
DEF CON 33 - Tunnelpocalypse - Rich Compton
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 28:11
The video exposes a critical tunneling vulnerability that allows attackers to bypass IP spoofing protections, affecting millions of devices worldwide 0:46-0:52.
Key Takeaways:
• The vulnerability affects GRE, IP-in-IP, and other tunneling protocols, allowing spoofed traffic to be sent through vulnerable routers that de-encapsulate packets without proper validation 6:31-6:45
• Researchers discovered approximately 4 million vulnerable hosts on the internet, with 2.3 million specifically capable of sending spoofed traffic 9:23-9:35
• Many devices are vulnerable including Cisco routers/switches, Juniper equipment, VPN servers, and ISP home routers, even without explicit tunnel configuration 10:47-11:06
• The vulnerability enables various attacks including DDoS amplification, ACL bypass, direct path spoofed attacks, and log corruption 13:02-13:36
• Network administrators should patch devices, implement access lists to block unwanted tunnel traffic, and use tools like the speaker's Tattletail to detect spoof traffic 15:57-16:12
This vulnerability represents a significant threat to internet security as it dramatically lowers the barrier for launching sophisticated spoofing attacks 17:35-17:45.
Sources:
- 0:46-0:52 Overview of DDoS amplification attacks
- 6:31-6:45 Explanation of the tunneling vulnerability
- 9:23-9:35 Statistics on vulnerable hosts
- 10:47-11:06 Affected devices and sc
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Uh so my name is is Rich and um work for a company that uh gets a lot of DOS attacks. I I do a lot of stuff related to to DOS and uh network security. And this this vulnerability uh got released about 6 months ago and the the vulnerability is related to uh encapsulating traffic. Um and then there are various types of attacks that you can you can do with this encapsulated traffic. But first, I'm just going to give like a brief overview on DOS amplification attacks. So, in in a DOS amplification attack, the the attacker is able to spoof the source IP of the victim. They uh say the victim is quad one. The attacker will spoof that quad one go and then send an amplification request, a a request packet to a open amplifier. And so these can be open DNS servers. We see that quite a bit. Open NTP s…