windows has a MAJOR IPv6 problem

Поделиться
HTML-код
  • Опубликовано: 26 сен 2024

Комментарии • 676

  • @LowLevel-TV
    @LowLevel-TV  Месяц назад +102

    no way haha anyway, you should go learn to code at lowlevel.academy (hehe)

    • @resist_or_die
      @resist_or_die Месяц назад +2

      way

    • @Kane0123
      @Kane0123 Месяц назад +16

      You’ve sold out man. Letting these dodgy sponsors into the channel…

    • @byronlefevre8266
      @byronlefevre8266 Месяц назад +1

      No way. Big if true

    • @Bro-trust-me
      @Bro-trust-me Месяц назад +2

      Why don't you use adblock?

    • @sarkybugger5009
      @sarkybugger5009 Месяц назад +1

      An IT guy that gets ads in his browser? WTAF? 👎

  • @sadface
    @sadface Месяц назад +1473

    "Nobody uses Edge in IE mode"
    *allow me to introduce 20 year old corporate web apps*

    • @twqzjsidIsndusiakdixisqjeksixi
      @twqzjsidIsndusiakdixisqjeksixi Месяц назад +23

      Lemme introduce Opera 5, Oracle shittiest app that runs on IE mode.

    • @pheonixmmkc
      @pheonixmmkc Месяц назад +9

      This is 100% true

    • @donniedarko7751
      @donniedarko7751 Месяц назад +3

      I was gonna say.

    • @Chiramisudo
      @Chiramisudo Месяц назад +1

      I can already smell the next big wave of ransomware. 😭

    • @test-rj2vl
      @test-rj2vl Месяц назад +5

      Oracle forms application running as a Java applet in IE is always fun thing to work with..... And the 2nd best thing is having like 2 page manual on intranet how to hack it to work....

  • @mx338
    @mx338 Месяц назад +725

    A ton of people are still using Edge in IE mode, and they are all part of large companies.

    • @benargee
      @benargee Месяц назад +27

      So ultimately the end user is safe but isn't because a company that has their personal data is gonna get hacked.

    • @guusqwertyuiopasdfgh
      @guusqwertyuiopasdfgh Месяц назад +4

      Usually you set this up to only open up certain pages in IE mode and not all pages which makes it much harder to exploit. At least according to my experience

    • @CrispyCircuits
      @CrispyCircuits Месяц назад +3

      @@benargee And if you know nothing about computers, you are going to copy those settings at home, "because they work"

    • @trail.blazer
      @trail.blazer Месяц назад +5

      If configured correctly then Edge will not use IE mode except for specific sites that are put in to a list of sites that require IE mode, such as an intranet site. If not using a centrally managed enterprise list of sites for Edge in IE mode then sites in the browser managed list expire after 30 days. Clicking a random link is somewhat unlikely to send you to Edge in IE mode.

    • @ElvenSpellmaker
      @ElvenSpellmaker Месяц назад +3

      I'd wager a lot of people who have Crowdstrike have Edge in IE mode...

  • @jonathancrowder3424
    @jonathancrowder3424 Месяц назад +505

    LLL: "no one uses IE mode"
    Banking companies / check scanner systems: 👀

    • @voyager-tc9dz
      @voyager-tc9dz Месяц назад +13

      those use the original IE on Windows XP, and no, I'm not joking, just have a closer look at your local ATM, you will be surprised ...

    • @unmanaged
      @unmanaged Месяц назад +3

      I could not believe that a bank is still using IE mode for scanning checks for payroll ... its so odd ... I had to support this garbage

    • @JoaoPedroDeOliveiraAderaldo
      @JoaoPedroDeOliveiraAderaldo Месяц назад +5

      Once my mother was using an ATM here in Brazil and when she finished what she was doing the ATM showed a windows xp shutting down screen.

    • @psylenced
      @psylenced Месяц назад

      I was so happy when they moved from IE6 -> IE8.

    • @dooorrr
      @dooorrr Месяц назад

      Yeah, an average person has no idea what goes on in their bank, Edge IE mode is pretty modern compared to the 100s of legacy mainframe systems.
      Also as many people already stated, no way you gonna open a wrong link in IE mode unless something is wrong on org settings level.

  • @madezra64
    @madezra64 Месяц назад +1247

    "Nobody uses Edge or Edge in IE mode" Oh.. sweet summer child...

    • @darkshardrex7589
      @darkshardrex7589 Месяц назад +99

      @@DefinetlyFamillyFriendly I work for a large enterprise in health care... we have a IE mode entries in our EMSites list. This is very common in enterprise for support of older software or internal websites.

    • @eduardomiranda7640
      @eduardomiranda7640 Месяц назад +47

      Some of the most widespread SCADA systems feature web servers that can only be accessed with IE

    • @Anonymous-m9f9j
      @Anonymous-m9f9j Месяц назад +100

      So many tech RUclipsrs, especially security focused RUclipsrs have this cringe ignorance, it’s a lack of real world experience I think.

    • @madezra64
      @madezra64 Месяц назад

      @@DefinetlyFamillyFriendly Most EMR and EHR (if not most, it’s still a LOT of) only works on IE. Honest to god it destroys my soul every time I have to configure a Device Configuration profile in InTune for a client that opens up and enforces Edge in IE mode, adding all the providers URLs to the trusted sites list… Madness…
      Edit: rereading my comment, it sounds like I am trying tell you something you don’t already know. So my bad, was just a general statement

    • @2rx_bni
      @2rx_bni Месяц назад +10

      My last employer only deprecated that because they HAD to, not because they wanted to. Required an entire backend change.

  • @АфанасийШереметьев-б5ч

    Microsoft, this is seventh time in a row you're showing remote code exploit to the class

    • @nomore6167
      @nomore6167 Месяц назад +3

      "Microsoft, this is seventh time in a row you're showing remote code exploit to the class" - Somebody once told them to do what they're good at, and they took that advice to heart. The problem for us is that they're good at being insecure.

  • @TheRealBigYang
    @TheRealBigYang Месяц назад +140

    People have no idea how much of the world runs in legacy mode. Edge IE is one of the requirements for the world to run. Large companies usually only change what makes money. We are still migrating to github at work

  • @SomeDudeInBaltimore
    @SomeDudeInBaltimore Месяц назад +184

    "Nobody uses Edge in IE mode"
    My career installing electronic security and servicing 10+ year old PoE cams needing ancient obscure ActiveX plugins to manage them says otherwise.

    • @ZipplyZane
      @ZipplyZane Месяц назад +1

      Do those actually run on the wider Internet? Because I know people use IE mode for intranet stuff, but a website designed for IE mode would fail for 95% of users.

    • @devrim-oguz
      @devrim-oguz Месяц назад

      Or silverlight…

    • @billbuyers8683
      @billbuyers8683 Месяц назад

      @@SomeDudeInBaltimore ActiveX, yeah that was too many Exes ago to remember

  • @zyplocs
    @zyplocs Месяц назад +426

    It's funny you state that no one uses Edge and especially not Edge in IE mode - meanwhile I work for a large, well-known corporation whose handful of extremely important internal applications are incompatible with Edge and can only be run in IE mode...

    • @gulagamelee4804
      @gulagamelee4804 Месяц назад +24

      Had that with infrastructure equipment like switches in really big companies. Their stuff was so ancient that you either had to download a reaaaaaaaaaaaaaaaaaaaaaaaaaaaaaallly old firefox version or use edge in ie mode

    • @bouboul3597
      @bouboul3597 Месяц назад +1

      same...

    • @syrslava705
      @syrslava705 Месяц назад +2

      The fnсk is the large well-known corporation whose handful of extremely important internal applications REQUIRE IE IN 2024. Clients need to know XD

    • @MelodicMurder
      @MelodicMurder Месяц назад +4

      @@zyplocs is it Delta or Cloudstrike? 😂

    • @trail.blazer
      @trail.blazer Месяц назад +3

      If configured correctly then Edge will not use IE mode except for specific sites that are put in to a list of sites that require IE mode, such as an intranet site. If not using a centrally managed enterprise list of sites for Edge in IE mode then sites in the browser managed list expire after 30 days. Clicking a random link is somewhat unlikely to send you to Edge in IE mode.

  • @dk9469
    @dk9469 Месяц назад +115

    2:25 „it’s just another Tuesday for Microsoft“ xD

    • @mgancarzjr
      @mgancarzjr Месяц назад +9

      _For you, the day Microsoft ruined your security was the most important day of your life. But for me, it was Tuesday._

    • @sansmoraxz
      @sansmoraxz Месяц назад +2

      At least it ain't Friday.

  • @thedausthed
    @thedausthed Месяц назад +94

    A major bug in the TCP/IP stack is not at all surprising, Microsoft is the same company that never bothered to fix a bug in Windows 8.1 that would cause the TCP/IP stack to break after about 30 minutes if you used a Wi-FI driver compiled against Windows 8.1.

    • @ArkenGAMES
      @ArkenGAMES Месяц назад +3

      What does compiling against mean? Compiling the driver to run on a specific version of windows? Also shouldn't there be tons of Wi-Fi drivers out there from different Wifis manufacturers?

    • @mattmurphy7030
      @mattmurphy7030 Месяц назад +7

      @@ArkenGAMESeach version of windows has its own SDKs (DDKs in the case of drivers)

    • @ArkenGAMES
      @ArkenGAMES Месяц назад +4

      @@mattmurphy7030 I would have thought that windows has pretty good backwards compatibility and assumed that you don't have to maintain the same driver across multiple windows versions. That must suck.
      So there is a single global wifi driver pre installed in windows 8.1 that works for all wifi manufacturers and had that bug you were talking about?

    • @int16_t
      @int16_t Месяц назад +5

      There's also the WSAPoll bug and they didn't care until Win10 was released.

    • @ThePlayerOfGames
      @ThePlayerOfGames Месяц назад +7

      ​@@ArkenGAMESnah it's that Microsoft broke the dependencies that WiFi device manufacturers use to build the firmware blobs into installable Windows drivers so that when the driver installs regardless of the manufacturer it will break
      Another reason the driver should be presented at the kernel level and treated sincerely as such, rather than slapping them on willy nilly

  • @DoorThief
    @DoorThief Месяц назад +32

    "Nobody uses Edge in IE mode"
    Laughs in Corporate IT

  • @ThioJoe
    @ThioJoe Месяц назад +10

    Me who always disables IPV6 because the long weird address is annnoying 😎

    • @kodirovsshik
      @kodirovsshik Месяц назад +1

      mfw 127.0.0.1 instead of ::1 (the latter is longer and more annoying)

  • @kissgergo5202
    @kissgergo5202 Месяц назад +110

    For some reason I read the title as "microsoft patches IN extreme vulnerability" and I wasn't even surprised I was just curious what it was

    • @w_rnz
      @w_rnz Месяц назад +12

      @@kissgergo5202 underrated comment

    • @arcanealchemist3190
      @arcanealchemist3190 Месяц назад +2

      its their new crypto AI skibidi toilet update. it buzzwords your software and such

  • @SterileNeutrino
    @SterileNeutrino Месяц назад +10

    "Yes, master. They left an interpreter in the TCP/IP stack that can be fed instructions directly from the packet"
    "Good. Good."

  • @scotts918
    @scotts918 Месяц назад +47

    IPv6 is disabled on my machine because it wouldn't play nicely with Outlook... So a bug in one product, saved me from a security vulnerability in another 😅

    • @howelon3099
      @howelon3099 Месяц назад

      Turning it off actually doesnt prevent the bug from working just make sure that your windows is up to date

    • @erikb4407
      @erikb4407 Месяц назад +1

      @@howelon3099 7:44 So you interpreted "Systems are not affected if IPv6 is disabled on the target machine." to mean "Systems *are* affected even if IPv6 is disabled on the target machine." or am I missing something...

    • @howelon3099
      @howelon3099 Месяц назад +2

      @@erikb4407 Well when I read the original writeup it said even if ipv6 is disabled the packets bypass the firewall anyways and will execute the said packets/code. Maybe this is referring to something else?

    • @Corteum
      @Corteum Месяц назад

      @@howelon3099 If you look at the original writeup on the microsoft website for this specific CVE, it says under *Mitigations* _"Systems are not affected if IPv6 is disabled on the target machine."_

  • @DrDarkRyder
    @DrDarkRyder Месяц назад +11

    I know it isn't really relevant to to the discussion at hand, but saying IPv6 has "billions and billions of addresses" (9:48) is just a *crazy* understatement of how many addresses IPv6 has. It's IPv4 that has "billions AND billions" - about 4.3 billion, in fact - while IPv6 is more like "billions OF billions… OF BILLIONS… of addresses *for each IPv4 address*". If you assigned an entire IPv4 worth of addresses, to every human who has ever lived, once a second, it would take about 21 BILLION YEARS (or about time and a half the current age of the universe) to exhaust IPv6. That is a BIG address space!

  • @kensmith5694
    @kensmith5694 Месяц назад +22

    Fun fact: There are still some computers that are running code written in COBOL.
    Be careful what you say nobody does

    • @Sypaka
      @Sypaka Месяц назад +2

      The IRS does.

    • @absurdengineering
      @absurdengineering Месяц назад

      Fun fact: Another language in the “BOL” tradition - SNOBOL4 and SNOBOL5 (Oregon) has ancient syntax but awesome feature set for text data extraction and parsing, and is very much useful today. It may have COBOL vibes but wowzers is it miles better than trying to use regexes to extract data from non-regular-language input (CrowdStrike cough cough).

    • @kensmith5694
      @kensmith5694 Месяц назад

      @@absurdengineering I just looked up SNOBOL. I knew of its existence but not the nature of the language.

    • @mor4y
      @mor4y Месяц назад

      @kensmith5694 there's a couple of banks near me offering damm good money for students to do COBOL, apparently saying their last few programmers are in their 60's and 70's(!), and have returned to work after retiring some years ago. They paid for eye surgery for one lol 😆

    • @mor4y
      @mor4y Месяц назад

      Oh yea, if you want a idea how dire their situation is, heck a cold winter could finish off their COBOL team 😬 the local Unis allow them to come it at fresher week and say to the Comp Sci students can you see yourself doing this? There's a paid 'apprenticeship' right this way if you do.... but every week that you learn more about new stuff you get further away from where we need you to be, so come now
      No other companies get that opportunity

  • @Devvbot
    @Devvbot Месяц назад +71

    Heard him say "noone uses edge" thats all I need to know he hasnt a clue about enterprise.

  • @Bob-wz4my
    @Bob-wz4my Месяц назад +81

    Control systems use Microsoft Edge in IE mode.

    • @Kane0123
      @Kane0123 Месяц назад +8

      Plenty of things use it in the enterprise space… “we either have to upgrade the LOB system and pay a ton of cash… or set GPO to automatically open these in IE Mode.”

  • @francescachen4530
    @francescachen4530 Месяц назад +34

    Nice ! If you have time - try to reverse-engineer the faulty (bugged) DLL, will ya ? Diff-compare the old and the patched, unleash our unholy couple - Ghidra and x64dbg - on them ... and lets see whether it was a bug ... or a feature? Should be a good watch :)

  • @min3craftpolska514
    @min3craftpolska514 Месяц назад +9

    2024: The year of IT crazyness - vulnerabilities, outages, everything

  • @jagdtigger
    @jagdtigger Месяц назад +8

    10:21 I respectfully disagree, every reputable brand router will have the same defualt deny rule for IPv6 as they have on IPv4 in the firewall config.

    • @kneesnap1041
      @kneesnap1041 Месяц назад

      The problem is that the words "reputable" and "router" usually do not belong in the same sentence

    • @jagdtigger
      @jagdtigger Месяц назад

      @@kneesnap1041 Yeah sure, lets nit-pick about semantics while it is clear i simplified my point so normies can understand it......

    • @kneesnap1041
      @kneesnap1041 Месяц назад +1

      @@jagdtigger perhaps my point was missed, I was hoping to point out that users often do not get a choice what router they can use, I sure don't. I have 2 ISPs in my area, and one is DSL and would go out on an hourly basis, and when it did work it had less than 1MBPS download.
      So, I've realistically got only one option for my ISP. They refuse to service any router which isn't theirs, and their routers are extremely locked down. I don't have an option

    • @jagdtigger
      @jagdtigger Месяц назад

      @@kneesnap1041 You can always hook up yours after the ISP junk.....

  • @espfan9841
    @espfan9841 Месяц назад +5

    Interesting fact: MS at some point took the TCP/IP stack from OpenBSD because they lost knowledge of their own sourcecode. Yet they still fucked up something robust anyway.
    There is also a story that they asked the Samba project to help them with their SMB protocol code because they also lost the knowledge. They refused because MS wasn't willing tho share information in the past.

  • @Vifnis
    @Vifnis Месяц назад +8

    1:40 "no one uses Edge"
    I would like to point out -- for all it's flaws... *MS* does a *FANTASTIC* job with the *READ ALOUD* function it is TOP TIER ! ! !

    • @Nerd3927
      @Nerd3927 Месяц назад +1

      yep, use that too, to check on my own documents. You can read across missing words, but hearing it read aloud you spot all the things the spelling checker misses.

    • @niv8880
      @niv8880 Месяц назад

      @@Nerd3927 Hmmmmmm... I need to check this out

    • @nikolatasev4948
      @nikolatasev4948 Месяц назад

      The Edge tab management is the best. I wish Firefox could do that.

  • @JohnWilliams-gy5yc
    @JohnWilliams-gy5yc Месяц назад +5

    Crowdstrike: The "Patch Tuesday" is not even close to "Stranded Friday."

    • @nomore6167
      @nomore6167 Месяц назад +1

      "Crowdstrike: The 'Patch Tuesday' is not even close to 'Stranded Friday.'" - I can't say I agree with that. I would much rather have my computer crash and refuse to boot than have a malicious actor take control of it remotely, especially if they can do so without any user interaction.

  • @im1random263
    @im1random263 Месяц назад +81

    Can't believe that there are still people who don't use an adblocker lol

    • @rowbart3095
      @rowbart3095 Месяц назад +13

      especially someone who is allegedly so computer literate

    • @VitisCZ
      @VitisCZ Месяц назад +4

      ​@@rowbart3095it's probably on purpose to support creators or websites

    • @Brahvim
      @Brahvim Месяц назад +1

      @@VitisCZ Or rather, it's because Ed is actually in a Windows VM to avoid getting his real fingerprinted get identified so he can protect his privacy.

    • @Brahvim
      @Brahvim Месяц назад

      Could it be that he was running a Windows VM for privacy reasons? *_Resisting_* fingerprinting is its own way to getting fingerprinted, LOL.

    • @Hmm-p9t
      @Hmm-p9t Месяц назад

      I don't either. I'd rather have my data be stolen by microsoft, google, and other large companies than some unknown browser extension. I don't have ANY browser extension at all. I used to have quite a few and a well-known one in them got hacked one day and I believe it stole my credentials from sites. So I had to change my credentials and reset my computer. Chrome extensions can't really be trusted. The Chrome web store, most obviously, doesn't work like the google play store. Nothing is reviewed on there and there are no constraints over what the extension can access, obviously because most extensions need to access site data such as dark mode readers, and ad blockers, for example.

  • @catoleg
    @catoleg Месяц назад +23

    "Nobody uses Edge or Edge in IE mode" I think Ed was speaking to us, viewers.

  • @apexberserker3057
    @apexberserker3057 Месяц назад +6

    correction (5:10): the OSI model is a reference model and not actually used in practice. the TCP/IP model is used in practice, though OSI is taught as it's a good entry point into networking.

  • @tranthien3932
    @tranthien3932 Месяц назад +16

    LLL: "No one uses Edge in IE mode."
    The comments section: "You just activated my trap card!"
    Large companies: "Guess I'll die"
    Banks: "First time?"
    Me: *grab popcorn*

  • @richardokeefe7410
    @richardokeefe7410 Месяц назад +20

    The figures I've seen say that Edge has 5% of the browser share. It simply isn't true that "nobody uses it".

    • @trail.blazer
      @trail.blazer Месяц назад +4

      Not just Edge, but Edge in IE mode. That means it is really running Internet Explorer with an Edge wrapper.

    • @BlueBetaPro
      @BlueBetaPro Месяц назад

      @@trail.blazer I doubted that would be true and that it would probably just emulate IE like changing the user agent header and a bunch of other compatibility settings but you're actually right it ships with the "Trident MSHTML" browser engine that was first released in 1997, and apparently that means a bunch of new web standards totally wont work. Microsoft is wack. I do not envy anyone who has to maintain software made for IE mode, must be a pain in the ass.

    • @abcdqwerty3562
      @abcdqwerty3562 Месяц назад +4

      @@BlueBetaPro Is it really Microsoft that is wack? The reason Microsoft is providing it is that there are ancient pieces of software only compatible with it. So it’s the enterprises using such software that are ‘wack’, if anything.

    • @BlueBetaPro
      @BlueBetaPro Месяц назад

      @@abcdqwerty3562 I know it's not wack to provide the backwards compatibility in the first place but it's the way that they went about it from a technical perspective that sounds wack. From a web development perspective it's really incompatible with modern standards despite being in a modern browser, and from a software development perspective it's lazy to include something that I assume is quite a large binary/library into the application just to provide a little bit of backwards compatibility.

    • @ThePlayerOfGames
      @ThePlayerOfGames Месяц назад +1

      The number of users is inflated as Microsoft force edge to launch by overriding default settings
      Plus Windows 11 silently uses edge to run user-implied search requests

  • @bobster852
    @bobster852 Месяц назад +11

    Correction regarding the IPv6 reach-ability topic. The true protection we get from NAT is the statefulness capability that it forced on dinky home routers. that same statefulness also protects IPv6 hosts, regardless of whether they have an internet routeable address or not. If the connection didnt initiate from my host, it doesnt matter that you can guess my IP. if it _did_ initiate from my host NAT won't protect me from those dodgy packets.
    This particular vuln would be most effective in places where a host is not behind a firewall or where the malicious actor is already behind the firewall. roaming wifi, some cellular networks, weak govt agency networks, that sort of thing

    • @ivok9846
      @ivok9846 Месяц назад

      in other words: how would these "carefully crafted" malicious ipv6 packets even reach my pc if adsl modem/router has all ports closed? and pc has firewall.
      in that case i have to click something, somewhere...which is same as openiong suspicious mail attachments....
      so....not really 9.8 of 10 vulnerability with all those factors.
      and...well....i'm not on ipv6 anyway.....i hear half the germans are....hehe.....

    • @bobster852
      @bobster852 Месяц назад

      @@ivok9846 IMO it's still a 9.8. I don't think CVEs should assume anything about local networks when assessing risks. But for the rest of us, its an important reminder that stateful firewalls are useful, IPv6 does not equal direct internet access and maybe stay away from MS Windows.

    • @BrendonGreenNZL
      @BrendonGreenNZL Месяц назад

      That assumes the dinky router in question even bothers to run a firewall on IPv6.

    • @ivok9846
      @ivok9846 Месяц назад

      @@BrendonGreenNZL are you on ipv6?

    • @MikeKrasnenkov
      @MikeKrasnenkov Месяц назад +1

      NAT can be punched through if you spoof the packet so that it matches one of the opened connections, both for ipv4 and 6.

  • @Hezeri
    @Hezeri Месяц назад +1

    "Systems are not affected if IPv6 is disabled on the target machine."
    Oh, so basically every Windows machine I've had to touch is already unaffected. IPv6 is one of the first things I disable on any machine and I have never needed it in local network environment.

  • @AttilaAsztalos
    @AttilaAsztalos Месяц назад +18

    Except unless your Grandma is somehow still managing to use XP or Win7, she IS PATCHING, whether she bloody likes it or not, pretty much every time she turns on her computer.

    • @burtburtist
      @burtburtist Месяц назад

      @@AttilaAsztalos ?

    • @SreenikethanI
      @SreenikethanI Месяц назад

      @@burtburtist watch from 3:54 onwards

    • @burtburtist
      @burtburtist Месяц назад

      @@SreenikethanI i mean how is someone just using whatever came with their pc patching, the os stopped getting patches, i dont imagine them manually going through the kb catalogue, just disabling update notifications

    • @ZipplyZane
      @ZipplyZane Месяц назад

      @@burtburtist Because Windows automatically updates (and forces restarts), and you cannot override this without knowing a decent bit about computers.
      The only way a Windows 10+ computer wouldn't be updating is if it isn't online. But then it isn't vulnerable.

    • @burtburtist
      @burtburtist Месяц назад

      @@ZipplyZane thanks for the actual answer, i didnt consider it working as intended i guess, the windows 7 failing to update bug seems pretty common, and im pretty sure 7 was no longer getting updates anyway, forgot if the update to 8 then 10 or whatever was truly automatic but its been a hot minute since ive run 7 myself.

  • @lauram5905
    @lauram5905 Месяц назад +6

    I used to work for a company that was using IBM's SAP HR platform which required all the computers to be versions of windows that still supported full IE (so it was Windows 7 across the board), not to mention it had an antique Java backend

  • @bocote3119
    @bocote3119 Месяц назад +18

    Unrelated but, adblockers are your best friends

  • @UNcommonSenseAUS
    @UNcommonSenseAUS Месяц назад +52

    Somebody found the cia's backdoor & thry had to cover their asses

    • @originzz
      @originzz Месяц назад +2

      If it were that easy they wouldn't be the CIA

    • @UNcommonSenseAUS
      @UNcommonSenseAUS Месяц назад

      @@originzz one of their access paths likely Waa discovered.
      Let's not forget that your:
      CPU
      Gpu
      Bios
      Cables
      TV
      Phone
      Entire life is backdoored. There is no privacy, soon we will see covid & 1940s esque neighbours snitching on neighbours and anyone they can in order to win favour with big brother.
      Dangerous times ahead

  • @byAnArgentinian
    @byAnArgentinian Месяц назад +6

    I always have ipv6 disabled by default. There's a lot of privacy and security concerns about being directly out with an unique address.

    • @RoddyDev
      @RoddyDev Месяц назад +2

      firewalls exists for that. and NAT for IPv4 is a hack and was never meant for security.

    • @byAnArgentinian
      @byAnArgentinian Месяц назад

      @@RoddyDev It was not, but it's a by product of the workaround.

    • @BrendonGreenNZL
      @BrendonGreenNZL Месяц назад

      IPv6 also has an implementation of private-enhanced addresses; whereby your OS can use unique, randomly generated addresses for different sessions.

  • @geweurzgurke
    @geweurzgurke Месяц назад +11

    Well shows how little IPv6 is used even after 25 Years😜

    • @collin4555
      @collin4555 Месяц назад +4

      Any day now!

    • @ElectronicInspiration
      @ElectronicInspiration Месяц назад +7

      2025 will be the year of IPv6!!!

    • @clashcon11
      @clashcon11 Месяц назад +3

      NAT cancel IPv6

    • @nickwallette6201
      @nickwallette6201 Месяц назад +2

      Doing a ping-sweep on IPv6 is a little like the SETI mission statement. There's gotta be somebody out there somewhere.... right?
      I guess bounds-checking code in the IPv6 stack is down there on the priority list, when having malformed packets hurled randomly at your machine from the ether would be an event so novel that it might inspire the plot of a science fiction movie.

    • @brandyballoon
      @brandyballoon Месяц назад +1

      @@clashcon11 "NAT cancel IPv6" This. The problem it was designed to solve no longer exists.

  • @nomore6167
    @nomore6167 Месяц назад +1

    So, in other words, to take control of a Windows system which has IPv6 enabled, an attacker simply needs to know the IPv6 address of a target machine and send a specially-formed packet (or series of packets) to it. The saddest part of this is not that this vulnerability exists, but rather that it's not surprising. Microsoft (and all other companies) needs to either fire all of its programmers for negligence or stop releasing software until they patch all of the existing security vulnerabilities and audit the software to find all vulnerabilities that are currently unknown (and fix them, too). It's infuriating that virtually nobody who writes software thinks of security as a priority. Security should be the top priority, far ahead of performance and "how quickly can we get this product released".

  • @bobsock8718
    @bobsock8718 Месяц назад +49

    Hello, I'm just here to flex on most people here and say that I'm using Linux even though no one asked me.

    • @mikerope5785
      @mikerope5785 Месяц назад +12

      Arch Linux user confirmed.

    • @temposparkz
      @temposparkz Месяц назад

      Plot twist they actually use windows 11 jk

    • @AntonioZL
      @AntonioZL Месяц назад +5

      I use Arch, btw.

    • @dazealex
      @dazealex Месяц назад +4

      Does using a Mac count? Nobody asked me either. I'll go back to my over paid walled garden... Sorry.

    • @klukva3296
      @klukva3296 Месяц назад

      Surely linux have 0 vulnerabilities

  • @scaptal
    @scaptal Месяц назад +6

    Hey, Low level learning, just wanted to inform you that, on your academy website, the original price in the price discount for lifetime access is incorrect (or at least, it states that the normal price is 197 and the new price is 319, which would certainly push me to wait till September 2nd ;p)

  • @charliecharliewhiskey9403
    @charliecharliewhiskey9403 Месяц назад +1

    Plenty of people use Edge. And even those who don't, still have times where they use edge, because windows continues defaulting links into Edge regardless of your chosen browser. And as others have said, there are many corporates that still rely on legacy IE mode for Edge. Saying "noone uses Y" is weird in a world where Southwest Airlines was able to escape the Crowdstrike issue solely because their systems are all Windows 3.1 or 95 and where banks are still running Fortran-based systems.

  • @privacyvalued4134
    @privacyvalued4134 Месяц назад +1

    So...everyone's home computers in the U.S. are safe. That's because the major U.S. ISPs (Comcast, Cox, CenturyLink, Spectrum, etc.) have been dragging their feet on IPv6 deployments since forever and have zero incentive to do a full nationwide rollout. The only truly affected entities in the U.S. are Windows servers in the cloud that got assigned both IPv4 and IPv6 addresses, which amounts to two classes of affected users: "Large enterprises paying ridiculous sums of money to host their stuff on Azure" and the government. Everyone else is largely unaffected.

  • @TSgotstolengoddamm
    @TSgotstolengoddamm Месяц назад +1

    When he stated that the extreme vulnerability is related to ipv6 i laughed as i always disablr that on every machine i get :)

  • @firetroll91
    @firetroll91 Месяц назад +13

    As an IPv6 stan this saddens me! Knee jerk reaction will be to turn off IPv6 and never turn it back on.
    IPv6 does have a private address range. Hopefully router manufacturer default will be to use these addresses and not a public addresses for your LAN
    Link-Local addresses are a god send when a remote device gets replaced with a spare and you get the call that it's not working.

    • @Lue30499
      @Lue30499 Месяц назад +11

      No, please. Do not use IPv6 private ranges. They are there for a legacy reason. Your router should use DHCP-PD to ask for a range from your ISP. Then your router will announce that range via SLAAC to the internal networks. IPv6 is designed to not need DHCP server.
      The concept of public v private is a characteristic of your firewall. Your internal networking being publicly routeable doesn't mean they are publicly accessible.

    • @nickwallette6201
      @nickwallette6201 Месяц назад

      @@Lue30499 I will never, ever understand this ridiculous notion.
      "Let's not have private addresses anymore! YAY! Everyone is directly on the Internet!" and it's equally daft companion ... "NAT is not security!"
      Except _it literally is._ If you're not reachable directly via the Internet, you are not vulnerable to exploits that attack you ... directly ... from the Internet. The route just does not exist.
      "So use a firewall that blocks incoming traffic."
      And that's fine. _If you do it._ With IPv4, and the near-ubiquitous usage of NAT imposed by the IP shortage, there was basically no choice. Everyone was behind a one-way filter by a matter of course. With IPv6 ... eh. It's optional. The problem with that, of course, is that.... _it's optional_ ... and therefore, it _will_ be turned off. (Or just never turned on.) More to the point, you won't necessarily know, because it works either way.
      IPv6 has gazillions of IPs. There's no need to conserve. But that doesn't mean NAT isn't still a really good *layer* to have in the security stack. Removing it from conventional network design was the dumbest freakin thing about IPv6. And there are a lot of dumb things about IPv6.

    • @lassipulkkinen273
      @lassipulkkinen273 Месяц назад +7

      How can you be an "IPv6 stan" and advocate for IPV6 NAT?

    • @HaveYouHeardOfManedWolves
      @HaveYouHeardOfManedWolves Месяц назад

      ​@@Lue30499what meaningful difference does being publicly routable make if it doesn't allow packets the user may not have expected or prepared for to reach the device?

    • @brandyballoon
      @brandyballoon Месяц назад

      @@lassipulkkinen273 I'd take everything said by someone who's username contains "troll" with a grain of salt.

  • @seansingh4421
    @seansingh4421 Месяц назад +2

    Microsoft having severe RCE vulnerabilities ? And the sky is blue

  • @christianalvarado528
    @christianalvarado528 Месяц назад

    I thicked ever insecurity box:
    - A stupidly large number of open ports.
    - Having SMB (v1) enabled all the time.
    - Turning off antivirus always.
    - Questionable custom Firewall rules.
    Turns out randomly choosing to disable IPv6 would actually save my ass.

  • @geroffmilan3328
    @geroffmilan3328 Месяц назад +1

    So many comments about Edge & IE when there's a CVSS 9.8 RCE in TCP/IP.
    Corporate machines will get patched pretty quick, the concern will be those "unpatchable" devices, since we need to assume this bug has existed in the codebase of older OS, IPv6 is fully routabble, edge security may not be blocking the affected traffic, and patch reversing is a whole thing for motivated attackers & curious minds.

  • @darkfox2401
    @darkfox2401 Месяц назад +1

    Edge is Also a background process windows uses to operate.
    so you don't have to use there browser to lose everything.

  • @pixselious
    @pixselious Месяц назад

    Can we please have a break from worldwide critical IT messups 😩😩😭 I’m gonna cry

  • @bokami3445
    @bokami3445 Месяц назад +1

    The problem is that hackers use these patches to see what Microsoft is patching and then reverse engineer and/or start investigating the code that is being patched and discover how to use the exploit. I give it a few days before the IPv6 TCP/IP stack *is* being used to exploit systems in the wild. Patch or disable IPv6 on your NIC interfaces NOW!

  • @mhdm
    @mhdm Месяц назад +8

    As a security researcher you should set a good example and use an ad blocker.

  • @Tabu11211
    @Tabu11211 Месяц назад +2

    When ,"I have your ip" means something haha

  • @cancer5895
    @cancer5895 Месяц назад +1

    pause for "7 days" saves me again

  • @Tenetri
    @Tenetri Месяц назад +26

    Pv6 security is more important than I thought! This bug sounds wild - gotta go patch Windows now. Keep up the great vids!

    • @felixhex
      @felixhex Месяц назад

      @@Tenetri it is, also take a look at the android security bulletin, yeah, it's udp in general, buuuuut, probably easier to exploit with ipv6, there was an unauthenticated, remote code execution in Android's network stack, too

    • @ivok9846
      @ivok9846 Месяц назад

      plot twist: you're not on ipv6, just like most of the planet....

  • @rifle
    @rifle Месяц назад +1

    1:40 I can't speak for everyone, but there are some systems I have worked with that still require the compatibility mode for their web app to function, and this is in Health Care, although it may not be many, the impact that could have on patient privacy needs to be taken into consideration

  • @Lukeff7
    @Lukeff7 Месяц назад

    Love your channel, I am fairly technical due to my career and interests in computers and so I enjoy how you recap stuff, explain stuff but also don’t go so far as sucking eggs. Subscribed!

  • @mytechnotalent
    @mytechnotalent Месяц назад

    This is a huge deal. Thank you for this. I was hoping to catch you at DEFCON but hopefully next year!

  • @Josh4x4
    @Josh4x4 Месяц назад

    I’ve never heard IPv6 explained so succinctly.👏👏👏

  • @wkrick
    @wkrick Месяц назад +6

    Unless I'm mistaken, a webserver can force edge into IE compatibility mode with http headers. So if a user goes to such a site while using Edge and clicks a malicious link, bad things can happen.

    • @Electro-tw9um
      @Electro-tw9um Месяц назад

      It depends, there's a setting to disallow that.

  • @guymenashe6856
    @guymenashe6856 Месяц назад

    Love your security technical reviews !!❤
    I think it would also be cool if you would do this as a series about Snowdens leaks

  • @jenpsakiscousin4589
    @jenpsakiscousin4589 Месяц назад +1

    I still use win7, I don’t get to participate in patch Tuesday anymore

  • @coholmes-k3c
    @coholmes-k3c Месяц назад +1

    Companies usually use exclusively microsoft edge….

  • @Oxxygen_io
    @Oxxygen_io Месяц назад

    well a quick google says you get roughly 2.5 pow(21) IP addresses per grain of sand in sahara, still way way to big to visualize.
    given that 7506320 grains of sand per sqf, and average depth of sand is 200feet.
    Some large numbers like this, what is understandable is that we no longer need NAT :D

  • @endunry
    @endunry Месяц назад +1

    "So you and i can use our PC in a safer way"
    *laughs in Linux*

  • @Wkaelx
    @Wkaelx Месяц назад

    every single day, every day, every week there is a new zero day exploit a new data leak, bro whats happening

  • @howardelton6273
    @howardelton6273 Месяц назад +2

    Many companies use Edge on their managed operating environments (MOE) for Windows Clients and indeed Servers, and in fact we actively have been removing Chrome due to all of the security vulnerabilities that is was getting compared to Edge (issues not related to the common Chromium compoent). When you have to do regular patching cycles and off-cycle urgent securty patching for many different software tools (Microsoft, Google, Adobe etc), it makes sense to consolidate the number of update points if you can, without impacting the users' ability to work effectively. It's more efficient and easier to maintain. No real need for Chrome in a Microsoft Azure environment, for example, unless you have some wierd software that is somehow dependent on Chrome (highly unlikely situation since Edge move to Chromium though). I am not saying that that Edge is better than Chrome al the time, but it is better in those type of corporate situations. Obviously IE Mode is just asking for trouble, but this can be locked down using group policy.

  • @GrannyDryden
    @GrannyDryden Месяц назад

    This reminds me if the issue back in the day, with Windows XP SP1 called "Raw Sockets". This was a vulnerability that allowed attacker to attack a system remotely, outside of the standard TCP/IP protocol and allowed attackers to be able to manipulate both the Transport and IP Layers. It was kind of a big deal back then and a major reason why, Microsoft implemented a firewall in Windows XP SP2.

  • @Petch85
    @Petch85 Месяц назад +2

    Can you explain the new AMD CPU buck in detail. It sounds super complicated, but it also sound like you are in trouble anyway on a machine if you can be effected by this buck.
    But a vulnerability that stays on your pc even after you reinstall your OS just sounds bad 🙁.
    But I think it could be interesting to take a closer look.

    • @apIthletIcc
      @apIthletIcc Месяц назад

      Man ngl I think I got hit by one of those, and I still have the motherboard (an amd b450) but have not quite been able to figure out how to diagnose the thing without infecting more USB drives with whatever was on it. So as far as I got, was basically that it has the capability to propagate via USB drives without any user interaction (just by plugging it into the powered on motherboard). Drives used in my testing/troubleshooting/analysis lost all ability to be reformatted too. Idk if that's from the same exploit or vuln you mentioned but it sounds like what I had happen.

    • @Petch85
      @Petch85 Месяц назад

      @@apIthletIcc The USB issue is something else and I don't know how to test if you have this issue.
      The AMD CPU one that I am talking about, I think they call that Sinkclose vulnerability. 🤷‍♂But they are similar, just for CPU's.

  • @philipmrch8326
    @philipmrch8326 Месяц назад +4

    My ISP does not even provide me with IPv6

    • @jeffspaulding9834
      @jeffspaulding9834 Месяц назад

      Same here. I use a tunnel from Hurricane Electric, which works great except that Google makes you use a captcha because it's flagged HE's entire network.
      You can get a /48 and several /64s for free.

  • @SterileNeutrino
    @SterileNeutrino Месяц назад

    If you want to pick up a necessary skill (that should be in first semester but wasn't truly mentioned at my uni except in electronics engineering): "Practical UML Statecharts in C/C++ - Event-Driven Programming for Embedded System". Nothing complex or trendy, just a great book explaining the skills one should have. Pricey though, it's that luxury CRC company (and suddenly you understand why Godot is doing what it does in the way it does it)

  • @bborkzilla
    @bborkzilla Месяц назад +1

    Another Windows vulnerability? I'm shocked, SHOCKED!

  • @AnonymousAnarchist2
    @AnonymousAnarchist2 Месяц назад

    one thing that really gets me.
    Why is consumer, programer, and buisness service windows the same windows?
    Seems like Microsoft is inviting problems. Its one thing to have cross compatability, its another to try and make the same product for all of them

  • @yoshikawachinatsuu
    @yoshikawachinatsuu 21 день назад

    Windows has a major problem - it's existence.

  • @privacyvalued4134
    @privacyvalued4134 Месяц назад +1

    I'm going to guess that after the RCE vulnerability for WiFi that happened a few weeks back and sent everyone scrambling to update, someone at Microsoft decided to take a closer look at their TCP/IP stack to see if there were any other RCE vulnerabilities that they had also overlooked. Is _anyone_ surprised that they found one? Anyone? No? Okay.

  • @Dagobah359
    @Dagobah359 Месяц назад

    "No one uses Edge." Well, that's not true. They based it on Chromium and a lot of people no longer have any resistance to the MS pressure to use it, so use of Edge is increasing.
    "No one uses Edge in IE mode." Oh, bless your heart. You've never worked in the DoD. I'm sure you'll feel really safe learning that a LOT of DoD systems are outdated and can only be accessed using IE or Edge in IE mode.

  • @foobarf8766
    @foobarf8766 Месяц назад

    Getting Windows 95 NetBIOS OOB flashbacks from this

  • @xanaxity
    @xanaxity Месяц назад

    ".....it’s just another Tuesday for Microsoft“ 💀

  • @lennox3094
    @lennox3094 Месяц назад

    Instant subscription. Keep up your awesome work

  • @Ttarler
    @Ttarler Месяц назад

    Edge is basically mandatory for the large government agency I work for. I think usage is somewhat higher than you would expect.

  • @tuxrandom
    @tuxrandom Месяц назад

    Good thing that one of the first things I do on a new machine is to disable IPv6 for the crapton of QoS issues it causes for me. (Ignoring that I don't use Windows for anything important.)

  • @T1ppyTaps
    @T1ppyTaps Месяц назад

    "No one uses Edge in IE mode"
    Anything to do with the DEA: hold my beer.

  • @SteveWray
    @SteveWray Месяц назад

    Don't Microsoft say that running with IPv6 disabled is not a supported configuration...? Because they no longer test with it disabled...

  • @thripnixe
    @thripnixe Месяц назад

    1:38 "no one uses Edge" bro Im edging right now

    • @kensmith5694
      @kensmith5694 Месяц назад

      Gasp! and you admit that in public

  • @wompastompa3692
    @wompastompa3692 Месяц назад +2

    Good ol' Macroshit Wangblows. I really should switch to Lunix at some point.

    • @Sypaka
      @Sypaka Месяц назад +1

      "Macroshit Wangblows" Thank you. you made my day. xD

  • @hi_im_crimson
    @hi_im_crimson Месяц назад +1

    so what is the vulnerability. you just said that its ipv6 because there is no nat needed.

  • @sasukesarutobi3862
    @sasukesarutobi3862 Месяц назад

    I'd never really thought about encapsulation as something that contextualises the encapsulated data. Huh.

  • @beauxq
    @beauxq Месяц назад

    I think what he meant was: "Nobody that we care about uses Edge in IE mode."

  • @o0alessandro0o
    @o0alessandro0o Месяц назад

    Is it me or remote escalation bugs in pieces of software that should be decades old (and therefore bug free) are getting more and more common? What exactly *is* patch Tuesday these days? Adding two bugs for every one you fix?

  • @ClariNerd
    @ClariNerd Месяц назад

    “No one uses edge or edge in ie mode”
    *laughs in sitescope*

  • @mdimransarkar1103
    @mdimransarkar1103 Месяц назад

    NAT makes my peer to peer experience terrible.

  • @zaper2904
    @zaper2904 Месяц назад +1

    IPV6 considered harmful.
    Seriously though how the hell am I first hearing of this here? Thanks for the info, I updated my machine.

    • @TheIncredibleLaser
      @TheIncredibleLaser Месяц назад

      IPv6 Windows Implementation considered harmful more like

  • @pcbona
    @pcbona 29 дней назад

    IPv6 does have a private address range just as IPv4 has. So not all IPv6 is routable on the internet.

  • @donchaput8278
    @donchaput8278 Месяц назад +1

    Same as a lot of other comments. Our company force defaults us to Edge every reboot, some of our apps need Edge to load. Ughhhh

  • @endunry
    @endunry Месяц назад

    While yes, the most that are watching this already know about IPAdresses, but i basically just Forward this to my family so they Update their PC so i appreciate explaining this a bit more on a surface level.

  • @dlawsAcer
    @dlawsAcer Месяц назад

    I feel like I should have anticipated that leaving IPv6 enabled, because it's enabled by default, would be a security vulnerability. Was this really just discovered, or just the cover blown. Systems should be hardened out-of-the-box, requiring users a enable the features that they actually need.

  • @wernerviehhauser94
    @wernerviehhauser94 Месяц назад

    This feels like Blaster all over again......

  • @dervogel502
    @dervogel502 Месяц назад

    "Nobody uses Edge in IE mode"
    My ip camera's

  • @dewmi4403
    @dewmi4403 Месяц назад

    Me waiting for the day when thumbnail says "Playing this video can hack your computer"