Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
May 17, 2008, 03:37:17 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
155211
Posts
19181
Topics
47327
Members
Latest Member:
OldGrantonian
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
Anti Virus/Malware Products/Other Security products
TEREDO tunneling
« previous
next »
Pages:
[
1
]
Author
Topic: TEREDO tunneling (Read 234 times)
apache255
Guest
TEREDO tunneling
«
on:
December 20, 2006, 02:49:02 PM »
anybody knows something about Teredo? for a couple of days I have a constant connection to the ip
65.54.227.120 (or 122...). This is a Microsoft ip and from what I found out
http://en.wikipedia.org/wiki/Teredo_tunneling
it's related to Teredo Tuneling, some kind of new protocol from Microsoft, a new version of tcp/ip. Apparentlty my internet provider supports this protocol. I just don't understand why that would involve that my pc remains constantly connected to a Microsoft site. Since I've got that, comodo firewall shows me loads of connections between svchost.exe and my router, + one with Microsoft.
there's also that dll listed in component monitor: 6to4svc.dll. It is described as beeing part of a service that offers ipv6 connectivity over ipv4 network. That seems to be related too to Teredo. According to what I read it should be deactivated by default on xpsp2. So I found the service, deactivated it, blocked the dll in Comodo Firewall, but that changes nothing, I still have these connections. I already posted a screen shot in the forum before, here it is:
http://img175.imageshack.us/my.php?image=connectionsac4.jpg
I'll try to upload it directly here again...I've read the issue about "full upload folder" was resolved.
«
Last Edit: December 20, 2006, 03:41:06 PM by apache255
»
Logged
freshhh
Comodo Family Member
Offline
Posts: 57
Re: TEREDO tunneling
«
Reply #1 on:
May 02, 2008, 09:22:31 PM »
Why Teredo blocking is important
All Windows Vista machines come with a service known as "Teredo" enabled by default. This enables you to access the IPv6 internet using IPv4. It also means that any IPv4 user can masquerade as being on IPv6 in attempt to evade IP blockers and firewalls.
PeerGuardian fully detects these types of IPv6 users and will check them against the regular blocklist.
Logged
freshhh
Comodo Family Member
Offline
Posts: 57
Re: TEREDO tunneling
«
Reply #2 on:
May 02, 2008, 09:25:53 PM »
6to4, the most common IPv6 over IPv4 tunneling protocol, requires the tunnel endpoint to have a public IPv4 address. However, many hosts are currently attached to the IPv4 Internet through one or several NAT devices, usually because of IPv4 address shortage. In such a situation, the only available public IPv4 address is assigned to the NAT device, and the 6to4 tunnel endpoint needs to be implemented on the NAT device itself. Many NAT devices currently deployed, however, cannot be upgraded to implement 6to4, for technical or economic reasons.
Teredo alleviates this problem by encapsulating IPv6 packets within UDP/IPv4 datagrams, which most NATs can forward properly. Thus, IPv6-aware hosts behind NATs can be used as Teredo tunnel endpoints even when they don't have a dedicated public IPv4 address. In effect, a host implementing Teredo can gain IPv6 connectivity with no cooperation from the local network environment.
Teredo is a temporary measure: in the long term, all IPv6 hosts should use native IPv6 connectivity. The Teredo protocol includes provisions for a sunset procedure: Teredo implementation should provide a way to stop using Teredo connectivity when IPv6 has matured and connectivity becomes available using a less brittle mechanism.
Source :
http://en.wikipedia.org/wiki/Teredo_tunneling
(more to read)
Logged
freshhh
Comodo Family Member
Offline
Posts: 57
Re: TEREDO tunneling
«
Reply #3 on:
May 02, 2008, 09:30:05 PM »
Teredo may render your firewall useless
You most certainly know IPV4. You may have heard about IPV6. Do you know what Teredo is? No? That's bad provided you run a firewall to seperate the Internet from your local network. Teredo is a mechanism that allows encapsulation of IPV6 packets into IPV4 UDP and uses relay servers to let IPV6 clients communicate by using relay servers. Symantec has a very thorough analysis of Teredo:
Currently hardly any firewalls or intrusion detection systems are able to recognise Teredo packets and they are therefore unable to filter IPv6 traffic. Rather they see UDP traffic via any ports. Teredo could become a problem, in particular because it circumvents the supposed protection offered by NAT. While, to date, private IPv4 addresses have not been routed via the internet, with IPv6 every computer is automatically assigned a unique IPv6 address, into which goes, for example, the MAC address of the network card and which is in principle accessible from the internet.
Source :
http://web.luchs.at/article.php?cat=2&aid=298
Logged
freshhh
Comodo Family Member
Offline
Posts: 57
Re: TEREDO tunneling
«
Reply #4 on:
May 03, 2008, 02:15:17 PM »
mm why the moving?
i think this is linked to Comodo Firewall ability to handle or not IP6 traffic (new protocol used by Vista OS)
so, is Comodo Firewall vulnerable to IP6 masking ? should we block all UDP requests?
«
Last Edit: May 03, 2008, 02:22:20 PM by freshhh
»
Logged
sded
Global Moderator
Comodo's Hero
Offline
Posts: 1653
Re: TEREDO tunneling
«
Reply #5 on:
May 03, 2008, 02:46:39 PM »
A NAT router blocks all input connections that are not responses to outgoing traffic or a selected exception. So unless you have a program in your computer that has opened a port for Toredo traffic, should be blocked there. With CFP3, you should either get the same block or get a popup asking you to allow or deny, depending on how you have set up stealth port wizard. Most users have UDP in blocked, with allow only by exception. And SPI takes care of the usual responses for DNS, DHCP, ... . IPv6 is not new for Vista; it has been around for quite a while and even old firewalls like Kerio 2.1.5 worried about it and blocked it in XP and before (protocol 50). NICs for Vista do routinely allow you to select or not select support to IPv6 as part of the connection setup, a feature missing in XP. The other native support for IPV6 (routers, ISP links, ...) still seems pretty sparse. Haven't used it myself though; haven't found a reason yet. Maybe a security expert will show up and tell us more.
«
Last Edit: May 03, 2008, 03:08:29 PM by sded
»
Logged
CFP 3.0.22/349, Vista Ultimate 32x + SP1, Avast! 4.8
freshhh
Comodo Family Member
Offline
Posts: 57
Re: TEREDO tunneling
«
Reply #6 on:
May 03, 2008, 02:55:20 PM »
thanks for this long answer
well it seems that CF does not block IP's (in a specific rule) that PG RC1 (Peerguardian) can block so I thought IPv6 protocal not very well handled by CF was the reason...
Logged
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> General Discussion (off topic) Anything and everything...
-----------------------------
Desktop Security Products
-----------------------------
===> Help for v2
=> AntiSpam
=> Comodo Anti-Viruspyware (CAVS)
=> Backup
-----------------------------
Free Services for End Users
-----------------------------
=> Hacker Guardian
-----------------------------
Desktop Security Products
-----------------------------
=> i-Vault
=> Launch Pad
-----------------------------
Free Services for End Users
-----------------------------
=> Comodo Meet (Web Conferencing Product)
-----------------------------
Web Server Products
-----------------------------
=> Trustlogo
-----------------------------
Desktop Security Products
-----------------------------
=> Trusttoolbar
=> Verification Engine (allows you to verify what you see on the Internet)
-----------------------------
Digital Certificates
-----------------------------
=> SSL Certificate
=> Email Certificate
=> Content Verification Certificate
=> Code Signing Certificate
-----------------------------
Free Services for End Users
-----------------------------
=> Trustfax (free Trial) (online faxing)
-----------------------------
Infrastructure Products
-----------------------------
=> Trustix Enterprise Firewall
-----------------------------
Want to help Comodo?
-----------------------------
===> Help spread the word! (Please read and help)
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
-----------------------------
General Category
-----------------------------
=> Which Product do you want Comodo to develop next?
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> Italiano / Italian
===> ελληνικά / Greek
===> Turkce / Turkish
-----------------------------
Desktop Security Products
-----------------------------
===> Frequently Asked Questions (FAQ) for Comodo firewall
-----------------------------
Want to help Comodo?
-----------------------------
=> Please tell us your views and Vote here!
-----------------------------
Free Services for End Users
-----------------------------
=> User Anywhere (Remote Access product)
-----------------------------
International Comodo Forums
-----------------------------
===> Espanol / Spanish
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
-----------------------------
International Comodo Forums
-----------------------------
===> Português/Portuguese
-----------------------------
Want to help Comodo?
-----------------------------
=> How can you help Comodo? (Please we do need you!)
-----------------------------
International Comodo Forums
-----------------------------
===> Nihongo / Japanese
-----------------------------
Desktop Security Products
-----------------------------
===> FAQ for Comodo Anti-ViruSpyware
-----------------------------
Want to help Comodo?
-----------------------------
===> Comodo website issues for submitting website problems only
-----------------------------
General Category
-----------------------------
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Desktop Security Products
-----------------------------
===> Virus/Malware Removal Assistance
===> Comodo Firewall Translations
-----------------------------
International Comodo Forums
-----------------------------
===> Svenska / Swedish
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Anti Phishing solutions
=> HIPS (Host Intrusion Prevention Systems)
=> Digital Certificates, Encryption and Digital Signing
-----------------------------
International Comodo Forums
-----------------------------
===> Francais / French
===> По-русски / Russian
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Magyar / Hungarian
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Secure Email (CSE) Product
===> CSE Beta Corner
-----------------------------
International Comodo Forums
-----------------------------
===> Deutsch / German
===> Polski / Polish
===> Norsk / Norwegian
===> Українська / Ukrainian
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo BOClean Anti-Malware
===> Comodo BOClean Anti-Malware FAQ
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments (not product related)
-----------------------------
Desktop Security Products
-----------------------------
===> Help for Comodo AntiVirus
-----------------------------
International Comodo Forums
-----------------------------
===> tiếng Việt / Vietnamese
-----------------------------
Desktop Security Products
-----------------------------
===> Announcements
===> Feedback/Comments/Announcements/News about CAVS
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> FAQ for Comodo Backup
=> Comodo TrustConnect - Securing the Wireless world!
===> Help
===> Help for v3
===> Bug Reports
===> Feedback/Comments/Announcements/News
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Vulnerability Analyzer
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
Page created in 0.116 seconds with 18 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com