Page 1 of 1

VPN hijacking on Linux (and beyond) systems

Posted: Sun Dec 08, 2019 11:44 pm
by thepiney
Came across this on Distrowatch Weekly --> https://distrowatch.com/weekly.php?issue=20191209#news

Affecting Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android.

William Tolley has disclosed a severe VPN-related problem in most current systems: "I am reporting a vulnerability that exists on most Linux distros, and other *nix operating systems which allows a network adjacent attacker to determine if another user is connected to a VPN, the virtual IP address they have been assigned by the VPN server, and whether or not there is an active connection to a given website. Additionally, we are able to determine the exact seq and ack numbers by counting encrypted packets and/or examining their size. This allows us to inject data into the TCP stream and hijack connections." There are various partial mitigations available, but a full solution to the problem has not yet been worked out. Most VPNs are vulnerable, but Tor evidently is not.
More information ---> https://lwn.net/Articles/806546/

Re: VPN hijacking on Linux (and beyond) systems

Posted: Mon Dec 09, 2019 6:03 am
by Midas
Wow! That's like a "your VPN is now void" kind of vulnerability -- repressive regimes are sure to applaud... :shock:

Re: VPN hijacking on Linux (and beyond) systems

Posted: Mon Dec 09, 2019 10:40 am
by bitcoin
i just assume i'm being spied on whenever i use the internet by various scumbag govt organizations and private sleazeballs as well

Re: VPN hijacking on Linux (and beyond) systems

Posted: Sun Feb 02, 2020 4:55 am
by Midas
All hope is not lost...

Linux creator Linus Torvalds merged David Miller's net-next into his source tree for the Linux 5.6 kernel. This merger added plenty of new network-related drivers and features to the upcoming 5.6 kernel, with No.1 on the list being simply "Add WireGuard."
arstechnica.com /gadgets/2020/01/linus-torvalds-pulled-wireguard-vpn-into-the-5-6-kernel-source-tree/


Just in case you're left wondering, Wireguard is a VPN solution comparable to IPsec and OpenVPN. Here's hoping this spills into Windows, too...

Re: VPN hijacking on Linux (and beyond) systems

Posted: Tue Feb 04, 2020 5:51 pm
by thepiney
Some more information on WireGuard --> https://www.wireguard.com