USENIX Security2025Top-tier venue
Haunted by Legacy: Discovering and Exploiting Vulnerable Tunnelling Hosts
Angelos Beitis, Mathy Vanhoef
Abstract
This paper studies the prevalence and security impact of open tunnelling hosts on the Internet. These hosts accept legacy or modern tunnelling traffic from any source. We first scan the Internet for vulnerable IPv4 and IPv6 hosts, using 7 different scan methods, revealing more than 4 million vulnerable hosts which accept unauthenticated IP in IP (IPIP), Generic Routing Encapsulation (GRE), IPv4 in IPv6 (4in6), or IPv6 in IPv4 (6in4) traffic. These hosts can be abused as one-way proxies, can enable an adversary to spoof the source address of packets, or can permit access to an organization's private network. The discovered hosts also facilitate new Denial-of-service (DoS) attacks. Two new DoS attacks amplify traffic: one concentrates traffic in time, and another loops packets between vulnerable hosts, resulting in an amplification factor of at least 16 and 75, respectively. Additionally, we present an Economic Denial of Sustainability (EDoS) attack, where the outgoing bandwidth of a host is drained. Finally, we discuss countermeasures and hope our findings will motivate people to better secure tunnelling hosts.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 642f539f-d49a-4b70-af7e-45356b883ca8Cited by top-tier papers2
- Lost in Encapsulation: Exploiting Open Tunnelling Hosts and Attacking Private NetworksAngelos Beitis, Mathy VanhoefUSENIX Security 2026
- TED: Abusing Tunnel Hosts and IPv6 Extension Headers for Pulsing DoS AttacksLe Gai, Zedong Jia, Lin He, Daguo Cheng et al.USENIX Security 2026
Builds on3
- Fragment and Forge: Breaking Wi-Fi Through Frame Aggregation and FragmentationMathy VanhoefUSENIX Security 2021 · 48 citations
- Scan, Test, Execute: Adversarial Tactics in Amplification DDoS AttacksHarm Griffioen, Kris Oosthoek, Paul van der Knaap, Christian DoerrCCS 2021 · 35 citations
- TCP Spoofing: Reliable Payload Transmission Past the Spoofed TCP HandshakeYepeng Pan, Christian RossowS&P 2024 · 15 citations
Related papers
- On Using Application-Layer Middlebox Protocols for Peeking Behind NAT GatewaysTeemu Rytilahti, Thorsten HolzNDSS 2020
- Loopy Hell(ow): Infinite Traffic Loops at the Application LayerYepeng Pan, Anna Ascheman, Christian RossowUSENIX Security 2024 · 4 citations
- Glowing in the Dark: Uncovering IPv6 Address Discovery and Scanning Strategies in the WildHammas Bin Tanveer, Rachee Singh, Paul Pearce, Rishab NithyanandUSENIX Security 2023
- Off-Path Network Traffic Manipulation via Revitalized ICMP Redirect AttacksXuewei Feng, Qi Li, Kun Sun, Zhiyun Qian et al.USENIX Security 2022
- Don't Forget to Lock the Back Door! A Characterization of IPv6 Network Security PolicyJakub Czyz, Matthew J. Luckie, Mark Allman, Michael D. BaileyNDSS 2016 · 87 citations
