IPv6 can create exposure beside an IPv4 mental model
Many systems have IPv6 enabled and reachable while everybody's mental model, and sometimes the firewall rules, cover only IPv4.
The result is a second front door nobody is looking at, often with no equivalent filtering. It is not exotic; it is default on most modern operating systems. The check is simple and rarely done: is this reachable over IPv6, and do the same rules apply.
More on Attack surface management
- The Internet sees what you expose, not what your CMDB remembersCounted three. Answering six
- A new subdomain can create a new perimeterThe fence just got longer
- Shadow IT becomes shadow attack surfaceDoors around the back
- Acquisitions merge attack surfaces before inventoriesThe wire arrives first
- Internet exposure is a property that changesThe tide does not read your map
- A forgotten test system can be a production entry pointThe shed is still joined to the house
