IPv6 is already running on your devices — most people just don’t know it yet. It carries a large and growing share of internet traffic, your phone and laptop almost certainly have an IPv6 address right now, and most security programs still treat it as someone else’s problem. That gap is exactly where attackers live. This Cover6 Community session covers IPv6 from the ground up — and IPv6 is in our name for a reason, so this one is close to home.
Use this post as your read-ahead, then come back to it when you need to read an address or remember an attack.
Why IPv6 exists
IPv4 has about 4.3 billion addresses. The internet ran out. IPv6 replaces the 32-bit address with a 128-bit one — enough space that address exhaustion stops being a concern for any timeframe worth planning around. That’s the “why.” The “so what” is that IPv6 is on by default on modern systems, which means it’s part of your attack surface whether you’ve thought about it or not.
Reading a 128-bit address
A full IPv6 address looks intimidating until you learn the two shortening rules, and then it’s quick:
- Drop leading zeros in each group (
0db8becomesdb8). - Collapse one run of all-zero groups to
::(used once per address).
So 2001:0db8:0000:0000:0000:0000:0000:0001 shortens to 2001:db8::1. The session walks through this until reading and shortening an address is second nature — it’s the single skill that makes everything else about IPv6 approachable.
Three ways IPv6 communicates
IPv6 drops the broadcast model and uses three address types instead:
- Unicast — one-to-one, a single interface.
- Multicast — one-to-many, everyone subscribed to the group.
- Anycast — one-to-nearest, the same address on many nodes, routed to the closest.
No more broadcast is a real change from IPv4, and it reshapes how discovery and attacks work on the wire.
SLAAC: addresses configure themselves
One of the biggest differences from IPv4: with SLAAC (Stateless Address Autoconfiguration), a device can build its own routable address from the network prefix it hears and its own interface — historically derived from the MAC address. No DHCP server required. DHCPv6 still exists for networks that want stateful control, but the default experience is a device that addresses itself the moment it joins. Convenient — and a thing defenders need to account for.
The security story: no NAT, and new attacks
IPv6 changes the defender’s assumptions:
- IPSec was designed in, not bolted on — encryption and authentication are native to the protocol.
- No NAT. The address-translation layer many people quietly relied on as a firewall-by-accident isn’t there. Addresses are globally routable by default.
- RA Spoofing — forged Router Advertisements can redirect traffic, and the THC-IPv6 toolkit is where you’ll see this demonstrated.
- Tunneling attacks — IPv6 tunneled over IPv4 (and the reverse) can carry traffic straight past monitoring that only speaks IPv4.
- Transition mechanisms — Dual Stack, tunneling, and NAT64 are how the two protocols coexist, and each one is its own set of things to watch.
The through-line: if your monitoring, your scans, and your firewall rules only cover IPv4, you have a blind spot the size of the other half of the internet.
See it on your own machine
The session ends with a live demo on Kali Linux you can run yourself — these are the commands that make IPv6 real:
ip a # see the IPv6 addresses already on your interfaces
ping6 # test IPv6 connectivity
dig AAAA # look up a host's IPv6 DNS record
nmap -6 # scan over IPv6
Then visit test-ipv6.com to grade your own connectivity. Running ip a and finding an address you didn’t know you had is the moment IPv6 stops being theoretical.
Practice on a live lab, free
IPv6 shows up on both sides of the house — as an attack surface to scan and as traffic to monitor. First Shell gives you an authorized target to scan, free, where nmap -6 and address enumeration become muscle memory: https://www.cover6solutions.com/product/cover6-first-shell-free-access/
Prefer the defender’s seat? First Watch gives you a live Splunk lab and your first SOC shift, free — where IPv6 traffic is one more thing an analyst learns to see: https://www.cover6solutions.com/product/cover6-first-watch-free-access/
Where this path leads
Networking fundamentals like IPv6 sit under both the SOC Analyst and Penetration Tester paths on Chrysalus. Build your free profile and track your progress.
- Read the SOC Analyst Roadmap 2026 and the Pentester Roadmap 2026.
- Not sure which lane? Take the free career path assessment.
- Keep the Cover6 Field Manual handy as a free reference, and browse every Cover6 course.
- Join The 6, our free newsletter, to catch the next session.
Watch the replay
We ran this live in the Cover6 Community — why IPv6 exists, reading and shortening addresses, the three communication types, SLAAC, the security differences and attacks, and a full Kali demo with ip a, ping6, dig AAAA, and nmap -6. Planning to attend a future meetup? Use this post as your read-ahead, and catch the replay above.
