{"id":997,"date":"2013-05-06T08:24:35","date_gmt":"2013-05-06T07:24:35","guid":{"rendered":"http:\/\/securite.intrinsec.com\/?p=997"},"modified":"2013-05-06T08:24:35","modified_gmt":"2013-05-06T07:24:35","slug":"evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6","status":"publish","type":"post","link":"https:\/\/www.intrinsec.com\/en\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\/","title":{"rendered":"Evil Foca: An attack tool targeting IPv4 and IPv6 networks"},"content":{"rendered":"<p>As part of Intrinsec&#039;s research activities on IPv6 security, we tested the features of Evil Foca. This article examines the implemented attacks and their relevance. Evil Foca is a tool designed by <a href=\"http:\/\/www.informatica64.com\/\">Informatica64<\/a> to test the security level of IPv4 and IPv6 networks. The Alpha version released on April 6, 2013, implements three types of attacks: Man in the middle, a denial-of-service type attack and a DNS hijacking attack.<\/p>\n<p><strong>Network scan:<\/strong><\/p>\n<p>When the tool is launched, the user chooses the network interface that will be used to send the packets. By default, it uses ICMPv6 Ping (type 128), with the multicast addresses ff01::1, ff02::1, ff01::2 and ff02::2 as destinations, as illustrated in the network screenshot below.<\/p>\n<p><a href=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2013\/05\/ping-Evil-Foca.png\"><img fetchpriority=\"high\" decoding=\"async\" class=\"alignnone size-full wp-image-1000\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2013\/05\/ping-Evil-Foca.png\" alt=\"\" width=\"810\" height=\"84\" \/><\/a><\/p>\n<p>At this stage, the tool retrieves all responses from existing machines on the network, then sends an ICMPv6 &quot;Neighbor Solicitation&quot; message to collect the MAC addresses of those machines. Once the &quot;Neighbor Advertisement&quot; messages are received, Evil Foca sends an ICMPv6 &quot;Parameter problem&quot; message\u2014type 4, with the &quot;code&quot; field set to 0, indicating the error &quot;unrecognized Next Header type encountered&quot;\u2014to all machines that responded to the &quot;Echo Request&quot; message sent during the scan. As the purpose of this packet is unclear, we contacted the tool&#039;s developers regarding its function. Having received no response so far, this point will be updated later. For more information on the Parameter problem message, refer to RFC 2463 section <a href=\"http:\/\/www.ietf.org\/rfc\/rfc2463.txt\">3.4<\/a>. Finally, the machine discovery process is repeated every 60 seconds.<\/p>\n<p>Evil Foca uses a scan that employs Router Advertisement packets sent to the multicast address ff02::1, which all machines on the network must listen to in order to receive information sent by routers. A closer look at the packet sent by Evil Foca reveals that it instructs the client not to request any configuration from the DHCPv6 server while simultaneously positioning the attacker&#039;s machine as the router with the highest preference value, as shown in the following screenshot.<\/p>\n<p><a href=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2013\/05\/RA_packet_detail_1.png\"><img decoding=\"async\" class=\"alignnone size-full wp-image-1003\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2013\/05\/RA_packet_detail_1.png\" alt=\"\" width=\"547\" height=\"260\" \/><\/a><\/p>\n<p>The user can choose the type of scan they wish to perform by changing the option in the configuration (setting) menu.<\/p>\n<p><strong>Man in the middle:<\/strong><\/p>\n<p>Evil Foca implements the Man in the middle attack for both IPv6 and IPv4 network stacks, using several exploitation methods.<\/p>\n<p><strong><em>For IPv6 networks:<\/em><\/strong><\/p>\n<p>To perform a Man-in-the-Middle attack on IPv6 networks, Evil Foca proposes three methods. The first is to use &quot;Neighbor Advertisement Spoofing,&quot; which involves sending malicious &quot;Neighbor Advertisement&quot; messages to modify the &quot;Neighbor Cache&quot; of target machines. The second method uses &quot;Router Advertisement&quot; messages to position the attacker as a router, causing traffic from all targets to be redirected to the attacker. The final method employs a malicious DHCPv6 server that broadcasts false addressing information.<\/p>\n<p><strong><em>Scenario :<\/em><\/strong><\/p>\n<p>Consider the following network diagram:<\/p>\n<p><a href=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2013\/05\/schema.jpg\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-1004\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2013\/05\/schema.jpg\" alt=\"\" width=\"711\" height=\"389\" \/><\/a><\/p>\n<p>Suppose an attacker manages to connect to the network and launches the tool. Upon launch, Evil Foca will perform a network scan and display the results. Before the attack is launched, the target machine&#039;s &quot;Neighbor cache&quot; contains only one record: that of the router.<\/p>\n<p><a href=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2013\/05\/neighbor-before.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1006\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2013\/05\/neighbor-before.png\" alt=\"\" width=\"555\" height=\"49\" \/><\/a><\/p>\n<p>To launch the attack, simply add the targets and then click the Start button. Depending on the method used, the tool will begin sending malicious packets to corrupt the target&#039;s cache.<\/p>\n<p><a href=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2013\/05\/scan-attack.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1007\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2013\/05\/scan-attack.png\" alt=\"\" width=\"958\" height=\"666\" \/><\/a><\/p>\n<p>After the attack was launched, the target machine&#039;s cache was indeed modified, containing the IPv6 addresses of both the legitimate router and the attacker&#039;s router. However, the router&#039;s addresses were assigned the same MAC address (that of the attacker&#039;s machine), as illustrated below.<\/p>\n<p><a href=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2013\/05\/neighbor-after.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1008\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2013\/05\/neighbor-after.png\" alt=\"\" width=\"557\" height=\"66\" \/><\/a>At this stage, we are supposed to receive packets to and from the target machine. However, during the machine search phase, Evil Foca only found the &quot;Link-local&quot; addresses we used to corrupt the caches of the target machine and the router. Since machines in an IPv6 network can have multiple addresses, including global addresses, we can only intercept communications using &quot;Link-local&quot; addresses. This can be seen as a major drawback of the tool. To overcome this problem, we can perform a scan using other tools like Nmap (version 6.0 or higher), which perfectly handles the collection of global addresses, and then add these addresses to the target list.<\/p>\n<p><strong><em>For IPv4 networks:<\/em><\/strong><\/p>\n<p>The Man-in-the-Middle attack implemented by Evil Foca for IPv4 networks uses two exploitation methods. The tool proposes ARP spoofing as the first attack method or performing a &quot;DHCP ACK injection&quot; as illustrated below.<\/p>\n<p><a href=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2013\/05\/DHCPACK.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1009\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2013\/05\/DHCPACK.png\" alt=\"\" width=\"501\" height=\"293\" \/><\/a><\/p>\n<p>This attack relies on sending erroneous data to the machine requesting addressing information, using &quot;DHCP ACK&quot; packets and information broadcast by the client machine when it searches for a DHCP server.<\/p>\n<p><strong>Denial-of-service attacks:<\/strong><\/p>\n<p>The denial-of-service attack against hosts with the IPv6 stack enabled is aimed at Windows machines. This attack exploits a vulnerability in the implementation of NDP &quot;Neighbor Discovery Protocol&quot; (<a href=\"http:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2010-4669\">CVE-2012-4669<\/a>During this attack, Evil Foca sends multiple Router Advertisement (RA) packets with different source addresses, leading to the consumption of all CPU resources and rendering the equipment unavailable. Regarding the denial-of-service attack against IPv4 machines, the tool severs the connection between two machines by modifying the target&#039;s ARP cache with a malicious ARP packet.<\/p>\n<p><strong>DNS Hijacking:<\/strong><\/p>\n<p>Evil Foca allows us to implement a &quot;DNS Hijacking&quot; attack. The principle of this attack is to redirect DNS queries to a malicious DNS server. To carry out this attack, a Man-in-the-Middle attack must be performed beforehand.<\/p>\n<p><strong><em>Scenario<\/em><\/strong>\u00a0:<\/p>\n<p>We will use the same network diagram as before. To carry out a phishing campaign, an attacker needs to set up a web server that simulates an authentication page for a well-known website offering an email service, such as Gmail. Then, to redirect users to the malicious site, we will use a DNS hijacking attack. This is to link the domain name <a href=\"http:\/\/www.gmail.com\">www.gmail.com<\/a> addressed to the attacker as shown below.<\/p>\n<p><a href=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2013\/05\/DNS-attaque.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1010\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2013\/05\/DNS-attaque.png\" alt=\"\" width=\"501\" height=\"294\" \/><\/a><\/p>\n<p>After the attack is launched, when a network user tries to access the domain name www.gmail.com, the IP address sent to the client will be that of the attacker hosting the malicious server.<\/p>\n<p><a href=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2013\/05\/dns-req.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1011\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2013\/05\/dns-req.png\" alt=\"\" width=\"751\" height=\"266\" \/><\/a>Finally, the web page will be loaded from the malicious web server, and thus the attacker will be able to retrieve the login information entered by the user.<\/p>\n<p><a href=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2013\/05\/rogue-gmail.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1012\" src=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2013\/05\/rogue-gmail.png\" alt=\"\" width=\"1027\" height=\"534\" \/><\/a><\/p>\n<p><strong>Conclusion<\/strong><\/p>\n<p>Evil Foca is still under development, which explains its weakness in node detection. The tool does not identify the global addresses of IPv6 machines, thus limiting the effectiveness of the &quot;Man-in-the-Middle&quot; attack, as outgoing and incoming network traffic is not intercepted. Evil Foca does contain some interesting attacks, particularly the &quot;Man-in-the-Middle&quot; attack in an IPv6 network, which is not available in any user-friendly tool. This makes these attacks more accessible and increases the risk of their execution.<\/p>\n<p>There are solutions that operate at layer 2 to protect against this type of attack. These include open-source solutions like Rafixd and NDPMon, which detect malicious packets traveling across the network, and FHS (First Hop Security), offered by Cisco, which provides a comprehensive solution for protection against this type of attack.<\/p>\n<p>The final version of Evil Foca will implement an attack using IPv6 to intercept traffic in an IPv4 network, which will pose a real threat to networks with both IPv6 and IPv4 stacks enabled (for more information on the NAT64\/DNS64 attack, refer to the\u00a0<a href=\"http:\/\/www.elladodelmal.com\/2013\/03\/evil-foca-ataque-slaac-1-de-4.html\">blog<\/a>\u00a0(from informatica64). To protect against this attack, the IPv6 network stack must be disabled if it is not in use.<\/p>","protected":false},"excerpt":{"rendered":"<p>Dans le cadre des activit\u00e9s de recherche d\u2019Intrinsec sur la s\u00e9curit\u00e9 du protocole IPv6, nous [&hellip;]<\/p>\n","protected":false},"author":13,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13,22],"tags":[46],"class_list":["post-997","post","type-post","status-publish","format-standard","hentry","category-evaluation-securite","category-veille-securite","tag-ipv6"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.0 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Evil Foca : Outil d\u2019attaque sur les r\u00e9seaux IPv4 et IPv6 - INTRINSEC<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intrinsec.com\/en\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Evil Foca : Outil d\u2019attaque sur les r\u00e9seaux IPv4 et IPv6\" \/>\n<meta property=\"og:description\" content=\"Dans le cadre des activit\u00e9s de recherche d\u2019Intrinsec sur la s\u00e9curit\u00e9 du protocole IPv6, nous [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intrinsec.com\/en\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\/\" \/>\n<meta property=\"og:site_name\" content=\"INTRINSEC\" \/>\n<meta property=\"article:published_time\" content=\"2013-05-06T07:24:35+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2013\/05\/ping-Evil-Foca.png\" \/>\n<meta name=\"author\" content=\"Admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@Intrinsec\" \/>\n<meta name=\"twitter:site\" content=\"@Intrinsec\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\\\/\"},\"author\":{\"name\":\"Admin\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/person\\\/5636e3e5276b952facbd0aadb12a858a\"},\"headline\":\"Evil Foca : Outil d\u2019attaque sur les r\u00e9seaux IPv4 et IPv6\",\"datePublished\":\"2013-05-06T07:24:35+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\\\/\"},\"wordCount\":1505,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2013\\\/05\\\/ping-Evil-Foca.png\",\"keywords\":[\"IPv6\"],\"articleSection\":[\"S\u00e9curit\u00e9 offensive &amp; Audit\",\"Veille S\u00e9curit\u00e9\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.intrinsec.com\\\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\\\/\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\\\/\",\"name\":\"Evil Foca : Outil d\u2019attaque sur les r\u00e9seaux IPv4 et IPv6 - INTRINSEC\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2013\\\/05\\\/ping-Evil-Foca.png\",\"datePublished\":\"2013-05-06T07:24:35+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.intrinsec.com\\\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2013\\\/05\\\/ping-Evil-Foca.png\",\"contentUrl\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2013\\\/05\\\/ping-Evil-Foca.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\\\/\\\/www.intrinsec.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Evil Foca : Outil d\u2019attaque sur les r\u00e9seaux IPv4 et IPv6\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#website\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/\",\"name\":\"INTRINSEC\",\"description\":\"Notre m\u00e9tier , Prot\u00e9ger le v\u00f4tre\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.intrinsec.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#organization\",\"name\":\"INTRINSEC\",\"alternateName\":\"ISEC\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/libellule.png\",\"contentUrl\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/libellule.png\",\"width\":1322,\"height\":1322,\"caption\":\"INTRINSEC\"},\"image\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/Intrinsec\",\"https:\\\/\\\/fr.linkedin.com\\\/company\\\/intrinsec\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UC0trUZAHNZOUbxYnNdecM4A\"],\"description\":\"soci\u00e9t\u00e9 de consulting, pure player cybers\u00e9curit\u00e9 fran\u00e7ais et europ\u00e9en depuis plus de 30ans, sp\u00e9cialiste dans la s\u00e9curit\u00e9 offensive & audit (pentest\\\/red team), GRC, et services IMSS comme le SOC, CTI et CERT Intrinsec est qualifi\u00e9 PASSI Elev\u00e9, PRIS Elev\u00e9 et PACS par l'ANSSI\",\"email\":\"contact@intrinsec.com\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/person\\\/5636e3e5276b952facbd0aadb12a858a\",\"name\":\"Admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=retro&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=retro&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=retro&r=g\",\"caption\":\"Admin\"},\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/author\\\/admin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Evil Foca: An attack tool targeting IPv4 and IPv6 networks - INTRINSEC","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intrinsec.com\/en\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\/","og_locale":"en_US","og_type":"article","og_title":"Evil Foca : Outil d\u2019attaque sur les r\u00e9seaux IPv4 et IPv6","og_description":"Dans le cadre des activit\u00e9s de recherche d\u2019Intrinsec sur la s\u00e9curit\u00e9 du protocole IPv6, nous [&hellip;]","og_url":"https:\/\/www.intrinsec.com\/en\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\/","og_site_name":"INTRINSEC","article_published_time":"2013-05-06T07:24:35+00:00","og_image":[{"url":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2013\/05\/ping-Evil-Foca.png","type":"","width":"","height":""}],"author":"Admin","twitter_card":"summary_large_image","twitter_creator":"@Intrinsec","twitter_site":"@Intrinsec","twitter_misc":{"Written by":"Admin","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.intrinsec.com\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\/#article","isPartOf":{"@id":"https:\/\/www.intrinsec.com\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\/"},"author":{"name":"Admin","@id":"https:\/\/www.intrinsec.com\/#\/schema\/person\/5636e3e5276b952facbd0aadb12a858a"},"headline":"Evil Foca : Outil d\u2019attaque sur les r\u00e9seaux IPv4 et IPv6","datePublished":"2013-05-06T07:24:35+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intrinsec.com\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\/"},"wordCount":1505,"commentCount":0,"publisher":{"@id":"https:\/\/www.intrinsec.com\/#organization"},"image":{"@id":"https:\/\/www.intrinsec.com\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2013\/05\/ping-Evil-Foca.png","keywords":["IPv6"],"articleSection":["S\u00e9curit\u00e9 offensive &amp; Audit","Veille S\u00e9curit\u00e9"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.intrinsec.com\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.intrinsec.com\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\/","url":"https:\/\/www.intrinsec.com\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\/","name":"Evil Foca: An attack tool targeting IPv4 and IPv6 networks - INTRINSEC","isPartOf":{"@id":"https:\/\/www.intrinsec.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intrinsec.com\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\/#primaryimage"},"image":{"@id":"https:\/\/www.intrinsec.com\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2013\/05\/ping-Evil-Foca.png","datePublished":"2013-05-06T07:24:35+00:00","breadcrumb":{"@id":"https:\/\/www.intrinsec.com\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intrinsec.com\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.intrinsec.com\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\/#primaryimage","url":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2013\/05\/ping-Evil-Foca.png","contentUrl":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2013\/05\/ping-Evil-Foca.png"},{"@type":"BreadcrumbList","@id":"https:\/\/www.intrinsec.com\/evil-foca-outil-dattaque-sur-les-reseaux-ipv4-et-ipv6\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.intrinsec.com\/"},{"@type":"ListItem","position":2,"name":"Evil Foca : Outil d\u2019attaque sur les r\u00e9seaux IPv4 et IPv6"}]},{"@type":"WebSite","@id":"https:\/\/www.intrinsec.com\/#website","url":"https:\/\/www.intrinsec.com\/","name":"INTRINSEC","description":"Our job is to protect yours.","publisher":{"@id":"https:\/\/www.intrinsec.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intrinsec.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.intrinsec.com\/#organization","name":"INTRINSEC","alternateName":"ISEC","url":"https:\/\/www.intrinsec.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.intrinsec.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2025\/02\/libellule.png","contentUrl":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2025\/02\/libellule.png","width":1322,"height":1322,"caption":"INTRINSEC"},"image":{"@id":"https:\/\/www.intrinsec.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/Intrinsec","https:\/\/fr.linkedin.com\/company\/intrinsec","https:\/\/www.youtube.com\/channel\/UC0trUZAHNZOUbxYnNdecM4A"],"description":"Intrinsec, a consulting firm and pure-play French and European cybersecurity provider for over 30 years, specializes in offensive security and auditing (penetration testing\/red teams), GRC, and IMSS services such as SOC, CTI, and CERT. Intrinsec is qualified at PASSI High, PRIS High, and PACS levels by ANSSI.","email":"contact@intrinsec.com"},{"@type":"Person","@id":"https:\/\/www.intrinsec.com\/#\/schema\/person\/5636e3e5276b952facbd0aadb12a858a","name":"Admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=retro&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=retro&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=retro&r=g","caption":"Admin"},"url":"https:\/\/www.intrinsec.com\/en\/author\/admin\/"}]}},"_links":{"self":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts\/997","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/comments?post=997"}],"version-history":[{"count":0,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts\/997\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/media?parent=997"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/categories?post=997"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/tags?post=997"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}