Author Topic: IP leak affecting VPN providers with port forwarding  (Read 447 times)

0 Members and 1 Guest are viewing this topic.

Offline iTpHo3NiX

  • EZ's Pirate Captain
  • Administrator
  • Titan
  • *
  • Posts: 2920
  • Cookies: 328
    • View Profile
    • EvilZone
IP leak affecting VPN providers with port forwarding
« on: November 27, 2015, 02:10:07 am »
https://www.perfect-privacy.com/blog/2015/11/26/ip-leak-vulnerability-affecting-vpn-providers-with-port-forwarding/

Vulnerability “Port Fail” reveals real IP address
We have discovered a vulnerability in a number of providers that allows an attacker to expose the real IP address of a victim. “Port Fail” affects VPN providers that offer port forwarding and have no protection against this specific attack. Perfect Privacy users are protected from this attack.

This IP leak affects all users: The victim does not need to use port forwarding, only the attacker has to set it up.

We have tested this with nine prominent VPN providers that offer port forwarding. Five of those were vulnerable to the attack and have been notified in advance so they could fix this issue before publication. However, other VPN providers may be vulnerable to this attack as we could not possibly test all existing VPN providers.
[09:27] (+lenoch) iTpHo3NiX can even manipulate me to suck dick
[09:27] (+lenoch) oh no that's voluntary
[09:27] (+lenoch) sorry

Offline Katheudo

  • Peasant
  • *
  • Posts: 83
  • Cookies: 14
  • What anti-virus do you have? - "Common Sense 2015"
    • View Profile
Re: IP leak affecting VPN providers with port forwarding
« Reply #1 on: December 01, 2015, 08:08:17 pm »
Private Internet Access have already released patches for their servers and client programs. Both for Linux and Windows.

Linux Beta App: https://www.privateinternetaccess.com/forum/discussion/1940/pia-vpn-app-linux-beta

Windows: https://www.privateinternetaccess.com/pages/client-support/

Save people searching if they use this VPN provider...
Its nice to be important but always important to be nice!

Offline Architect

  • Sir
  • ***
  • Posts: 428
  • Cookies: 56
  • STFU
    • View Profile
    • Rootd IRC
Re: IP leak affecting VPN providers with port forwarding
« Reply #2 on: December 06, 2015, 05:01:43 pm »
I can attest to this. I was part of a small team to investigate <large and widely used VPN network here> for this reason and it all came down to server side weaknesses that, as it turns out, are very difficult to patch for this type of vuln.

Good luck every other company that is vulnerable. This will cost thousands to have professionally and efficiently resolved.