top | item 39100261

(no title)

Throw84949 | 2 years ago

I disable ipv6 on my network, way too many security exploits!

discuss

order

sgjohnson|2 years ago

Such as?

msm_|2 years ago

Firewall misconfigurations, mostly. It's way harder to keep firewall up to date when you have to worry about two independent stacks.

Throw84949|2 years ago

I don't have vulnerability ids.

What made me disable it was some issue in Linux network stack, with ipv6 broadcast, on by default, exploitable to root execution.

For me it is yet another complex service that I do not need, and that should not be exposed to network. Ipv4 network stack code is far smaller, simpler and way more tested over decades!