Jump to content

Routing ‘Feature’ Can Expose VPN Users’ Real IP-Addresses


NelsonG

Recommended Posts

[img]http://torrentfreak.com/images/ip-address.png[/img]A few weeks ago we covered a [url="https://torrentfreak.com/huge-security-flaw-can-expose-vpn-users-real-ip-adresses-151126/"]security flaw[/url] which allowed attackers to uncover the real IP-addresses of VPN users, if their providers allow forwarding on their network.

The news was picked up widely as it affected millions of users. However, it is just one of the many possible exploits VPN users are facing.

This week another issue was highlighted by [url="https://medium.com/@ValdikSS/another-critical-vpn-vulnerability-and-why-port-fail-is-bullshit-352b2ebd22e2#.bvtyzf9no"]ProstoVPN[/url]. This “vulnerability” affects both users with a direct connection and those with routers that have UPnP port forwarding enabled.

The issue boils down to a rather basic network routing feature where UDP listening software (e.g. torrent clients) respond to packets that are sent to the user’s ISP IP-address, through the VPN interface.

This means that a potential attacker can link a VPN IP-address to a user’s ISP IP-address.

[b]The problem[/b]
</br>[img]http://torrentfreak.com/images/route.png[/img]

The issue affects users on all operating systems and is not always easy to fix on the user end. VPN providers with custom software can address it, but with the standard OpenVPN software users have to take action themselves.

While the scope of the issue is large, as many users and providers have yet to address the issue, it requires quite a bit of effort to carry out an attack. It basically requires the attacker to send UDP packets to the entire Internet.

In addition, there’s the possibility of false positives which means that it’s harder to pinpoint the exact ISP IP-address. With this in mind, it seems unlikely that monitoring companies will attempt to expose every BitTorrent user with a VPN.

ProstoVPN informs TorrentFreak that they alerted 11 providers, and two confirmed that they have fixed the issue with a software update.

“Information about this ‘feature’ was sent to 11 VPN providers and only five of them replied: Private Internet Access and Perfect Privacy have released updated software which blocks incoming connections.”

Not all providers were equally responsive and one suggested that the issue should be addressed by the users. There is some truth to that, but the same provider does protect its users against similar problems on the user-side, such as DNS, IPv6 and WebRTC leaks.

While there’s no need for outright panic, it is a good development that these type of problems are being highlighted. It prompts VPN providers to take action and users to remain vigilant.

That said, it also shows that 100% anonymity is pretty much impossible.

More details on the routing “feature” and its consequences are available in [url="https://medium.com/@ValdikSS/another-critical-vpn-vulnerability-and-why-port-fail-is-bullshit-352b2ebd22e2#.4pz9k7m1t"]ProstoVPN’s article[/url] and in the statement [url="https://www.perfect-privacy.com/blog/2015/12/21/wrong-way-security-problem-exposes-real-ip/"]published[/url] by Perfect Privacy.

Source: [url="https://torrentfreak.com"]TorrentFreak[/url], for the latest info on copyright, file-sharing, [url="http://torrentfreak.com/top-popular-torrent-sites-2015-150104/"]torrent sites[/url] and [url="http://torrentfreak.com/anonymous-vpn-service-provider-review-2015-150228/"]ANONYMOUS VPN services[/url].

[url="http://feed.torrentfreak.com/~ff/Torrentfreak?a=rmwY-V49jes:dpWzFTkfeFw:yIl2AUoC8zA"][img]http://feeds.feedburner.com/~ff/Torrentfreak?d=yIl2AUoC8zA[/img]</img>[/url] [url="http://feed.torrentfreak.com/~ff/Torrentfreak?a=rmwY-V49jes:dpWzFTkfeFw:D7DqB2pKExk"][img]http://feeds.feedburner.com/~ff/Torrentfreak?i=rmwY-V49jes:dpWzFTkfeFw:D7DqB2pKExk[/img]</img>[/url][img]http://feeds.feedburner.com/~r/Torrentfreak/~4/rmwY-V49jes[/img]

[url=http://feed.torrentfreak.com/~r/Torrentfreak/~3/rmwY-V49jes/]View the full article[/url]

Link to comment
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Our picks

    • Wait, Burning Man is going online-only? What does that even look like?
      You could have been forgiven for missing the announcement that actual physical Burning Man has been canceled for this year, if not next. Firstly, the nonprofit Burning Man organization, known affectionately to insiders as the Borg, posted it after 5 p.m. PT Friday. That, even in the COVID-19 era, is the traditional time to push out news when you don't want much media attention. 
      But secondly, you may have missed its cancellation because the Borg is being careful not to use the C-word. The announcement was neutrally titled "The Burning Man Multiverse in 2020." Even as it offers refunds to early ticket buyers, considers layoffs and other belt-tightening measures, and can't even commit to a physical event in 2021, the Borg is making lemonade by focusing on an online-only version of Black Rock City this coming August.    Read more...
      More about Burning Man, Tech, Web Culture, and Live EventsView the full article
      • 0 replies
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
×
×
  • Create New...