This Internet-Draft is no longer active. Unofficial copies of old Internet-Drafts can be found here:
http://tools.ietf.org/id/draft-ietf-v6ops-tunnel-loops.
Abstract:
This document is concerned with security vulnerabilities in IPv6-in- IPv4
automatic tunnels. These vulnerabilities allow an attacker to take advantage of inconsistencies between the IPv4 routing state
and the IPv6 routing state. The attack forms a routing loop that can be abused as a
vehicle for traffic amplification to facilitate denial- of-service (DoS) attacks. The first aim of this document is
to inform on this attack and its root causes. The second aim is to present some possible
mitigation measures. It should be noted that at the time of this writing there are no known
reports of malicious attacks exploiting these vulnerabilities. Nonetheless, these
vulnerabilities can be activated by accidental misconfiguration. This document is not an
Internet Standards Track specification; it is published for informational
purposes.
Authors:
Gabi Nakibly <gnakibly@yahoo.com>
Fred Templin <fltemplin@acm.org>
(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid)