Haunted by Legacy: Discovering and Exploiting Vulnerable Tunnelling Hosts

Angelos Beitis, Mathy Vanhoef, DistriNet

34th USENIX Security Symposium · Day 1

This groundbreaking research paper, "Haunted by Legacy: Discovering and Exploiting Vulnerable Tunnelling Hosts," systematically investigates the widespread prevalence and severe security implications of misconfigured or insecure tunnelling hosts across the IPv4 and IPv6 Internet. Presented by Angelos Beitis and Mathy Vanhoef from KU Leuven, the work uncovers a startling number of vulnerable hosts—over 4 million—that accept unauthenticated tunnelling traffic from any source. These hosts, often running legacy or modern tunnelling protocols without proper security mechanisms, present significant risks, ranging from enabling source address spoofing and acting as one-way proxies to facilitating access to private networks.

AI review

This is what real Internet security research looks like. Beitis and Vanhoef didn't just find a vulnerability — they systematically mapped 4+ million vulnerable tunnelling hosts across the entire IPv4/IPv6 address space, then weaponized the findings into three novel DoS attacks with measured amplification factors. The Ping-Pong and TuTL attacks are genuinely clever, the scanning methodology is rigorous, and the CVEs are already assigned.