We present IPvSeeYou, a privacy attack that permits a remote and unprivileged adversary to physically geolocate many residential IPv6 hosts and networks with street-level precision. The crux of our method involves: 1) remotely discovering wide area (WAN) hardware MAC addresses from home routers; 2) correlating these MAC addresses with their WiFi BSSID counterparts of known location; and 3) extending coverage by associating devices connected to a common penultimate provider router. We first obtain a large corpus of MACs embedded in IPv6 addresses via high-speed network probing. These MAC addresses are effectively leaked up the protocol stack and largely represent WAN interfaces of residential routers, many of which are all-in-one devices that also provide WiFi. We develop a technique to statistically infer the mapping between a router's WAN and WiFi MAC addresses across manufacturers and devices, and mount a large-scale data fusion attack that correlates WAN MACs with WiFi BSSIDs available in wardriving (geolocation) databases. Using these correlations, we geolocate the IPv6 prefixes of $>$12M routers in the wild across 146 countries and territories. Selected validation confirms a median geolocation error of 39 meters. We then exploit technology and deployment constraints to extend the attack to a larger set of IPv6 residential routers by clustering and associating devices with a common penultimate provider router. While we responsibly disclosed our results to several manufacturers and providers, the ossified ecosystem of deployed residential cable and DSL routers suggests that our attack will remain a privacy threat into the foreseeable future.
翻译:我们提出了IPvSeeYou, 这是一种隐私攻击,它允许一个远程和无特权的敌人将许多住宅IPv6主机和网络以街道精确度实际定位到地貌位置。我们的方法的关键在于:(1) 从家用路由器远程发现广域(广域网)硬件MAC地址;(2) 将这些MAC地址与已知地点的WiFi BSSID对应地址联系起来;(3) 通过将连接到一个共同的倒数提供商路由器路由器连接起来,扩大覆盖范围。我们首先通过高速网络探测,获得大量嵌入IPv6地址的MAC设备。这些MAC地址有效地泄漏了协议路径堆,并在很大程度上代表了住宅路由器路由器的广域网界面界面界面界面界面界面界面界面界面界面界面界面界面界面界面的界面界面界面界面界面界面界面。 我们开发了一种技术方法,将路由路由器网络和WiFMMMMMM的地址连接到我们当时的固定路由路由路由路由路由系统定位的路径和路由系统定位的系统定位系统定位系统定位路由我们内部的路径和内部智能路由系统定位路由系统定位系统定位的系统定位系统定位系统连接的系统连接系统连接系统连接到我们内部的路径的路径和内部的路径定位系统将持续地标路由。