
ã©ãããŠä»ã§ã¯IPv6ãèŠããŠããã®ã§ããããïŒ å®éãIPv4ã¢ãã¬ã¹ã®æåŸã®ãããã¯ãå°åã®ã¬ãžã¹ãã©ã«é
ããããšããäºå®ã«ãããããããã€ã³ã¿ãŒãããã¯å€æŽãªãã§æ©èœããŸãã å®éãIPv6ã¯1995幎ã«åããŠç»å Žãããã®ã¿ã€ãã«ã¯1998幎ã«RFCã§å®å
šã«èª¬æãããŸããã ãªããããéèŠãªã®ã§ããïŒ ã¯ããIPv4ãšåãä¿¡é Œã¹ããŒã ã§ãè
åšãèæ
®ããã«éçºãããããã§ãã ãŸããéçºããã»ã¹ã«ã¯ãããé«éãªãããã³ã«ãäœæããå€æ°ã®ã¢ãã¬ã¹ã䜿çšããã¿ã¹ã¯ããããŸããã
æé·çã«ã€ããŠç°¡åã«
IPã¢ãã¬ã¹ããã³èªåŸã·ã¹ãã ã®å°åã¬ãžã¹ãã©ãæäŸããã°ã©ããèŠããšã2014幎9æ1æ¥ã®æç¹ã§ãç»é²æžã¿IPv6èªåŸã·ã¹ãã ã®æ°ã¯ãã§ã«20ïŒ
ãè¶
ããŠããããšãããããŸãã äžèŠãããã¯æ·±å»ãªæ°åã§ãã ããããäžçã®IPv6ãã©ãã£ãã¯ã®å®éã®éã®ã¿ãèæ
®ãããšãæåéã3幎åã¯ããã0.5ïŒ
ã§ããããçŸåšã§ã¯å
šäžçã®ã€ã³ã¿ãŒããããã©ãã£ãã¯ã®çŽ6ïŒ
ã§ãã

å³ 1. IPv6ãã©ãã£ãã¯ã®å®éã®é
æãä¿å®çãªèŠç©ããã«ãããšã2015幎æ«ãŸã§ã«ãIPv6ãã©ãã£ãã¯ã®ã·ã§ã¢ã¯å°ãªããšã10ïŒ
ã«éããã§ãããã ãããŠæé·ã¯ç¶ãã§ãããã ããã«ãå°åã®ã¬ãžã¹ãã©åãã®ç¹å¥ãªãããã³ã«ãæè¿çºå¹ããŸããã IPv4ã¢ãã¬ã¹ã®æ°ãããããã¯ã¯ãäŒç€ŸãIPv6ãæ¢ã«å®è£
ããŠããããšã蚌æããå Žåã«ã®ã¿çºè¡ãããŸãã ãããã£ãŠã誰ããçœãIPv4ã¢ãã¬ã¹ã®ãµãããããå¿
èŠãšããå ŽåãIPv6ãå®è£
ããå¿
èŠããããŸãã ãã®äºå®ã¯ãIPv6ã·ã¹ãã ã®ãããªãæé·ãšãã©ãã£ãã¯ã®å¢å ã«ã圹ç«ã¡ãŸãã äžè¬ãŠãŒã¶ãŒã«ã€ããŠã¯ãå
¬æ£ãªIPv6ã¢ãã¬ã¹ããšã³ããŠãŒã¶ãŒã«æäŸãããããã€ããŒããã§ã«äžçäžã«çŸãå§ããŠããŸãã ãããã£ãŠãIPv6ã¯ãŸããŸãäžè¬çã«ãªãããããç¡èŠããããšã¯ã§ããŸããã
IPv6ã®æ°æ©èœ
æåã«ç®ãåŒãã®ã¯ã¢ãã¬ã¹ã§ãã ãããã¯é·ããªãã16é²æ°ã§èšè¿°ãããèŠãã«ããã ãã ããIPv6ããã°ãã䜿çšããåŸãç¹ã«ç瞮圢åŒã®è¡šèšã䜿çšããŠããå Žåãã¢ãã¬ã¹ã¯äžè¬ã«èšæ¶ã«æ®ãããšãããããŸãã IPv4ã¯32ãããã¢ãã¬ã¹ã䜿çšãã4,294,967,296ïŒ2 ^ 32ïŒã®ã¢ãã¬ã¹ç©ºéãå¯èœãªäžæã®ã¢ãã¬ã¹ã«å¶éããããšãæãåºãããŠãã ããã IPv6ã®å Žåã128ãããããã§ã«ã¢ãã¬ã¹ã«å²ãåœãŠãããŠããŸãã ãããã£ãŠã2 ^ 128åã®ã¢ãã¬ã¹ã䜿çšã§ããŸãã ãããã¯ãå°çã®è¡šé¢äžã®åååã«å¯ŸããŠçŽ100åã®ã¢ãã¬ã¹ã§ãã ã€ãŸããã¢ãã¬ã¹ã¯ååã«é·ãéååã§ããå¿
èŠããããŸãã
ã¢ãã¬ã¹ã¯ã16é²å€ã®8ã€ã®ã°ã«ãŒããšããŠæžã蟌ãŸããŸãã ããšãã°ãIPv6ã¢ãã¬ã¹ã¯2001ïŒDB8ïŒ11 :: 1ã®ããã«ãªããŸãã 1ã€ã®ã€ã³ã¿ãŒãã§ã€ã¹ã«è€æ°ã®IPv6ã¢ãã¬ã¹ãååšããå¯èœæ§ãããããšã«æ³šæããããšãéèŠã§ããããã¯æšæºçãªç¶æ³ã§ãã ããšãã°ãã€ã³ã¿ãŒãã§ã€ã¹ã«ãã©ã€ããŒãã¢ãã¬ã¹ããã¯ã€ãã¢ãã¬ã¹ããããå¥ã®ã¢ãã¬ã¹ãDHCPv6çµç±ã§å°çããå ŽåããããŸãã ãããŠããã¹ãŠãé©åã«æ©èœããåã¿ã¹ã¯ã«å¯ŸããŠç¬èªã®ã¢ãã¬ã¹ã䜿çšãããŸãã äžçã«åºãããå¿
èŠãããå Žåã¯ãçœãäœæã䜿çšãããŸãã 次ã®ãµãŒããŒã«å¿
èŠã§ããïŒ ãã©ã€ããŒãã¢ãã¬ã¹ãééããŸãã ããã¯ãã¹ãŠãå®å
ãã£ãŒã«ãã®éåžžã®åæã«ãã£ãŠè§£æ±ºãããŸãã
ãã¹ãŠã®IPv6ã¢ãã¬ã¹ã¯ããªã³ã¯ããŒã«ã«ãšã°ããŒãã«ãŠããã£ã¹ãã®2ã€ã®ã°ã«ãŒãã«åããããŸãã ååãããLink localã¯1ã€ã®ãªã³ã¯å
ã§ã®ã¿äœ¿çšãããã¢ãã¬ã¹ã§ããããšã¯æããã§ãã ãã®åŸããã®ãããªã¢ãã¬ã¹ã¯ãèªåã¢ãã¬ã¹èšå®ãè¿é£æ¢çŽ¢ãã«ãŒã¿ãŒããªãå Žåãªã©ãå€ãã®ã¡ã«ããºã ã®åäœã«äœ¿çšãããŸãã äžçã«å
¥ãã«ã¯ããã®ãããªã¢ãã¬ã¹ã¯èš±å¯ãããŠããŸããã
ãªã³ã¯ããŒã«ã«ã¢ãã¬ã¹ã¯ããã¹ãããªã³ã©ã€ã³ã«ãªããšããã«èªåçã«å²ãåœãŠãããŸãããã®ãããªã¢ãã¬ã¹ã¯ãWindowsã®
APIPAã¡ã«ããºã ã«äŒŒãŠããŸãã ãã®ãããªã¢ãã¬ã¹ã¯åžžã«FE80ã§å§ãŸããŸãããæåŸã®64ãããã¯ãäžå€®ã«FFFEãæ¿å
¥ããããããŒã¢ãã¬ã¹ã«1ããããå転ãããã®ã§ãã ãã®ãããªã¢ãã¬ã¹ãçæããã¡ã«ããºã ã¯ãEUI-64ãšãåŒã°ããŸãã ãã®çµæãã±ã·ã®ã¢ãã¬ã¹ã¯éåžžãã¹ãŠã®ãã¹ãã§ç°ãªããããã¢ãã¬ã¹ã¯äžæã«ãªããŸãã ãã ããäžéšã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã¯ãEUI-64ã¡ã«ããºã ã®ä»£ããã«ã©ã³ãã ãªèå¥åã䜿çšããŸãã
ä»ã«äœãæ°ããã§ãã
ãã¡ãããå€æŽã®ã¢ãã¬ã¹ã ããããã§çµããããã§ã¯ãããŸããã èŠåºãã倧å¹
ã«ç°¡çŽ åãããŸããïŒå³2ãåç
§ïŒã

å³ 2. IPv6ããããŒãšIPv4ããããŒã®æ¯èŒ
ããã§ããã€ã³ãAãããã€ã³ãBã«ãã±ãããã«ãŒãã£ã³ã°ããããã«å¿
èŠã§ã¯ãªããã¹ãŠã®ãã®ããªãã·ã§ã³ã«ãªããŸããã ãªãã·ã§ã³ã®å Žåã¯ãIPv6ããããŒãšTCP / UDPããŒã¿ã®éã«ããæ¡åŒµããããŒã«ç§»åããŸãã ãã®åãæ¡åŒµããããŒããã©ã°ã¡ã³ããŒã·ã§ã³ãIPsecããœãŒã¹ã«ãŒãã£ã³ã°ãããã³ä»ã®å€ãã®æ©èœããã§ã«ååšããŠããŸãã
ãã§ãã¯ãµã ãåèšç®ããå¿
èŠããªããªã£ããããã«ãŒã¿ãŒã¯å€§å¹
ã«ç°¡çŽ åããããã®çµæãIPv6ã¯IPv4ãããé«éã«åŠçãããŸããã ãã§ãã¯ãµã ã¯å®å
šã«åé€ãããŸããã 第äžã«ãL2ã¬ãã«ã®ãã¬ãŒã ã«ã¯CRCãããã第äºã«ãäžã«ãããããã³ã«ïŒTCPïŒãé
ä¿¡ã®æŽåæ§ãä¿èšŒããŸãã ãã®çµæãããããŒããäœåãªãã£ãŒã«ããã¹ããŒãããããç°¡åã«ãããéããããä¿¡é Œæ§ã®é«ããã®ã«ãªããŸããã
èªåæ§æããã³ãµãŒãã¹ãããã³ã«
IPv6ã¢ãã¬ã¹ã®å²ãåœãŠã«ã¯ãäž»ã«2ã€ã®ãªãã·ã§ã³ããããŸããã¹ããŒãã¬ã¹èªåæ§æ-ããã¯ãã«ãŒã¿ãŒããããã¯ãŒã¯ã¢ãã¬ã¹ãããã©ã«ãã²ãŒããŠã§ã€ãããã³ãã®ä»ã®å¿
èŠãªæ
å ±ãã¯ã©ã€ã¢ã³ãã«éä¿¡ãããšãã§ãã ãããã£ãŠã以åã®DHCPãæ
å ±ãé
åžããããã®å¯äžã®ãªãã·ã§ã³ã§ãã£ãå ŽåãIPv6ã§ã¯è¿œå ã®ãªãã·ã§ã³ã«ãªããŸããã
ICMP 6thããŒãžã§ã³ãèŠéãããããå€ãã®æ©èœãè¿œå ãããŸããã ããšãã°ãã«ãŒã¿ãŒæ€åºã¡ã«ããºã âã¯ã©ã€ã¢ã³ãã¯ãã«ãŒã¿ãŒãäŒããå
容ïŒã¹ããŒãã¬ã¹èªåæ§æããã»ã¹ã®äžéšãšããŠæ¥ãICMPv6ã¡ãã»ãŒãžã¿ã€ã134ã«ãŒã¿ãŒã¢ããã¿ã€ãºã¡ã³ãïŒããªãã¹ã³ã§ããŸããã«ãŒã¿ãŒèŠè«ïŒã
è¿é£æ¢çŽ¢ã¡ã«ããºã ãè¿œå ããŸãã-ããã¯äžçš®ã®ARP眮æã§ããããã€ããŒãã«ãŒã¿ãŒã®ãããŒã¢ãã¬ã¹ãèŠã€ããããã»ã°ã¡ã³ãå
ã®éè€ã¢ãã¬ã¹ãæ€åºããã®ã«ã圹ç«ã¡ãŸãïŒéè€ã¢ãã¬ã¹æ€åºDaDïŒããã«ããã£ã¹ãã§ã®ã¿åäœããŸãã IPv6ã«ã¯çŽç²ãªãããŒããã£ã¹ãã¯ãããŸããããæããªãããŒã¹ã€ããããã«ããã£ã¹ãå
šäœããããŒããã£ã¹ãããããšãå¿ããŠã¯ãªããŸããããã®çµæãæ°ããã¡ã«ããºã ã®äžéšããŒãã«ãªããŸãã
IPv6 PentesterããŒã«ããã
è匱æ§ãšæ»æã«ç§»ãåã«ãã©ã®ããŒã«ãåœé²ç·çã®å
µåšåº«ã«ããããèãããšããã§ãããã æè¿ãŸã§ãIPv6ããã³ICMPv6ãããã³ã«ãæ»æããããã®ãŠãŒãã£ãªãã£ã¯1ã»ãããããããŸããã§ããã ããã¯ãæªåé«ãMark van Hauserã®THC-IPV6ã§ãããTHC-hydra bruteforceã®ãŸãã«èè
ã§ãããä»ã®äžå¯æ¬ ãªããŒã«ã®ãã¹ãã§ãã 2005幎ã«ãã®ãããã¯ã«çå£ã«èå³ãæã¡ãIPv6ã®ãããã³ã«ãç解ããã®ã¯åœŒã§ããã ãããŠæè¿ãŸã§ãå
é§è
ã§ããç¶ããŸããã
ããããæšå¹Žãç¶æ³ã¯å€ããå§ããŸããã ããå€ãã®ç 究è
ãIPv6ã«æ³šç®ããããã«ãªããããã«å¿ããŠãæ°ãããŠãŒãã£ãªãã£ãšæ°ããã¹ãã£ããŒãç»å Žãå§ããŠããŸãã ãããä»ã®ãšãããTHC-IPV6ã¯äŸç¶ãšããŠPentesterãŠãŒãã£ãªãã£ã®æé«ã®ã»ããã§ãã ãããã«ã¯ãã§ã«ãã¹ãã£ã³ãããããããã©ããã£ã³ã°ããã¡ãžã³ã°ãŸã§ãããŸããŸãªã«ããŽãªã«åé¡ããã60以äžã®ããŒã«ãå«ãŸããŠããŸãã ãã ããscapyããŒã«ã¯ãRFCã§ãã®ãããªããªãšãŒã·ã§ã³ãæäŸãããŠããªããŠããããããŒä»ãã®ããã±ãŒãžãæåã§äœæã§ãããŠãŒãã£ãªãã£ã§ãã
IPv6ãããã¯ãŒã¯ã®ã€ã³ããªãžã§ã³ã¹
ã¿ãŒã²ãããæ»æããåã«ãäœããã®æ¹æ³ã§ãããæ€åºããå¿
èŠããããŸãããã®ãããéåžžãæšæºã®ãã³ãã¹ãã¯ã©ã€ããã¹ãã®æ€çŽ¢ããå§ãŸããŸãã ãã ããåé¡ããããŸããç¯å²å
šäœãã¹ãã£ã³ããããšã¯ã§ããŸããã 1ç§éã«100äžãã±ãããéä¿¡ããå Žåã§ãã1ã€ã®ãµããããã®ã¿ãã¹ãã£ã³ããã«ã¯æ°å¹ŽããããŸãã ãã®çç±ã¯ã/ 64ãµããããïŒãŸãã¯ãã¬ãã£ãã¯ã¹ãšãåŒã°ããŸãïŒã®ã¿ããä»æ¥ã®ã€ã³ã¿ãŒãããå
šäœããã倧ããããã以äžã§ããããã§ãã ãããã£ãŠãIPv6ã§æãæ·±å»ãªåé¡ã¯ã¿ãŒã²ããã®çºèŠã§ãã
幞ããªããšã«ã解決çããããŸãã æåã«ãã¿ãŒã²ããïŒãã³ãã¹ããªããžã§ã¯ãïŒã«å±ããASïŒèªåŸã·ã¹ãã ïŒãèŠã€ããå¿
èŠããããŸãã ASã§ææè
ãæ€çŽ¢ã§ãããµãŒãã¹ã§ååã§ããããã¯ãå°åã®ã¬ãžã¹ãã©ã®ãµã€ãã§çŽæ¥è¡ãããšãã§ããŸãïŒãšãŒãããã®ã¬ãžã¹ãã©ã¯RIPE NCCã§ãïŒã 次ã«ãç¹å®ã®äŒç€Ÿã«å±ããASçªå·ããããã°ãããã«å²ãåœãŠãããIPv6ãµãããããæ¢ã«æ€çŽ¢ã§ããŸãã
æã䟿å©ãªãã®ãããªæ€çŽ¢ãµãŒãã¹ã¯ãHurricane ElectricïŒbgp.he.netïŒã«ãã£ãŠæäŸãããŠããŸãã ãã®çµæãããã€ãã®å·šå€§ãªãµãããããèŠã€ããããšãã§ããŸããããã§ã«èŠãããã«ãã©ã€ããã¹ããã¹ãã£ã³ããã®ã¯éçŸå®çã§ãã ãã®ãããé »ç¹ã«äœ¿çšããã¢ãã¬ã¹ã®ãªã¹ããäœæãããããã®ã¢ãã¬ã¹ã§æ¢ã«ãã€ã³ãããšã«ã¹ãã£ã³ããå¿
èŠããããŸãã
ãã®ãããªèŸæžãã³ã³ãã€ã«ããã«ã¯ã©ãããã°ããã§ããïŒ IPv6ãæ¢ã«å®è£
ããŠããäŒæ¥ã®ã¯ã©ã€ã¢ã³ããžã®ã¢ãã¬ã¹ã®å²ãåœãŠæ¹æ³ãåæãããšãèªåæ§æãæåã¢ãã¬ã¹å²ãåœãŠãDHCPv6ã®3ã€ã®äž»èŠãªã°ã«ãŒããåºå¥ã§ããŸãã
èªåæ§æã¯3ã€ã®æ¹æ³ã§è¡ãããšãã§ããŸãïŒãã©ã€ãã·ãŒãªãã·ã§ã³ã䜿çšããMACã¢ãã¬ã¹ã«åºã¥ããŠïŒã€ãŸããã©ã³ãã ã«ãããšãã°é±ã«1åå€æŽïŒãåºå®ã©ã³ãã ïŒå®å
šã«ã©ã³ãã ïŒã ãã®ç¶æ³ã§ã¯ããããŒã«åºã¥ããã¢ãã¬ã¹ã®ã¿ãã¹ãã£ã³ã§ããŸãã ãã®çµæãIPv4ã¯ã©ã¹Aã«å¹æµãããµã€ãºã®ãµãããããåºãŠããå¯èœæ§ããããŸãããã®ãããªãããã¯ãŒã¯ã§äœæ¥ããããã»ã¹ã¯ããã»ã©é«éã§ã¯ãããŸããããããã§ãããªãçŸå®çã§ãã ããšãã°ãã¿ãŒã²ããäŒæ¥ãç¹å®ã®ãã³ããŒã®ã©ãããããã倧éã«äœ¿çšããŠããããšãããã£ãŠããå Žåãäœæã®åœ¢ææ¹æ³ã«é¢ããç¥èã«åºã¥ããŠã¹ãã£ã³ãæ§ç¯ã§ããŸãã
ã¢ãã¬ã¹ãæåã§èšå®ããå Žåã¯ãã©ã³ãã ã«ããŸãã¯äœããã®ãã¿ãŒã³ã«åŸã£ãŠã¢ãã¬ã¹ãå²ãåœãŠãããšãã§ããŸãã 2çªç®ã¯ããã¡ããã人çã§ã¯ããã«äžè¬çã§ãã ãã¿ãŒã³ã¯ãïŒ:: 1 ã: 2 ã: :: 3ãŸãã¯:: 1001 ã: 1002ã:: 1003ã§ãã ãŸãããµãŒããŒã«ãã£ãŠã¯ããµãŒãã¹ããŒããã¢ãã¬ã¹ãšããŠäœ¿çšãããå ŽåããããŸããããšãã°ãWebãµãŒããŒã¯ã¢ãã¬ã¹:: 2ïŒ80ãæã€ããšãã§ããŸãã
DHCPv6ã䜿çšããå Žåããã®å Žåãã¢ãã¬ã¹ã¯éåžžãããŒã«ããé çªã«é
åžãããŸãïŒéåžžã®DHCPv4ãµãŒããŒã§ããŸã£ããåãåäœã確èªã§ããŸãïŒã DHCPv6ã§ã¯ãå€ãã®å Žåã:: 1000-2000ãŸãã¯:: 100-200ã®ãããªããŒã«ãèŠã€ããããšãã§ããŸãã ãã®ãããæçµçã«alive6ãŠãŒãã£ãªãã£ïŒTHC-IPV6ãã³ãã«ã«å«ãŸããŠãããçŸåšæ€èšãããŠãããã¹ãŠã®ããŒã«ãšåæ§ã«ãKali Linuxã«ããã©ã«ãã§å«ãŸããŠããŸãïŒãå®è¡ããŸãã
ãã®ãªãã³ã°ãã·ã³ã®æ€åºã«ããããã¹ãã¢ãã¬ã¹ãæ
åœããéšåã®ã¿ãå€æŽãããŸãã ãã®ã¢ãããŒãã䜿çšãããšã以åã«æ€åºããããµããããã§ã©ã€ããã¹ããéåžžã«å¹æçãã€åŠ¥åœãªæéå
ã«èŠã€ããããšãã§ããŸãã
ããããããã ãã§ã¯ãããŸãã-ãã¡ãããDNSã䜿çšã§ããŸãã IPv6ã®åºçŸã«ãããèŸæžã«ãããšDNSãŸãŒã³è»¢éãšDNSãã«ãŒããã©ãŒã¹ã¯ãªããªããŸããã§ããã ããããã¹ãŠã®ææ³ãäžç·ã«é©çšãããšãç¹å®ã®IPv6ãµããããã«å«ãŸãããã¹ãŠã®ãã¹ãã®æ倧80ïŒ
ãæ€åºã§ããŸããããã¯éåžžã«åªããŠããŸãã 1å°ã®ãã¹ãã®ã¿ã䟵害ãããå Žåããã«ããã£ã¹ãã䜿çšããŠãã¹ãŠã®é£æ¥ãã¹ããèŠã€ããããšã¯é£ãããããŸããã åããŠãŒãã£ãªãã£alive6ãå®è¡ããã«ã¯ã-lã¹ã€ããã䜿çšããã ãã§ååã§ãã
THC-IPV6ã®ææ°æ©èœãç¹ã«alive6ãŠãŒãã£ãªãã£ãããåæã®ãã¿ãŒã³ãšããŠIPv4ãµããããå
šäœãæž¡ãããšã«ãããã©ã€ããã¹ããæ€çŽ¢ããæ©èœã«æ³šç®ã§ããŸãã
åŸæ¥ã®ã¹ãã£ã³ã䜿çšããå Žåãå®éã«ã¯äœãå€æŽãããŠããŸããã åãNmapãåãããŒãã¹ãã£ã³ãªãã·ã§ã³ãå¯äžã®éãã¯ãäžåºŠã«1ã€ã®ãã¹ãããã¹ãã£ã³ã§ããªãããšã§ãããããã¯æãããªè§£æ±ºçã§ãã
ãããããããŒãã¹ãã£ã³ã®å¯äžã®è¿œå ææ³ã¯ãæåã«IPv4ãã¹ãã£ã³ããŠããããããã®ãã¹ãã§IPv6æ
å ±ãååŸããããšã§ãã ã€ãŸããæ»æ察象é åã®ããçš®ã®æ¡å€§ã§ãã ãã®ããã«ãipv6_neighbor metasplitè£å©ã¢ãžã¥ãŒã«ãšåå¥ã®ipv6_surface_analyzerã¹ã¯ãªããã®äž¡æ¹ã䜿çšã§ããŸãã ãããã¯åæ§ã®ååã«åŸã£ãŠåäœããŸã-å
¥åã§IPv4ãµãããããååŸãããããã¹ãã£ã³ããã©ã€ããã¹ããèŠã€ããããŒãã®éæŸæ§ããã§ãã¯ãã次ã«MACã¢ãã¬ã¹ã決å®ããããããIPv6ã¢ãã¬ã¹ãèšç®ããããã§äœæ¥ãè©Šã¿ãŸãã æã«ã¯ãããæ¬åœã«åœ¹ç«ã€ããšããããŸãããå Žåã«ãã£ãŠã¯ïŒãã©ã€ãã·ãŒãªãã·ã§ã³ïŒIPv6ã¢ãã¬ã¹ãèŠã€ãã£ãŠãèŠã€ãããªãããšããããŸãã
æ
å ±
IPv4ãšARPã䜿çšããå ŽåãARPãã£ãã·ã¥ãæã
èŠãã®ã¯éåžžã«äŸ¿å©ã§ããã LinuxãWindowsãã©ãããã©ãŒã ã§ã¯ãããã¯arp -aã³ãã³ãã䜿çšããŠå®è¡ã§ããŸãã
çŸåšãIPv6ã®å ŽåãLinuxã§ã¯ip -6 neighbor showã³ãã³ãã䜿çšããŠè¿é£ã衚瀺ããŸããWindowsç°å¢ã§ã¯ãnetsh interface ipv6 show neighborsã³ãã³ãã§ãããå®è¡ã§ããŸãã
å¢çè
åšIPv6
å€éšå¢çãèŠããšããã§ã«IPv6ã®å®è£
ãéå§ããŠããå€ãã®äŒæ¥ãæ¥ãã§ç®¡çããŒãïŒSSHãRDPãTelnetãVNCãªã©ïŒãéããŠããããšãããããŸãã ãããŠãã»ãšãã©ãã¹ãŠã®äººãäœããã®æ¹æ³ã§IPv4ããã£ã«ã¿ãªã³ã°ããããšããŠããå ŽåãIPv6ãå¿ããããIPv4ã®å Žåãšåãæ¹æ³ã§ä¿è·ããå¿
èŠãããããšãç¥ããªãã ãŸãã䜿çšãããŠããIPv4 telnetãéšåçã«ç解ã§ããå ŽåïŒããšãã°ãã¡ã¢ãªã®å¶éãCPUãSSHãå®å
šã«äœ¿çšã§ããªãå ŽåïŒãçŸåšIPv6ããµããŒããããã¹ãŠã®ããã€ã¹ã¯ãSSHããµããŒãããããšãä¿èšŒãããŸãã ISPãã«ãŒã¿ãŒäžã§IPv6管çããŒããäžçã«å
¬éããå ŽåããããŸãã ãããã€ããŒã§ããIPv6æ»æã«å¯ŸããŠããè匱ã§ããããšãå€æããŠããŸãã ããã¯ããŸããŸãªçç±ã§çºçããŸãã 第äžã«ãå€ãã®åªããIPv6ãã¡ã€ã¢ãŠã©ãŒã«ããããŸããã第äºã«ããããã賌å
¥ããŠæ§æããå¿
èŠããããŸãã ããŠãäž»ãªçç±ã¯ãå€ãã®äººãIPv6ã®è
åšãçãããšãããªãããšã§ãã ãŸããIPv6ããã«ãŒããã«ãŠã§ã¢ãIPv6æ»æã¯ãããŸããããä¿è·ãã¹ããã®ã¯ãªãããã§ãã
LANå
ã§åŸ
æ©ããè
åš
IPv4ãæãåºããšãããŒã«ã«ãããã¯ãŒã¯ã§ãŸã æå¹ãª3ã€ã®æ»æããããŸã-ARPã¹ããŒãã£ã³ã°ãDHCPã¹ããŒãã£ã³ã°ãããã³ICMPãªãã€ã¬ã¯ãïŒãã®ã¯ã©ã¹ã®æ»æã«ã€ããŠã¯ãPHDaysã§ã®è¬æŒã§è©³ãã説æããŸããããŠã§ãäžã®å¯Ÿå¿ããåç»ïŒã
IPv6ã®å Žåãæ»æè
ã被害è
ãšåãããŒã«ã«ã»ã°ã¡ã³ãã«ãããšããå¥åŠãªããšã«ãç¶æ³ã¯ã»ãŒåããŸãŸã§ãã ARPã®ä»£ããã«NDPãç»å ŽããDHCPãèªåæ§æã«çœ®ãæããããICMPãICMPv6ã«ã¢ããã°ã¬ãŒããããŸããã éèŠãªããšã¯ãæ»æã®æŠå¿µãã»ãšãã©å€ãã£ãŠããªãããšã§ãã ããããããã«å ããŠãDADã®ãããªæ°ããã¡ã«ããºã ãè¿œå ãããããã«å¿ããŠãæ°ãããã¯ã¿ãŒãšæ°ããæ»æãããã«ç»å ŽããŸããã
è¿é£æ¢çŽ¢ãããã³ã«ïŒNDPïŒã¯ãIPv6ãã¹ããçžäºã«çºèŠããããïŒIPv4ã§äœ¿çšãããARPã®ä»£ããã«ïŒå¥ã®ãã¹ãã®ãªã³ã¯å±€ã¢ãã¬ã¹ã決å®ããããã«ãŒã¿ãŒãçºèŠãããã§ãããããã³ã«ã§ãã ãã®ã¡ã«ããºã ãæ©èœãããã«ããã£ã¹ãã䜿çšããŠæ©èœããã«ã¯ããªã³ã¯ããŒã«ã«ãŸãã¯ã°ããŒãã«IPv6ã¢ãã¬ã¹ãã€ã³ã¿ãŒãã§ã€ã¹ã«å²ãåœãŠããããã³ã«ããã¹ãããã«ããã£ã¹ãã°ã«ãŒãã«åå ããŸãã å®éã«ã¯ã2çš®é¡ã®ã¡ãã»ãŒãžã®ã¿ãè¿é£æ¢çŽ¢ããã»ã¹ã§äœ¿çšãããŸããæ
å ±ã®èŠæ±ããŸãã¯NSïŒè¿é£èŠè«ïŒãããã³æ
å ±ã®æäŸ-NAïŒè¿é£åºåïŒã§ãã
ãã®ã¢ãŒãã§ã®çžäºäœçšã¯å³ã«èŠãããšãã§ããŸãã 3ã

å³ 3.ã¹ã¿ããã£ã³ã°ND
ãã®çµæãæ»æè
ã¯parasite6ãŠãŒãã£ãªãã£ãå®è¡ããã ãã§æžã¿ãåäžã®ã»ã°ã¡ã³ãã§é£è¡ãããã¹ãŠã®NSã«å¿çããŸãïŒå³4ãåç
§ïŒã ãã®åã«ã転éãæå¹ã«ããããšãå¿ããªãã§ãã ããïŒecho 1> / proc / sys / net / ipv6 / conf / all / forwardingïŒãããããªããšãMITMæ»æã§ã¯ãªãDoSæ»æãçºçããŸãã

å³ 4. parasite6ãŠãŒãã£ãªãã£ã®æäœ
ãã®ãããªæ»æã®æ¬ ç¹ã¯ãæ»æè
ããã¹ãŠã®ãã¹ãã®NDãã£ãã·ã¥ããã€ãºãã³ã°ããããšããããšã§ããããã¯ã第äžã«ãã€ãºãå€ãã第äºã«å€§éã®ãã©ãã£ãã¯ã®å Žåã«å°é£ã§ãã ãããã£ãŠãããªãã¯éããããšãã§ãããã®æ»æãæåã§å®è¡ããããšãã§ããŸãã ãŸããå¿
èŠãªå€æ°ããã¹ãŠå
¥åããå¿
èŠããããŸãã
>>> ether=Ether(src="00:00:77:77:77:77", dst="00:0c:29:0e:af:c7") , - , â - . >>> ipv6=IPv6(src="fe80::20d:edff:fe00:1", dst="fe80::fdc7:6725:5b28:e293") , ( ), â IPv6- . >>> na=ICMPv6ND_NA(tgt="fe80::20d:edff: fe00:1", R=0, S=0, O=1)
3çªç®ã®å€æ°ã¯ãé©åã«ã¢ã»ã³ãã«ãããNAãã±ãããæå®ããå¿
èŠããããŸããICMPv6ND_NAã¯ICMPv6 Neighbor Discovery-Neighbor Advertisementãtgtã¯ã«ãŒã¿ãŒã®å®éã®ã¢ãã¬ã¹ã§ãæ»æè
ã®ã¢ãã¬ã¹ãšããŠã¢ããŠã³ã¹ãããŸãã ãã¹ãŠã®ãã©ã°ãæ£ããèšå®ããããšãéèŠã§ããR= 1ã¯éä¿¡è
ãã«ãŒã¿ãŒã§ããããšãæå³ããS = 1ã¯NSã¡ãã»ãŒãžãžã®å¿çãšããŠã¢ããŠã³ã¹ãéä¿¡ãããããšã瀺ããO = 1ã¯ãããããªãŒããŒã©ã€ããã©ã°ã§ãã
>>> lla=ICMPv6NDOptDstLLAddr (lladdr="00:00:77:77:77:77") â Link local ICMPv6NDOptDstLLAddr (ICMPv6 Neighbor Discovery Option â Destination Link-Layer). - . >>> packet=ether/ipv6/na/lla , . >>> sendp(packet,loop=1,inter=3)
å€loop = 1ã¯ã3ç§ããšã«ç¡éã«éä¿¡ããå¿
èŠãããããšãæå³ããŸãã
ãã®çµæããã°ãããããšã被害è
ã¯è¿é£ã®ãã£ãã·ã¥ãæŽæ°ããã«ãŒã¿ãŒå®ãŠã®ãã¹ãŠã®ãã©ãã£ãã¯ãæ»æè
ã®æã«çŽæ¥éä¿¡ããŸãã æ¬æ ŒçãªMITMãäœæããããã«ã¯ãscapyã®å¥ã®ã€ã³ã¹ã¿ã³ã¹ãå®è¡ããå¿
èŠããããŸããscapyã§ã¯ãã¢ãã¬ã¹ãéã«ããŠã«ãŒã¿ãŒããã€ãºãã³ã°ããŸãã ã芧ã®ãšãããè€éãªããšã¯äœããããŸããã
IPv6ã«ã¯ãARPã®æ代ã®ããã«ãç¡åNAã®æŠå¿µããªãããšã«ã泚ç®ãã䟡å€ããããŸãïŒç¡åARPã¯èŠæ±ãªãã§éä¿¡ãããARPå¿çã§ãïŒã ãã ããåæã«NDãã£ãã·ã¥ã¯é·ãåç¶ãããããã«æéåãã«ãªããŸãã ããã¯ãååšããªãMACã¢ãã¬ã¹ãžã®ãã±ããéä¿¡ãåé¿ããããã«èšèšãããŸããã ãããã£ãŠãIPv6ãããã¯ãŒã¯ã§ã¯ãNS-NAã¡ãã»ãŒãžã³ã°ãéåžžã«é »ç¹ã«çºçããæ»æè
ã®æã«æž¡ããŸãã
ãšã³ããã€ã³ãã®è
åš
ãŸããRAã«ã€ããŠè©±ããŠããããããšã³ããã¹ãã®è
åšãç¹ã«IPv6ã§ã®äœæ¥ãèšç»ãããŠããªããã¹ãã®è
åšã«ã¹ã ãŒãºã«ç§»è¡ããŸãã ã€ãŸããéåžžã®IPv4ãããã¯ãŒã¯äžã®ããã©ã«ãã®IPv6æ§æã§å®è¡ãããŠãããã¹ããžã®æ»æãæ€èšããŠãã ããã ææ°ã®OSãRAããã±ãŒãžãååŸãããšã©ããªããŸããïŒ çŸåšãã©ã®ã·ã¹ãã ãIPv6ããµããŒããããã®ãããªãã±ãããæ³å®ããŠãããããããã«ãããããã¥ã¢ã«ã¹ã¿ãã¯ã«å€ãããŸãã ããã¯ãåãOSå
ã§IPv4ãšIPv6ãåæã«äœ¿çšãããç¶æ³ã§ãã ããã«ããã以åã¯ã¢ã¯ã»ã¹ã§ããªãã£ãå€æ°ã®ãã¯ã¿ãŒãããã«éããŸãã ããšãã°ãã¿ãŒã²ãããã¹ãã£ã³ã§ããŸããããã¯ãéåžžIPv4ããã£ã«ã¿ãŒåŠçãããŠãããæ¢ã«ããã£ãŠããããã«ãå€ãã®å ŽåãIPv6ãèæ
®ããªãããã§ãã
ããã«ãã»ãšãã©ã®OSã§ã¯ãIPv6ã¯IPv4ãããåªå
ãããŸãã ããšãã°ãDNSã¯ãšãªãå°çããå ŽåãIPv6ãããæ©ãæ©èœããå¯èœæ§ãé«ããªããŸãã ããã«ãããããŸããŸãªMITMæ»æã®ç¯å²ãåºãããŸãã æãå¹æçãªæ¹æ³ã®1ã€ãå®è¡ããã«ã¯ãæªæã®ããIPv6ã«ãŒã¿ãŒããã¹ãããå¿
èŠããããŸãã åIPv6ã«ãŒã¿ãŒã¯ãå°çšã®ãã«ããã£ã¹ãã°ã«ãŒãã«åå ããå¿
èŠããããŸãã ããã¯FF02 :: 2ã§ãã ã«ãŒã¿ãŒã¯ããã®ãããªãã«ããã£ã¹ãã°ã«ãŒãã«åå ãããšããã«ãã¡ãã»ãŒãžã®éä¿¡ãéå§ããŸã-RAã Ciscoã«ãŒã¿ãŒã¯ãããã©ã«ãã§200ç§ããšã«éä¿¡ããŸãã ãã1ã€ã®ãã¥ã¢ã³ã¹ã¯ãã¯ã©ã€ã¢ã³ãã200ç§åŸ
ã€å¿
èŠããªãããšã§ããã¯ã©ã€ã¢ã³ãã¯ãã®ãã«ããã£ã¹ãã¢ãã¬ã¹ã«RSã¡ãã»ãŒãžïŒã«ãŒã¿ãŒèŠè«ïŒãéä¿¡ããããããã¹ãŠã®æ
å ±ãããã«å¿
èŠã§ãã ãã®ã¡ã«ããºã å
šäœã¯ãSLAAC-ã¹ããŒãã¬ã¹ã¢ãã¬ã¹èªåèšå®ãšåŒã°ããŸãã ããã«å¿ããŠãSLAACæ»æãšããååã§æ»æãéçºãããŸããã
æ»æã¯ãRAã¡ãã»ãŒãžãéä¿¡ããã«ãŒã¿ãŒãã€ã³ã¹ããŒã«ããå¿
èŠãããããšã§ãïŒæåéããLinuxãŸãã¯ä»®æ³ãã·ã³ã§ããã«ãŒã¿ãŒãšããŠæ©èœããããšã¯ã§ããŸããïŒãããããããã¯æŠãã®ååã«ãããŸããã ãŸããæ»æè
ã¯DHCPv6ãµãŒããŒãDNSv6ããã³NAT64ãã©ã³ã¹ã¬ãŒã¿ãŒãèµ·åããå¿
èŠããããŸãã RAã¡ãã»ãŒãžãéä¿¡ã§ãããµãŒãã¹ãšããŠãã«ãŒã¿ãŒã¢ããã¿ã€ãºããŒã¢ã³ïŒradvdïŒã䜿çšã§ããŸããããã¯IPv6ã«ãŒã¿ãŒã®ãªãŒãã³ãœãŒã¹å®è£
ã§ãã ãã®çµæããã¹ãŠã®ããŒã¢ã³ãæ£ããæ§æãããåŸã被害è
ã¯RAãåãåãããã¥ã¢ã«ã¹ã¿ãã¯ã«ãªãã被害è
ã®ãã¹ãŠã®ãã©ãã£ãã¯ã¯å®å
šã«ç®ã«èŠããªãããã«IPv6ãééããŸãã
æ»æè
ã®ã«ãŒã¿ãŒã§ã¯ããã®ãã©ãã£ãã¯ã¯ããªã¥ãŒã ã«ãã£ãŠéåžžã®IPv4ã«å²ã蟌ãŸããå®éã®ã«ãŒã¿ãŒã«éãããŸãã DNSv6ã¯ãšãªãåªå
ãããæ»æè
åŽã§ãåŠçãããŸãã
ãããã£ãŠãæ»æè
ã¯æ£åžžã«äžéã«ãªãããã¹ãŠã®è¢«å®³è
ã®ãã©ãã£ãã¯ãç£èŠã§ããŸãã ãããŠã被害è
ã¯äœãçããŸããã ãã®ãããªæ»æã¯æ倧ã®è
åšããããããŸããIPv4ãã¡ã€ã¢ãŠã©ãŒã«ãšéçARPã¬ã³ãŒãã䜿çšããŠããå Žåã§ãã被害è
ã«åœ±é¿ãäžããæ¹æ³ããªããšæãããå Žåã«æ©èœããŸãã
IPv6ãä¿è·ããæ¹æ³
äžèšã®æ»æããã®ä¿è·ã«ã€ããŠèª¬æããå Žåãå¢çã§ã¯ããã¹ãŠã®ãã©ãã£ãã¯ãæ
éã«ãã£ã«ã¿ãªã³ã°ããæªäœ¿çšã®ãµãŒãã¹ãç¡å¹ã«ããå¿
èŠãããããšãæåã«æããã«ãªããŸãã管çãµãŒãã¹ã«ã¯ç¹ã«æ³šæãæãå¿
èŠããããŸãã ICMPv6ãµãŒãã¹ãããã³ã«ã«åããããããŒã«ã«æ»æã®åœ±é¿ãæžããããã«ã倧èŠæš¡ãªãããã¯ãŒã¯ããµããããã«åå²ããïŒãã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ãšãåŒã°ããïŒããšã«ããããã®ãããªæ»æã®è¡šé¢ãå¶éã§ããŸãã åããããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ãè€æ°ã®vlaneã«åå²ããvlanããšã«åå¥ã®IPv6ãã¬ãã£ãã¯ã¹ãä»ããããšãã§ããŸãã ãã®å Žåãæ»æè
ã¯åãVLANå
ã«ã®ã¿ååšãããã¹ããæ»æã§ãããããæ»æã«ããæ害ã倧å¹
ã«å¶éã§ããŸãã

å³ 5. SLAACæ»æã¹ããŒã

å³ 6. SLAACæ»æã®çµæ
ãããšã¯å¥ã«ãåœã®RAã¡ãã»ãŒãžã«å¯Ÿããä¿è·ããããŸããããã¯ããåãã®ãšãããã«ãŒã¿ãŒããã®ã¿éä¿¡ãããã¹ããã®ã§ãã ã·ã¹ã³ã¯ãã«ãŒã¿ã¢ããã¿ã€ãºã¬ãŒããšåŒã°ããæ©èœãå®è£
ããŸãããããã¯ãæœåšçã«å®å
šã§ãªãããŒããåå¥ã«ããŒã¯ããããšã«ãããä¿¡é Œã§ããªãRAã¡ãã»ãŒãžã®æ¿å
¥ãé²ããŸãã ã€ãŸããRAãã±ããã¯ãŠãŒã¶ãŒããŒãããåã«åãå
¥ããããŸããã ãã®æ©èœã¯ãDHCPã¹ããŒãã³ã°ãšåæ§ã«æ©èœããŸãã å¯äžã®æ¬ ç¹ã¯ããã®ãããªæ©èœãç¹å®ã®ã¯ã©ã¹ã®ããŒããŠã§ã¢ïŒ2960Sã3560ã3750ã·ãªãŒãºã®CatalystïŒã§ã®ã¿å©çšã§ããããšã§ããããã«ãDHCPv6ã¬ãŒããšNDPã¹ããŒãã³ã°ã¯2012幎ã«ç»å ŽããŸããã ã ãããã®ä¿è·ã¡ã«ããºã ã¯ãCatalyst 4500/4948ããã³7600ã·ãªãŒãºã«ãŒã¿ã§äœ¿çšã§ããŸãã
ãšã³ããã¹ãã®ä¿è·ãæ€èšããå ŽåãWindowsã®ãã¹ãŠã®ææ°ããŒãžã§ã³ã¯RAã¡ãã»ãŒãžã®åŠçãå®å
šã«ç¡å¹ã«ããããšãã§ããŸãã ãã¹ãŠã®IPv6ãã©ã¡ãŒã¿ãŒãæåã§æ§æããå Žåãããã¯é©åãªãªãã·ã§ã³ã«ãªãå¯èœæ§ããããŸãããIPv6ã®æšæºçãªã¡ã«ããºã ãå€å°å£ããŸãã ã³ãã³ãã䜿çšããã€ã³ã¿ãŒãã§ãŒã¹äžã§ãéåžžã«ç°¡åã«ãªãã«ãªããŸã
netsh int ipv6 set int X routerdiscovery=disabled
Xã¯ã€ã³ã¿ãŒãã§ã€ã¹ã®ã€ã³ããã¯ã¹ã§ãïŒnetsh int ipv6 show intã³ãã³ãã§IPv6ã€ã³ã¿ãŒãã§ã€ã¹ã®ã€ã³ããã¯ã¹ã衚瀺ã§ããŸãïŒã çµæã¯ãnetsh int ipv6 show int Xã³ãã³ãã§ç¢ºèªãããŸãã
IPv6æ»æã®æ€åºã«é¢ããç¶æ³ãèæ
®ãããšãäžè¬ã«ããã¹ãŠãåé¡ãããŸããã IPv6æ»æã®æ€åºã¯ç°¡åã§ãããä»ã®ãšããé²ãã®ã¯å°é£ã§ãã
話ãç· ãããã
也ç¥æ®çç©ã«ã¯äœãå«ãŸããŠããŸããïŒ å€æããããã«ãIPv6èªäœã¯å®å
šã§ã¯ãããŸããããIPv4ãããæŒããããã¯ãããŸããã åé¡ã¯ããã®ãããã³ã«ã«é¢ããç¥èãšçµéšã®äžè¶³ã«ãããŸãã å¢çã§IPv6ããã£ã«ã¿ãªã³ã°ãããšã³ãããã€ã¹ã§äœ¿çšãããŠããªãå Žåã¯ãªãã«ããå¿
èŠããããŸãã IPv6ã§ã¯IPsecãå¿
èŠã§ãããããå€ãã®äººãIPv6ã¯IPv4ãããå®å
šã ãšèããŠããŸãã ããããããã¯ç¥è©±ã§ãã ã¯ããIPsecã¯IPv6ç°å¢ã§ããã«æ©èœããŸãããå¿
é ã§ã¯ãããŸããã IPv6ã¯ãããããšãããè¯ãããä»ã®ããšãããæªãããŸãããã»ãšãã©ã®ããšã¯èª°ããæ
£ããŠãããã®ãšã¯ç°ãªããŸãã èšãæããã°ãIPv6ã¯IPv4ã»ã©å®å
šã§ã¯ãªããIPv6ã¯åã«äžæã§ãããç¬èªã®ã»ãã¥ãªãã£äžã®æžå¿µãæ±ããŠããŸãã
æçš¿è
ïŒAlexander Dmitrienkoã
PentestIT
2014幎11æããæåã«Hackerèªã«æ²èŒãããŸãããããã«ãŒã賌èªãã

