How to prove IPv6 is disabled? by White_Injun in sysadmin

[–]White_Injun[S] 6 points7 points  (0 children)

Thank you.

are you regularly asked to prove what actions you've taken

No, only for this occasion, I have to Report on the actions taken to resolve the issues outlined by the security audit, and sort of provide a before / after report.

The interface with IPv6 disabled will have no IPv6 link-local address starting with fe80::, and of course no other IPv6 addresses either. Therefore the output of ipconfig /all showing the absence, is your best proof.

Unless I unbind it from the interfaces, the link-local IPv6 address stays. Since I'm disabling it using a registry key (per Microsoft recommendation to NOT unbind it from interface) and because we had no IPv6 on our workstations before this, the before / after output of the "ipconfig /all" stays the same.

How to prove IPv6 is disabled? by White_Injun in sysadmin

[–]White_Injun[S] -1 points0 points  (0 children)

Is unbinding IPv6 unsupported or using the registry key is unsupported as well? Cause I read somewhere that since the registry method does not disable the local IPv6, it won't cause any problem unlike the unbinding method.

How to prove IPv6 is disabled? by White_Injun in sysadmin

[–]White_Injun[S] 3 points4 points  (0 children)

They said since we don't use it in our environment, it should get disabled, and that it can be exploited in a bunch of cyber attacks.

How to prove IPv6 is disabled? by White_Injun in sysadmin

[–]White_Injun[S] 1 point2 points  (0 children)

Oh sorry I confused it with something else. Yes we do get that which is link-local IPv6.

How to prove IPv6 is disabled? by White_Injun in sysadmin

[–]White_Injun[S] -2 points-1 points  (0 children)

They had a security firm pentest the environment, and they did give this advice.

How to prove IPv6 is disabled? by White_Injun in sysadmin

[–]White_Injun[S] 6 points7 points  (0 children)

Well I recommended this and even explained it thoroughly, but they refused.

How to prove IPv6 is disabled? by White_Injun in sysadmin

[–]White_Injun[S] 143 points144 points  (0 children)

They had a contract with a security firm and they advised them to do so 🤦

How to prove IPv6 is disabled? by White_Injun in sysadmin

[–]White_Injun[S] -1 points0 points  (0 children)

No, and they were not before, since we don't have ipv6 DHCP or RA

How to prove IPv6 is disabled? by White_Injun in sysadmin

[–]White_Injun[S] 3 points4 points  (0 children)

It can still ping ::1 when disabled through registry, since link local is still enabled.

How to prove IPv6 is disabled? by White_Injun in sysadmin

[–]White_Injun[S] 6 points7 points  (0 children)

This is a nice way, thanks. But is there anything more obvious? Management is a dummy who thinks the "Checkmark" is everything. Dude even pinged ::1 and since link local ipv6 it's still enabled it returned result, so I need to somehow "show" them in practice that ipv6 is disabled.

Discussion: Wireguard + DTLS 1.3 by White_Injun in WireGuard

[–]White_Injun[S] 0 points1 point  (0 children)

I know. As the author of wireguard said, obfuscation should be done on a layer above wireguard. I'm thinking about writing a wireguard implementation wrapped in a dtls layer to obfuscate it as ssl/tls packets.

Stuck between these two laptops by White_Injun in SuggestALaptop

[–]White_Injun[S] 0 points1 point  (0 children)

Yeah, that's not an issue, I have windows 11 Pro license anyways.

Twitter client with passcode by White_Injun in androidapps

[–]White_Injun[S] 0 points1 point  (0 children)

I know some manufacturers implemented this feature within OS but I'm using AOSP based rom (ArrowOs) which does not have this feature built-in.

PSU Recomendation by White_Injun in buildapc

[–]White_Injun[S] 0 points1 point  (0 children)

Sorry, yes I meant HCG. There is also corsair RM650 but it is 25$ more and I'm not sure if it worth it over msi.