Vista Security Feature – Teredo Protocol Analysis

Outsmart Malicious Hackers


Teredo is a platform-independent protocol developed by Microsoft, which is enabled by default in Windows Vista. Teredo provides a way for nodes located behind an IPv4 NAT to connect to IPv6 nodes on the Internet. However, by tunneling IPv6 traffic over IPv4 UDP through the NAT and directly to the end node, Teredo raises some security concerns.

Primary concerns include bypassing security controls, reducing defense in depth, and allowing unsolicited traffic. Additional security concerns associated with the use of Teredo include the capability of remote nodes to open the NAT for themselves, benefits to worms, ways to deny Teredo service, and the difficulty in finding all Teredo traffic to inspect.

You can find the report here:

Teredo Security [PDF]

We have completed an analysis of the Teredo protocol based on a reading of the RFC (and apart from any implementation). In this section, we highlight some of the more significant security implications of the protocol; that is, ways in which Teredo positively or negatively impacts the IPv4 and IPv6 portions of the Internet.

Source: Securiteam

Posted in: Hacking News, Windows Hacking

, , , ,


Latest Posts:


OWASP ZSC - Obfuscated Code Generator Tool OWASP ZSC – Obfuscated Code Generator Tool
OWASP ZSC is an open source obfuscated code generator tool in Python which lets you generate customized shellcodes and convert scripts to an obfuscated script.
A Look Back At 2017 – Tools & News Highlights A Look Back At 2017 – Tools & News Highlights
So here we are in 2018, taking a look back at 2017, quite a year it was. Here is a quick rundown of some of the best hacking/security tools released in 2017, the biggest news stories and the 10 most viewed posts on Darknet as a bonus.
Spectre & Meltdown Checker - Vulnerability Mitigation Tool For Linux Spectre & Meltdown Checker – Vulnerability Mitigation Tool For Linux
Spectre & Meltdown Checker is a simple shell script to tell if your Linux installation is vulnerable against the 3 "speculative execution" CVEs that were made public early 2018.
Hijacker - Reaver For Android Wifi Hacker App Hijacker – Reaver For Android Wifi Hacker App
Hijacker is a native GUI which provides Reaver for Android along with Aircrack-ng, Airodump-ng and MDK3 making it a powerful Wifi hacker app.
Sublist3r - Fast Python Subdomain Enumeration Tool Sublist3r – Fast Python Subdomain Enumeration Tool
Sublist3r is a Python-based tool designed to enumerate subdomains of websites using OSINT. It helps penetration testers and bug hunters collect and gather subdomains for the domain they are targeting.
coWPAtty Download - Audit Pre-shared WPA Keys coWPAtty Download – Audit Pre-shared WPA Keys
coWPAtty is a C-based tool for running a brute-force dictionary attack against WPA-PSK and audit pre-shared WPA keys.


5 Responses to Vista Security Feature – Teredo Protocol Analysis

  1. TheRealDonQuixote August 31, 2007 at 12:05 am #

    You could almost sum up the whole article with this one line
    –“Teredo is a platform-independent protocol developed by Microsoft…”

    Right there bells start ringing in my head.

    Then I see this article, Microsoft UK Defaced by Saudi Hackers, and never want to touch a MS product again.

  2. Sandeep Nain August 31, 2007 at 1:39 am #

    HA HA HA HA…
    I like your comment TRDQ..

    Name one thing developed by Microsft which hasn’t got any design flaws..

    and this time they are trying their hands on Platform independent thing..

    ummmm thumbs down for micro$oft

  3. Ne0 September 19, 2008 at 10:30 am #

    the pdf link is broken….. any other plz , hope its good

  4. Darknet September 19, 2008 at 10:49 am #

    PDF still works for me, just tested it.

  5. Goodpeople September 22, 2008 at 7:00 am #

    why am I not surprised..