Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
July 25, 2008, 05:15:01 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
177071
Posts
20935
Topics
50761
Members
Latest Member:
Touriste
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
Anti Virus/Malware Products/Other Security products
TEREDO tunneling
« previous
next »
Pages:
[
1
]
Author
Topic: TEREDO tunneling (Read 527 times)
apache255
Guest
TEREDO tunneling
«
on:
December 20, 2006, 02:49:02 PM »
anybody knows something about Teredo? for a couple of days I have a constant connection to the ip
65.54.227.120 (or 122...). This is a Microsoft ip and from what I found out
http://en.wikipedia.org/wiki/Teredo_tunneling
it's related to Teredo Tuneling, some kind of new protocol from Microsoft, a new version of tcp/ip. Apparentlty my internet provider supports this protocol. I just don't understand why that would involve that my pc remains constantly connected to a Microsoft site. Since I've got that, comodo firewall shows me loads of connections between svchost.exe and my router, + one with Microsoft.
there's also that dll listed in component monitor: 6to4svc.dll. It is described as beeing part of a service that offers ipv6 connectivity over ipv4 network. That seems to be related too to Teredo. According to what I read it should be deactivated by default on xpsp2. So I found the service, deactivated it, blocked the dll in Comodo Firewall, but that changes nothing, I still have these connections. I already posted a screen shot in the forum before, here it is:
http://img175.imageshack.us/my.php?image=connectionsac4.jpg
I'll try to upload it directly here again...I've read the issue about "full upload folder" was resolved.
«
Last Edit: December 20, 2006, 03:41:06 PM by apache255
»
Logged
freshhh
Comodo Family Member
Offline
Posts: 58
Re: TEREDO tunneling
«
Reply #1 on:
May 02, 2008, 09:22:31 PM »
Why Teredo blocking is important
All Windows Vista machines come with a service known as "Teredo" enabled by default. This enables you to access the IPv6 internet using IPv4. It also means that any IPv4 user can masquerade as being on IPv6 in attempt to evade IP blockers and firewalls.
PeerGuardian fully detects these types of IPv6 users and will check them against the regular blocklist.
Logged
freshhh
Comodo Family Member
Offline
Posts: 58
Re: TEREDO tunneling
«
Reply #2 on:
May 02, 2008, 09:25:53 PM »
6to4, the most common IPv6 over IPv4 tunneling protocol, requires the tunnel endpoint to have a public IPv4 address. However, many hosts are currently attached to the IPv4 Internet through one or several NAT devices, usually because of IPv4 address shortage. In such a situation, the only available public IPv4 address is assigned to the NAT device, and the 6to4 tunnel endpoint needs to be implemented on the NAT device itself. Many NAT devices currently deployed, however, cannot be upgraded to implement 6to4, for technical or economic reasons.
Teredo alleviates this problem by encapsulating IPv6 packets within UDP/IPv4 datagrams, which most NATs can forward properly. Thus, IPv6-aware hosts behind NATs can be used as Teredo tunnel endpoints even when they don't have a dedicated public IPv4 address. In effect, a host implementing Teredo can gain IPv6 connectivity with no cooperation from the local network environment.
Teredo is a temporary measure: in the long term, all IPv6 hosts should use native IPv6 connectivity. The Teredo protocol includes provisions for a sunset procedure: Teredo implementation should provide a way to stop using Teredo connectivity when IPv6 has matured and connectivity becomes available using a less brittle mechanism.
Source :
http://en.wikipedia.org/wiki/Teredo_tunneling
(more to read)
Logged
freshhh
Comodo Family Member
Offline
Posts: 58
Re: TEREDO tunneling
«
Reply #3 on:
May 02, 2008, 09:30:05 PM »
Teredo may render your firewall useless
You most certainly know IPV4. You may have heard about IPV6. Do you know what Teredo is? No? That's bad provided you run a firewall to seperate the Internet from your local network. Teredo is a mechanism that allows encapsulation of IPV6 packets into IPV4 UDP and uses relay servers to let IPV6 clients communicate by using relay servers. Symantec has a very thorough analysis of Teredo:
Currently hardly any firewalls or intrusion detection systems are able to recognise Teredo packets and they are therefore unable to filter IPv6 traffic. Rather they see UDP traffic via any ports. Teredo could become a problem, in particular because it circumvents the supposed protection offered by NAT. While, to date, private IPv4 addresses have not been routed via the internet, with IPv6 every computer is automatically assigned a unique IPv6 address, into which goes, for example, the MAC address of the network card and which is in principle accessible from the internet.
Source :
http://web.luchs.at/article.php?cat=2&aid=298
Logged
freshhh
Comodo Family Member
Offline
Posts: 58
Re: TEREDO tunneling
«
Reply #4 on:
May 03, 2008, 02:15:17 PM »
mm why the moving?
i think this is linked to Comodo Firewall ability to handle or not IP6 traffic (new protocol used by Vista OS)
so, is Comodo Firewall vulnerable to IP6 masking ? should we block all UDP requests?
«
Last Edit: May 03, 2008, 02:22:20 PM by freshhh
»
Logged
sded
Global Moderator
Comodo's Hero
Online
Posts: 1788
Re: TEREDO tunneling
«
Reply #5 on:
May 03, 2008, 02:46:39 PM »
A NAT router blocks all input connections that are not responses to outgoing traffic or a selected exception. So unless you have a program in your computer that has opened a port for Toredo traffic, should be blocked there. With CFP3, you should either get the same block or get a popup asking you to allow or deny, depending on how you have set up stealth port wizard. Most users have UDP in blocked, with allow only by exception. And SPI takes care of the usual responses for DNS, DHCP, ... . IPv6 is not new for Vista; it has been around for quite a while and even old firewalls like Kerio 2.1.5 worried about it and blocked it in XP and before (protocol 50). NICs for Vista do routinely allow you to select or not select support to IPv6 as part of the connection setup, a feature missing in XP. The other native support for IPV6 (routers, ISP links, ...) still seems pretty sparse. Haven't used it myself though; haven't found a reason yet. Maybe a security expert will show up and tell us more.
«
Last Edit: May 03, 2008, 03:08:29 PM by sded
»
Logged
CFP 3.0.24/368, Vista Ultimate 32x + SP1, Avast! 4.8, Windows Defender. SAS offline. Acronis True Image just in case.
freshhh
Comodo Family Member
Offline
Posts: 58
Re: TEREDO tunneling
«
Reply #6 on:
May 03, 2008, 02:55:20 PM »
thanks for this long answer
well it seems that CF does not block IP's (in a specific rule) that PG RC1 (Peerguardian) can block so I thought IPv6 protocal not very well handled by CF was the reason...
Logged
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> CSE Beta Corner
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.127 seconds with 19 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com