the random number generator is not always working.

Please note, there are no published document with the same security study performed on XP, 2000 or Miredo, the Linux/BDS implementation of Teredo.

Lastly, Teredo has is place and value. When used in a home/coffee shop/hotel environment, it works great. But, it should never be used in an enterprise.

Reply

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <i> <b> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <blockquote> <br /> <br> <p>
  • Lines and paragraphs break automatically.
  • You can use BBCode tags in the text.
  • Web page addresses and e-mail addresses turn into links automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

Advertisement: