EDBT 2026 Demo / reviewers in the wild / expert
Tobias Fiebig
dblp:150/5174
· DBLP profile ↗
29ranked-venue papers
4as first author
23since 2021 · last 2025
0000-0002-0163-5134ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 19 · 3 first-author · 13 since 2021Computer networks · 5 · 1 first-author · 5 since 2021Human-computer interaction and ubiquitous computing · 3 · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Attacks Come to Those Who Wait: Long-Term Observations in an SSH HoneynetabstractNumerous studies have explored SSH attacks, often focusing on specific botnet activities or providing short-term analyses of particular honeynets. In this paper, we present an analysis of data collected from a large-scale honeynet over a three-year period, shedding light on gradual shifts in attacker behavior. Our findings suggest a trend toward more exploratory attacks, with indications that attackers are increasingly moving beyond the blind execution of scripts. Cristian Munteanu 0001, Yogesh Bhargav Suriyanarayanan, Georgios Smaragdakis, Anja Feldmann, Tobias Fiebig |
IMC | 5 |
| 2025 | Unraveling the Complexities of MTA-STS Deployment and Management in Securing EmailabstractEmail has been a cornerstone of online communication for decades, but its lack of built-in confidentiality has left it vulnerable to various attacks. To address this issue, two key protocols are being used: MTA-STS (Mail Transfer Agent Strict Transport Security) and DANE (DNS-based Authentication of Named Entities). While DANE was introduced first, MTA-STS has been actively adopted by major email providers like Google and Microsoft, as it does not require the complex DNSSEC chain that poses a significant challenge in deploying and managing DANE. However, despite its significance, there has been limited research on how MTA-STS is deployed and managed in practice. In this study, we present a thorough, longitudinal investigation of the MTA-STS ecosystem. We base our analysis on a dataset capturing over 87 million domains from DNS scans collected across four TLDs over 31 months, along with 10 months of additional component scanning such as TLS certificates, thereby offering a broad perspective on MTA-STS adoption and its management. Our analysis uncovers a concerning trend of misconfigurations and inconsistencies in MTA-STS setups. In our most recent snapshot, out of ~68K domains with MTA-STS record, 29.6% of domains were incorrectly configured, while 3.2% of these should encounter email delivery failure from MTA-STS supporting senders. To gain insights into the challenges faced by email administrators, we surveyed 117 operators. While awareness of MTA-STS was high (94.7%), many cited operational complexity (48.8%) and a preference for DANE (45.4%) as reasons for not deploying the protocol. Our study not only highlights the growing importance of MTA-STS but also reveals the significant challenges in its deployment and management. Md. Ishtiaq Ashiq, Tobias Fiebig, Taejoong Chung |
IMC | 2 |
| 2025 | 'How I learned to stop worrying and love IPv6': Measuring the Internet's Readiness for DNS over IPv6abstractIn this paper, we revisit a fundamental discussion in the context of the Internet's future from the past decade: Is IPv6 harmful for DNS or not? As simple as this question may sound, until now, there is no clear recommendation to support DNS for authoritative and recursive name servers. RFC3901 is unchanged since 2004. We revisit the decades long history of this discussion, how it relates to choices regarding fragmentation (end-to-end in IPv6 vs. on-path in IPv4), limitations to Path MTU Discovery (PMTUD), and diverging security policies which suggest dropping IPv6 fragments. To address this question we gather an extensive dataset to capture zones' resolvability (for the top 10 million domains in the Google Chrome User Experience report) over time for different MTU and PMTUD scenarios. To scale our experiments we introduce 'unique name server sets', since fragmentation avoidance (RFC9715) and EDNS0 and TCP fallback capabilities are name server specific. Our results challenge prior work, demonstrating that: i) The negative impact of DNS resolution via IPv6 is negligible, even for DNSSEC enabled zones in a worst-case MTU/PMTUD scenario, ii) NS-Sets supporting DNSSEC are more likely to also support DNS resolution via IPv6, iii) Dropping or not dropping of fragments has negligible impact on IPv6 DNS resolution, and iv) Prior work missed the notable role of a single Tier-1 when determining how wide-spread IPv6 fragment dropping is. From our results, we argue that it is time to recommend that IPv6 SHOULD be used in the DNS. Tobias Fiebig, Anja Feldmann |
IMC | 1 |
| 2025 | Measuring the deployment of DNSSEC Bootstrapping Using Authenticated SignalsabstractThe DNS, the Internet's address book, traditionally does not guarantee authenticity of data. The DNS Security Extensions (DNSSEC) exist to add cryptographic authenticity checks to the DNS. In spite of DNSSEC being over 30 years old, its widespread deployment has not yet come to fruition. Current work in the IETF tries automating the setup of DNSSEC, in the hopes of furthering its deployment. Q. Misell, Florian Steurer, Johannes Zirngibl, Anja Feldmann, Tobias Fiebig |
IMC | 5 |
| 2025 | A Tree in a Tree: Measuring Biases of Partial DNS Tree ExplorationabstractAbstract The Domain Name System (DNS) is a cornerstone of the Internet. As such, it is often the subject or the means of network measurement studies. Over the past decades, the Internet measurement community gathered many lessons-learned and captured them in widely available measurement toolchains such as ZDNS and OpenINTEL as well as many papers. However, for feasibility, these tools often restrict DNS tree exploration, use caching, and other intricate methods for reducing query load. This potentially hides many corner cases and unforeseen problems. In this paper, we present a system capable of exploring the full DNS tree. We gather 87 TB of DNS data covering 812M domains with over 85B queries over 40 days. Using this data, we replicate four earlier studies that used feasibility and time-optimized DNS datasets. Our results demonstrate the need for care in selecting which limitations regarding the perspective on DNS can be accepted for a given research question and which may alter findings and conclusions. Florian Steurer, Anja Feldmann, Tobias Fiebig |
PAM | 3 |
| 2025 | The Importance of Being Earnest: Shedding Light on Johnny's (False) Sense of PrivacyabstractAs privacy concerns grow, organizations and policy makers promote the use of privacy-enhancing technologies (PETs) to improve user trust and data-sharing behaviors. However, privacy-enhancing technologies (PETs) are often technologically complex and opaque to lay users. It is challenging to understand and effectively communicate the functionality of complex PETs to the users, such as Secure Multi-Party Computation (MPC). Studies typically assess the impact of new PETs by presenting users with a high-level description of the technology before measuring how this treatment changed their attitude or behavior. These results influence business and regulatory decisions (see Gartner's Hype Cycle for Emerging Technology [123]). In the present study, we question this approach. We assess whether naming specific PETs and providing generic descriptions impact users' willingness to put trust in service providers and share their data. Our survey presented three randomized controlled trials with 1,457 participants in a data marketplace scenario. The first group was treated with a PET (MPC), the second group with a fictional PET, and the third with a non-PET, serving as a control group. Our findings reveal that user trust and data-sharing willingness increased with MPC and the fictional PET, indicating that the high-level description, rather than the technology name, shapes user perception. We conclude that claiming the use of a PET is not an effective method to measure the impact of actually using this technology. However, given their mental model, lay users cannot verify the privacy claims of such descriptions presented in studies or by service providers. This increases the risks of users being deceived into a false sense of privacy, leading them to expose more private data than they otherwise would. Wirawan Agahari, Alexandra Dirksen, Martin Johns, Mark de Reuver, Tobias Fiebig |
SP | 5 |
| 2025 | Catch-22: Uncovering Compromised Hosts using SSH Public Keys
Cristian Munteanu 0001, Georgios Smaragdakis, Anja Feldmann, Tobias Fiebig |
USENIX Security Symposium | 4 |
| 2025 | 'You just wanna sign on the dotted line and hope for the best': Navigating the Cloudscapes of Higher EducationabstractCloud-hosted environments are increasingly being adopted in both industry and academia alike, with marketing material and popular belief holding a myriad of conjectures as to why this adoption progresses. There is, however, a limited understanding of the factors that influence the decision to move to the cloud and the challenges encountered on this migration journey, grounded in data, specifically in the context of higher education. To address this gap, we perform an in-depth qualitative investigation to better understand the human factors of cloud adoption in universities. We engaged with 18 participants via semi-structured interviews and analysed the data using thematic analysis. We present our findings around three main themes - the decision matrix, the people-centric transition and the guardians of data - to comprehend the landscape of cloud migration ( cloudscape ) in higher education. Our findings highlight that cloud migrations go beyond a technical transformation. While they regularly encompass shifts in people's roles and mindsets, cloud adoption in the absence of such a shift may lead to patterns that triggered the move away from self-hosted and on-premise solutions in the first place. Furthermore, we find interaction effects between the technical depth of decision makers in contrast to necessary risk acceptance in the context of cloud adoption, thereby further adding to the broader discussion regarding the place of academia in monopolistic markets. Simran Munot, Tobias Fiebig, Mannat Kaur 0001 |
Proc. ACM Hum. Comput. Interact. | 2 |
| 2024 | The Roots Go Deep: Measuring '.' Under ChangeabstractIn this study, we measure all root servers over a period of 174 days from 675 vantage points in 523 networks and 62 countries using IPv4 and IPv6. Using this data, we first investigate the co-location between root servers, finding that almost 70% of clients observe co-location of at least two servers. Second, we monitor the integrity of zone transfers, finding rare issues like bitflips or stale zone files. Finally, by enriching our data with passive ISP and IXP data, we quantify the role of IPv6 for performance and behavior under change, finding that even seemingly similar subsets of root servers can differ considerably. Florian Steurer, Danny Alex Lachos Perez, Anja Feldmann, Tobias Fiebig |
IMC | 5 |
| 2024 | Don't Patch the Researcher, Patch the Game: A Systematic Approach for Responsible Research via Federated Ethics Boards
Alexandra Dirksen, Sebastian Giessler, Hendrik Erz, Martin Johns, Tobias Fiebig |
NSPW | 5 |
| 2024 | SPF Beyond the Standard: Management and Operational Challenges in Practice and Practical Recommendations
Md. Ishtiaq Ashiq, Weitong Li, Tobias Fiebig, Taejoong Chung |
USENIX Security Symposium | 3 |
| 2023 | Certifiably Vulnerable: Using Certificate Transparency Logs for Target ReconnaissanceabstractThe Web PKI ecosystem provides an underlying layer of security to many Internet protocols used today. By relying on Certificate Authorities (CAs), communication can be authenticated and encrypted based on a chain of trust. Unfortunately, this chain of trust has been broken in the past. For instance, in 2011, adversaries managed to issue fraudulent certificates on behalf of the DigiNotar CA, resulting in a loss of trust in DigiNotar. To better detect fraudulent certificates, Google introduced the concept of Certificate Transparency (CT), which is based on append-only logs that allow one to monitor and detect wrongly issued X.509 certificates.In this work, we investigate the potential of these logs as a data source for target reconnaissance. Concretely, we divide our study into two parts: First, we deploy several honeypot web servers over a period of 200 days to study the effect on incoming scanning traffic after pushing a certificate to one or more CT logs. We find that adding a certificate to a CT log leads to incoming network probes, just seconds after publishing the entry. This suggests that CT logs are used as input for web scans. In the IPv6 address space, our web server received 2,700 packets after pushing our certificate to a CT log, compared to 0 packets in our control group.Second, we use large-scale active measurements to find potentially vulnerable domains from CT log data. Using certificate issuance and renewal patterns, we identify websites that are either at the beginning or at the end of their life cycle. Our results show that freshly deployed websites are not more likely to contain a known CVE compared to websites that just renewed their certificate. On the other side of the spectrum, however, we find that websites with an expired certificate, yet still deployed in the wild, tend to contain more outdated software, and hence more known CVEs. As such, CT logs can indeed function as a data source for target reconnaissance. Stijn Pletinckx, Tobias Fiebig, Christopher Krügel, Giovanni Vigna |
EuroS&P | 3 |
| 2023 | Connecting the .dotfiles: Checked-In Secret Exposure with Extra (Lateral Movement) StepsabstractPersonal software configurations, known as dotfiles, are increasingly being shared in public repositories. To understand the security and privacy implications of this phenomenon, we conducted a large-scale analysis of dotfiles repositories on GitHub. Furthermore, we surveyed repository owners to understand their motivations for sharing dotfiles, and their awareness of the security implications. Our mixed-method approach consisted of two parts: (1) We mined 124,230 public dotfiles repositories and inductively searched them for security and privacy flaws. (2) We then conducted a survey of repository owners (n=1,650) to disclose our findings and learn more about the problems and implications. We found that 73.6 % of repositories leak potentially sensitive information, most commonly email addresses (of which we found 1.2 million), but also RSA private keys, API keys, installed software versions, browsing history, and even mail client inboxes. In addition, we found that sharing is mainly ideological (an end in itself) and to show off ("ricing"), in addition to easing machine setup. Most users are confident about the contents of their files and claim to understand the security implications. In response to our disclosures, a small minority (2.2%) will make their repositories private or delete them, but the majority of respondents will continue sharing their dotfiles after taking appropriate actions. Dotfiles repositories are a great tool for developers to share knowledge and communicate – if done correctly. We provide recommendations for users and platforms to make them more secure. Specifically, tools should be used to manage dotfiles. In addition, platforms should work on more sophisticated tests, to find weaknesses automatically and inform the users or control the damage. Gerhard Jungwirth, Aakanksha Saha, Michael Schröder 0005, Tobias Fiebig, Martina Lindorfer, Jürgen Cito |
MSR | 4 |
| 2023 | Back-to-the-Future Whois: An IP Address Attribution Service for Working with Historic DatasetsabstractAbstract Researchers and practitioners often face the issue of having to attribute an IP address to an organization. For current data this is comparably easy, using services like whois or other databases. Similarly, for historic data, several entities like the RIPE NCC provide websites that provide access to historic records. For large-scale network measurement work, though, researchers often have to attribute millions of addresses. For current data, Team Cymru provides a bulk whois service which allows bulk address attribution. However, at the time of writing, there is no service available that allows historic bulk attribution of IP addresses. Hence, in this paper, we introduce and evaluate our ‘Back-to-the-Future whois’ service, allowing historic bulk attribution of IP addresses on a daily granularity based on CAIDA Routeviews aggregates. We provide this service to the community for free, and also share our implementation so researchers can run instances themselves. Florian Streibelt, Martina Lindorfer, Seda Gurses, Carlos Gañán, Tobias Fiebig |
PAM | 5 |
| 2023 | How Ready is DNS for an IPv6-Only World?abstractAbstract DNS is one of the core building blocks of the Internet. In this paper, we investigate DNS resolution in a strict IPv6-only scenario and find that a substantial fraction of zones cannot be resolved. We point out, that the presence of an resource record for a zone’s nameserver does not necessarily imply that it is resolvable in an IPv6-only environment since the full DNS delegation chain must resolve via IPv6 as well. Hence, in an IPv6-only setting zones may experience an effect similar to what is commonly referred to as lame delegation. Our longitudinal study shows that the continuing centralization of the Internet has a large impact on IPv6 readiness, i.e., a small number of large DNS providers has, and still can, influence IPv6 readiness for a large number of zones. A single operator that enabled IPv6 DNS resolution–by adding IPv6 glue records–was responsible for around 20.3% of all zones in our dataset not resolving over IPv6 until January 2017. Even today, 10% of DNS operators are responsible for more than 97.5% of all zones that do not resolve using IPv6 . Florian Streibelt, Patrick Sattler, Franziska Lichtblau, Carlos Gañán, Anja Feldmann, Oliver Gasser, Tobias Fiebig |
PAM | 7 |
| 2023 | You've Got Report: Measurement and Security Implications of DMARC Reporting
Md. Ishtiaq Ashiq, Weitong Li, Tobias Fiebig, Taejoong Chung |
USENIX Security Symposium | 3 |
| 2023 | "Oh yes! over-preparing for meetings is my jam :)": The Gendered Experiences of System AdministratorsabstractIn the system and network administration domain, gender diversity remains a distant target. The experiences and perspectives of sysadmins who belong to marginalized genders (non cis-men) are not well understood beyond the fact that sysadmin work environments are generally not equitable. We address this knowledge gap in our study by focusing on the ways in which sysadmins from marginalized genders manage their work in men-dominated sysadmin work spaces and by understanding what an inclusive workplace would look like. Using a feminist research approach, we engaged with a group of 16 sysadmins who are not cis-men via six online focus groups. We found that managing the impact of gender identity in the sysadmin workplace means demonstrating excellence and going above and beyond in system administration tasks, and also requires performing additional care work not expected from cis men. Furthermore, our participants handle additional layers of work due to gender considerations and to actively find community in the workplace. We found that sysadmins manage by going above and beyond in their tasks, performing care work and doing extra layers of work because of gender considerations, and finding community in the workplace. To mitigate this additional workload, we recommend more care for care work. For future research, we recommend the use of feminist lenses when studying sysadmin work in order to provide more equitable solutions that ultimately contribute to improving system security by fostering a just workplace. Mannat Kaur 0001, Harshini Sri Ramulu, Yasemin Acar, Tobias Fiebig |
Proc. ACM Hum. Comput. Interact. | 4 |
| 2023 | Heads in the Clouds? Measuring Universities' Migration to Public Clouds: Implications for Privacy & Academic FreedomabstractWith the emergence of remote education and work in universities due to COVID-19, the 'zoomification' of higher education, i.e., the migration of universities to the clouds, reached the public discourse. Ongoing discussions reason about how this shift will take control over students' data away from universities, and may ultimately harm the privacy of researchers and students alike. However, there has been no comprehensive measurement of universities' use of public clouds and reliance on Software-as-a-Service offerings to assess how far this migration has already progressed. We perform a longitudinal study of the migration to public clouds among universities in the U.S. and Europe, as well as institutions listed in the Times Higher Education (THE) Top100 between January 2015 and October 2022. We find that cloud adoption differs between countries, with one cluster (Germany, France, Austria, Switzerland) showing a limited move to clouds, while the other (U.S., U.K., the Netherlands, THE Top100) frequently outsources universities' core functions and services---starting long before the COVID-19 pandemic. We attribute this clustering to several socio-economic factors in the respective countries, including the general culture of higher education and the administrative paradigm taken towards running universities. We then analyze and interpret our results, finding that the implications reach beyond individuals' privacy towards questions of academic independence and integrity. Tobias Fiebig, Seda Gurses, Carlos Gañán, Erna Kotkamp, Fernando A. Kuipers, Martina Lindorfer, Menghua Prisse, Taritha Sari |
Proc. Priv. Enhancing Technol. | 1 |
| 2022 | Not that Simple: Email Delivery in the 21st Century
Florian Holzbauer, Johanna Ullrich, Martina Lindorfer, Tobias Fiebig |
USENIX ATC | 4 |
| 2022 | Security at the End of the Tunnel: The Anatomy of VPN Mental Models Among Experts and Non-Experts in a Corporate Context
Veroniek Binkhorst, Tobias Fiebig, Katharina Krombholz, Wolter Pieters, Katsiaryna Labunets |
USENIX Security Symposium | 2 |
| 2022 | "I needed to solve their overwhelmness": How System Administration Work was Affected by COVID-19abstractThe ongoing global COVID-19 pandemic made working from home -- wherever working remotely is possible -- the norm for what had previously been office-based jobs across the world. This change in how we work created a challenging situation for system administrators (sysadmins), as they are the ones building and maintaining the digital infrastructure our world relies on. In this paper, we examine how system administration work changed early in the pandemic from sysadmins' personal perspectives, through semi-structured interviews and thematic analysis. We find that sysadmins faced a two-sided crisis: While sysadmins' own work environment changed, they also had to react to the new situation and facilitate stable options to work online for themselves and their colleagues, supporting their users in adapting to the crisis. This finding embeds into earlier work on the connection between IT (security) work and the notion of 'care', where we substantiate these earlier findings with results from a repeatable method grounded in coordination theory. Furthermore, while we find that sysadmins perceived no major changes in the way they work, by consecutively probing our interviewees, we find that they did experience several counter-intuitive effects on their work. This includes that while day-to-day communication became inherently more difficult, other tasks were streamlined by the remote working format and were seen as having become easier. Finally, by structuring our results according to a model of coordination and communication, we identify changes in sysadmins' coordination patterns. From these we derive recommendations for how system administration work can be coordinated, ranging beyond the immediate pandemic response and the transition to any 'new normal' way of working. Mannat Kaur 0001, Simon Edward Parkin, Marijn Janssen, Tobias Fiebig |
Proc. ACM Hum. Comput. Interact. | 4 |
| 2021 | Out of Sight, Out of Mind: Detecting Orphaned Web Pages at Internet-ScaleabstractSecurity misconfigurations and neglected updates commonly lead to systems being vulnerable. Especially in the context of websites, we often find pages that were forgotten, that is, they were left online after they served their purpose and never updated thereafter. In this paper, we introduce new methodology to detect such forgotten or orphaned web pages. We combine historic data from the Internet Archive with active measurements to identify pages no longer reachable via a path from the index page, yet stay accessible through their specific URL. We show the efficacy of our approach and the real-world relevance of orphaned web-pages by applying it to a sample of 100,000 domains from the Tranco Top 1M. Stijn Pletinckx, Kevin Borgolte, Tobias Fiebig |
CCS | 3 |
| 2021 | SoK: A Framework for Asset Discovery: Systematizing Advances in Network Measurements for Protecting OrganizationsabstractAsset discovery is fundamental to any organization's cybersecurity efforts. Indeed, one must accurately know which assets belong to an IT infrastructure before the infrastructure can be secured. While practitioners typically rely on a relatively small set of well-known techniques, the academic literature on the subject is voluminous. In particular, the Internet measurement research community has devised a number of asset discovery techniques to support many measurement studies over the past five years. In this paper, we systematize asset discovery techniques by constructing a framework that comprehensively captures how network identifiers and services are found. We extract asset discovery techniques from recent academic literature in security and networking and place them into the systematized framework. We then demonstrate how to apply the framework to several case studies of asset discovery workflows, which could aid research reproducibility. These case studies further suggest opportunities for researchers and practitioners to uncover and identify more assets than might be possible with traditional techniques. Mathew Vermeer, Jonathan West, Alejandro Cuevas Villalba, Shuonan Niu, Nicolas Christin, Michel van Eeten, Tobias Fiebig, Carlos Gañán, Tyler Moore 0001 |
EuroS&P | 7 |
| 2018 | Investigating System Operators' Perspective on Security MisconfigurationsabstractNowadays, security incidents have become a familiar "nuisance," and they regularly lead to the exposure of private and sensitive data. The root causes for such incidents are rarely complex attacks. Instead, they are enabled by simple misconfigurations, such as authentication not being required, or security updates not being installed. For example, the leak of over 140 million Americans' private data from Equifax's systems is among most severe misconfigurations in recent history: The underlying vulnerability was long known, and a security patch had been available for months, but was never applied. Ultimately, Equifax blamed an employee for forgetting to update the affected system, highlighting his personal responsibility. In this paper, we investigate the operators' perspective on security misconfigurations to approach the human component of this class of security issues. We focus our analysis on system operators, who have not received significant attention by prior research. Hence, we investigate their perspective with an inductive approach and apply a multi-step empirical methodology: (i), a qualitative study to understand how to approach the target group and measure the misconfiguration phenomenon (ii) a quantitative survey rooted in the qualitative data. We then provide the first analysis of system operators' perspective on security misconfigurations, and we determine the factors that operators perceive as the root causes. Based on our findings, we provide practical recommendations on how to reduce security misconfigurations' frequency and impact. Constanze Dietrich, Katharina Krombholz, Kevin Borgolte, Tobias Fiebig |
CCS | 4 |
| 2018 | Cloud Strife: Mitigating the Security Risks of Domain-Validated Certificates
Kevin Borgolte, Tobias Fiebig, Shuang Hao 0001, Christopher Krügel, Giovanni Vigna |
NDSS | 2 |
| 2018 | In rDNS We Trust: Revisiting a Common Data-Source's Reliability
Tobias Fiebig, Kevin Borgolte, Shuang Hao 0001, Christopher Krügel, Giovanni Vigna, Anja Feldmann |
PAM | 1 |
| 2018 | Enumerating Active IPv6 Hosts for Large-Scale Security Scans via DNSSEC-Signed Reverse ZonesabstractSecurity research has made extensive use of exhaustive Internet-wide scans over the recent years, as they can provide significant insights into the overall state of security of the Internet, and ZMap made scanning the entire IPv4 address space practical. However, the IPv4 address space is exhausted, and a switch to IPv6, the only accepted long-term solution, is inevitable. In turn, to better understand the security of devices connected to the Internet, including in particular Internet of Things devices, it is imperative to include IPv6 addresses in security evaluations and scans. Unfortunately, it is practically infeasible to iterate through the entire IPv6 address space, as it is 2^96 times larger than the IPv4 address space. Therefore, enumeration of active hosts prior to scanning is necessary. Without it, we will be unable to investigate the overall security of Internet-connected devices in the future. In this paper, we introduce a novel technique to enumerate an active part of the IPv6 address space by walking DNSSEC-signed IPv6 reverse zones. Subsequently, by scanning the enumerated addresses, we uncover significant security problems: the exposure of sensitive data, and incorrectly controlled access to hosts, such as access to routing infrastructure via administrative interfaces, all of which were accessible via IPv6. Furthermore, from our analysis of the differences between accessing dual-stack hosts via IPv6 and IPv4, we hypothesize that the root cause is that machines automatically and by default take on globally routable IPv6 addresses. This is a practice that the affected system administrators appear unaware of, as the respective services are almost always properly protected from unauthorized access via IPv4. Our findings indicate (i) that enumerating active IPv6 hosts is practical without a preferential network position contrary to common belief, (ii) that the security of active IPv6 hosts is currently still lagging behind the security state of IPv4 hosts, and (iii) that unintended IPv6 connectivity is a major security issue for unaware system administrators. Kevin Borgolte, Shuang Hao 0001, Tobias Fiebig, Giovanni Vigna |
IEEE Symposium on Security and Privacy | 3 |
| 2017 | Something from Nothing (There): Collecting Global IPv6 Datasets from DNS
Tobias Fiebig, Kevin Borgolte, Shuang Hao 0001, Christopher Krügel, Giovanni Vigna |
PAM | 1 |
| 2017 | Static Program Analysis as a Fuzzing Aid
Bhargava Shastry, Markus Leutner, Tobias Fiebig, Kashyap Thimmaraju, Fabian Yamaguchi, Konrad Rieck, Stefan Schmid 0001, Jean-Pierre Seifert, Anja Feldmann |
RAID | 3 |