Hacker News new | ask | show | jobs
by nucotano 3532 days ago
I'm so looking forward at IPv6, the death of NAT, and billions of IoT devices with all ports exposed to the world :-)
5 comments

Arent most IOT devices behind a router and thus unexposed directly to the internet (excepting routers)?

This part of these attacks confuses me.

Compromised routers can be used to compromise devices behind it. Also many devices (like IP cameras) usually have port forwarding to allow the users to access it from outside.
This is an interesting approach to get past NAT: https://thehackerblog.com/sonar-a-framework-for-scanning-and...
Many devices use UPNP to automatically punch a hole through the NAT and expose their ports to the world.
Pretty much every router is sold with UPnP turned on.

Many IOT devices use UPnP to open their interface to the world.

NAT != stateful firewall.
Most CPE's running IPv6 will be following RFC 6092. Everything is blocked apart from ICMPv6 basicly.
>Most CPE's running IPv6 will be following RFC 6092.

It's pretty naive to think that any CPE will be following any kind of norm or rule.

/s
A brave new world!