Internet Protocol (IPv4 and IPv6)ΒΆ
IP moves packets and asks nothing about where they say they came from. A source address is a claim, a fragment is trusted to reassemble honestly, an IPv6 host configures itself from whatever router advertisement it hears, and a dual-stack machine runs two of these at once while most monitoring watches only one. Each of those assumptions is a way in: a spoofed source, an abused fragment, a forged advertisement, IPv4 and IPv6 played against each other, every one a route towards redirection or trust collapse.
The internet runs on IP. So do attackers.
- Attack tree (IPv4 and IPv6)
- IP fragmentation (IPv4)
- ARP spoofing/poisoning (IPv4)
- NAT abuse (IPv4)
- SLAAC and RA attacks (IPv6)
- NDP exploitation (IPv6)
- IPv6 extension header abuse
- Dual-stack attacks (IPv4 and IPv6)
- Address family exploitation
- IP spoofing and DDoS amplification
- BGP hijacking: the IP layer
- TTL expiry attacks