Besides, if I were on a red team, I'd enumerate all devices on the LAN as well. Simply to look for all that old cruft someone set up years ago and never updated... that's where you get persistence. No one goes and checks 'scopes, network gear or printers for indicators of compromise in their firmware, because no one thinks of them if the admin isn't looking for outgoing Internet traffic.
Times have changed a lot in the past decade. No reasonable network admin would be giving public IPs to everything that connects to the network any more.
IPv4 addresses are also scarce relative to a decade ago.
Instead, you should put a default-deny rule on your firewall for all incoming traffic to user devices (which is generally the default setting anyway).
Coupled with "NAT isn't a firewall", assigning actual IPs to your end devices isn't all that silly if you happen to have a few million to spare.
Even then, though, the downsides of consumer network security (mostly) relying on NAT were obvious. Common ports (80, 25, etc) were blocked inbound; the school's printers basically had to be on their own network, or get spammed all day.
You are speaking about academia. It's not mutually exclusive, but it's different then out there in the wild.
It is indeed a different environment.
Here is a service that will show you both your public IPv4 and your public IPv6 address.
Still, that's the only nmap-in-a-website I'm aware of. There are probably others.
Does the nmap scan work on IPv6? That site might actually only be IPv4...
At the end it said
Nmap done: 0 IP addresses (0 hosts up) scanned in 2.20 seconds
Even though it claims to support IPv6
Also the site spent a whole lot of time showing progress bars and stuff.
Whereas when I run Nmap from one of my servers on the internet against my public home IPv6 address
% nmap -6 -A -T4 2a0c:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx
I get: Starting Nmap 7.94 ( https://nmap.org ) at 2023-07-16 17:43 CEST
Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn
Nmap done: 1 IP address (0 hosts up) scanned in 2.23 seconds
So in conclusion yeah, that site you linked was not able to scan IPv6I think better than that online version of Nmap is to run Nmap from another computer on another IPv6 enabled network against your own public home IPv6 address. Assuming you have additional computers like a server or a VPS, etc. Same way I did.
Another possible alternative is to use shodan.io and check what they have found in their past scans for your IP address. Seems that shodan requires creating an account now in order to use it. Not sure if it did before. I remember testing shodan.io a few years ago but don’t remember if I had to create an account then.
Agree nmap from another machine is best but that's not always an option. I'm thinking like if I am on hotel wifi or something. I might not have easy access to another box.
Shodan is a great suggestion.
Also I'd be extremely surprised if Shodan had anything on your IPv6 address.
Nmap done: 0 IP addresses (0 hosts up) scanned in 2.20 seconds
And mine:
Nmap done: 1 IP address (0 hosts up) scanned in 2.23 seconds
And note that 0 IP addresses scanned is exactly what you get if you run nmap with an IPv6 address as target but without the -6 flag. They probably are doing just that; running nmap without the -6 flag.
But let's try something else.
% host google.com
google.com has address 142.250.184.14
google.com has IPv6 address 2a00:1450:4003:808::200e
google.com mail is handled by 10 smtp.google.com.
% nmap -6 -A -T4 2a00:1450:4003:808::200e
Starting Nmap 7.80 ( https://nmap.org ) at 2023-07-16 16:53 BST
Nmap scan report for mad06s10-in-x0e.1e100.net (2a00:1450:4003:808::200e)
Host is up (0.032s latency).
Not shown: 998 filtered ports
PORT STATE SERVICE VERSION
80/tcp open http gws
[...]
Nmap done: 1 IP address (1 host up) scanned in 76.10 seconds
And now try putting 2a00:1450:4003:808::200e into their web tool and see what they report.At the moment their website will get 0 addresses scanned for that as well.
Nmap done: 0 IP addresses (0 hosts up) scanned in 1.58 seconds
In the network path. On the device. They control what packets get allowed or denied.
So, to have any way to connect back to my home network I have to run a permanent vpn to a server in aws and connect to that.
Low end home routers have tiny connection tracking tables and fall back to software routing when that table overflows. IMO if you don't notice the massive drop in performance when this happens, you have very low standards/expectations for internet latency. In had to upgrade to a prosumer router just to get acceptable perf on IPv4
NAT on IPv4 vs stateful routing on IPv6 is a wash in terms of performance.