| ▲ | imoverclocked 16 hours ago | |
This is an interesting piece that is often overlooked by folks in the "but NAT is security" camp; Having a sparse address space that is 64-bits makes it impossible to iteratively scan over a range. If you don't reverse resolve or you disallow zone transfers then you also have no real discoverability for that /64. | ||
| ▲ | happosai 8 hours ago | parent [-] | |
Nobody allows zone transfers these days. But there is still the option for doing a dictionary attack on subdomains admin/ssh/console.example.com But yeah scanning IPv6 address space directly without DNS dictionary in hand is tough. | ||