IPV6 web tools

Networking with IPv6 Only annoyances

Currently i see a big sites reachable by DualStack but there are still some (for me)  websites that i thought they should be already support IPv6

for  Downloading Firefox is using Amazon infrastructure


Location Ashburn,Virginia,United States,North America
ISP: Amazon Technologies

To see progress goto

Ubuntu Addresses:, Canonical Ltd Addresses:,

All Ipv6 only no reachable

IPv6 Support in Microsoft Products and Services


IT pros blast Google over Android’s refusal to play nice with IPv6

DHCPv6 is an outgrowth of the DHCP protocol used in the older IPv4 standard – it’s an acronym for “dynamic host configuration protocol,” and is a key building block of network management. Nevertheless, Google’s wildly popular Android devices – which accounted for 78% of all smartphones shipped worldwide in the first quarter of this year – don’t support DHCPv6 for address assignment.

Why the lack of DHCPv6 support is a problem

Current Status of IPv6 Support for Networking Applications

see http://www ( LINUX/BSD)

Apple Will Require IPv6 Support For All iOS 9 Apps ( but still pending , my comment?)




FOSDEM: IPv6-only wireless network again!

IPv6-only wireless network again!

Last year we turned off IPv4 on our main FOSDEM wireless network. They idea is to confront developers with the IPv6-reality and encourage them to fix bugs. Progress has been made, but there is a lot of work left to do!

FOSDEM is a unique opportunity to confront thousands of developers with an IPv6-only reality. We are hopeful that making our default network IPv6-only will encourage people to fix bugs in applications and devices.

The FOSDEM network has NAT64 and DNS64 transition measures in place for communicating with the legacy internet. For those who need it, the FOSDEM-legacy wireless network provides the same dual stack connectivity we offered on FOSDEM prior to 2014.

While last year we had “seatbelts” in place for flipping FOSDEM back to dual stack, we decided not to implement those this year. If the main network catches fire, we will just have to fix our bugs!

  • FOSDEM: IPv6-only, provides NAT64 and DNS64. Recursive DNS resolvers announced with RA and DHCPv6. If you need to configure DNS manually, use 2001:67c:1810:f056::2 and 2001:41d0:2:1959:21c:c0ff:fe88:6f58
  • FOSDEM-legacy: provides native IPv6 and legacy IP connectivity. No DNS64.

But still Android has issues


Moving to IPv6 in the enterprise

We heard for years that IPv6 is comming. But it did not happen.

I was monitoring the progress and started to improve my  own knowledge. I was browsing how  i could get IPv6 access for me. I identified https:// and Gogonet  as tunnel Broker.

Start geting your IPV6 Range and Tunnel from free tunnelbrokers: SixXS, Hurricane Electric

Make your IPv6 Basic Certification !

web security

Seven Web Server HTTP Headers that Improve Web Application Security for Free

The ‘X-Content-Type-Options’ HTTP header if set to ‘nosniff’ stops the browser from guessing the MIME type of a file via content sniffing. Without this option set there is a potential increased risk of cross-site scripting.

Secure configuration: Server returns the ‘X-Content-Type-Options’ HTTP header set to ‘nosniff’.

The ‘X-XSS-Protection’ HTTP header is used by Internet Explorer version 8 and higher. Setting this HTTP header will instruct Internet Explorer to enable its inbuilt anti-cross-site scripting filter. If enabled, but without ‘mode=block’ then there is an increased risk that otherwise non exploitable cross-site scripting vulnerabilities may potentially become exploitable.

Secure configuration: Server returns the ‘X-XSS-Protection’ HTTP header set to ‘1; mode=block’.

The ‘X-Frame-Options’ HTTP header can be used to indicate whether or not a browser should be allowed to render a page within a >frame< or >iframe<. The valid options are DENY, to deny allowing the page to exist in a frame or SAMEORIGIN to allow framing but only from the originating host. Without this option set the site is at a higher risk of click-jacking unless application level mitigations exist.

Secure configuration: Server returns the ‘X-Frame-Options’ HTTP header set to ‘DENY’ or ‘SAMEORIGIN’.

The ‘Cache-Control’ response header controls how pages can be cached either by proxies or the user’s browser. Using this response header can provide enhanced privacy by not caching sensitive pages in the users local cache at the potential cost of performance. To stop pages from being cached the server sets a cache control by returning the ‘Cache-Control’ HTTP header set to ‘no-store’.

Secure configuration: Either the server sets a cache control by returning the ‘Cache-Control’ HTTP header set to ‘no-store, no-cache’ or each page sets their own via the ‘meta’ tag for secure connections.

Updated: The above was updated after our friend Mark got in-touch. Originally we had said no-store was sufficient. But as with all things web related it appears Internet Explorer and Firefox work slightly differently (so everyone ensure you thank Mark!).

The ‘X-Content-Security-Policy’ response header is a powerful mechanism for controlling which sites certain content types can be loaded from. Using this response header can provide defence in depth from content injection attacks. However it’s not for the faint hearted in our opinion.

Secure configuration: Either the server sets a content security policy by returning the ‘X-Content-Security-Policy’ HTTP header or each page sets their own via the ‘meta’ tag

The ‘HTTP Strict Transport Security’ (Strict-Transport-Security) HTTP header is used to control if the browser is allowed to only access a site over a secure connection and how long to remember the server response for thus forcing continued usage.

Note: This is a draft standard which only Firefox and Chrome support. But it is supported by sites such as PayPal. This header can only be set and honoured by web browsers over a trusted secure connection.

Secure configuration: Return the ‘Strict-Transport-Security’ header with an appropriate timeout over an secure connection.

The ‘Access Control Allow Origin’ HTTP header is used to control which sites are allowed to bypass same origin policies and send cross-origin requests. This allows cross origin access without web application developers having to write mini proxies into their apps.

Note: This is a draft standard which only Firefox and Chrome support, it is also advocarted by sites such as

Secure configuration: Either do not set or return the ‘Access-Control-Allow-Origin’ header restrict

Social Collabration Speaker

Portal & Social Collabration Days 2014

At the Marcus Evans Portal & Social Collabration Days 2014 i will speak about Data Dealing inside.

Date: 21.February.2014 Berlin


From the invitation (German)

Unternehmensportale und Intranets als „Digital Workplaces“ entwickeln sich insbesondere in Verbindung mit Social Business Collaboration 
zu einer Herausforderung für Unternehmen, wenn es um die Arbeits- und Organisationsformen der nahen Zukunft geht. 
Im Vordergrund steht dabei die deutliche Beschleunigung von Arbeitsabläufen und Prozessen durch eine direkte und hierarchunabhänge 
Kommunikation und Collaboration, was zu einer höheren Produktivität und geringeren Arbeitskosten führen soll.

Die Themen eCollaboration, Wissensmanagement und die Motivation der Mitarbeiter stehen daher bei dieser Konferenz im Mittelpunkt. 
Den nur mit einer Strategie die sowohl die technische wie auch die menschliche Komponente im Blick hat kann eine neue Art 
der internen Kommunikation effektiv umgesetzt werden.

Zur Zusammenarbeit gehört aber auch Vertrauen und Verständnis für die Bedürfnissse der jeweiligen zur Zusammerarbeit aufgeforderten Menschen.

Wir wollen ein Verzeichniss der Niederlassungen eines Firmenverbundes erstellen.
Aufgefordert werden Konzernkommunikation und Rechtsabteilung und die IT-Abteilung.
Das Ergebnis der einzelnen Abteilungen wird im ersten Moment völlig anders aussehen.

Nutzen entsteht durch “eine gemeinsame Liste” die aber je nach Darstellung und Filterung die gewünschten Sichten produziert und damit die Vorteile der Datenvalidation und der Wiederverwendbarkeit erreicht

Portal & Social Collaboration Days 2014.pdf