BestOfGeeks: Critical Port Fail Vulnerability Reveals Real IP Addresses of VPN Users 

Critical Port Fail Vulnerability Reveals Real IP Addresses of VPN Users


Noredine BAHRI
Noredine BAHRI
  • Technical Writer
  • Entrepreneur
  • Founder and CEO
  • Developer
  • Blogger and IT Analyst
2015-11-29 18:40:46

| Share
| Share
| Share
Critical Port Fail Vulnerability Reveals Real IP Addresses of VPN Users

A newly discovered flaw affecting all VPN protocols and operating systems has the capability to reveal the real IP-addresses of users' computers, including BitTorrent users, with relative ease.

The vulnerability, dubbed Port Fail by VPN provider Perfect Privacy (PP) who discovered the issue, is a simple port forwarding trick and affects those services that:

Allow port forwarding

Have no protection against this specific attack

Port Forwarding trick means if an attacker uses the same VPN (Virtual Private Network) as the victim, then the real IP-address of the victim can be exposed by forwarding Internet traffic to a specific port.

"The crucial issue here is that a VPN user connecting to his own VPN server will use his default route with his real IP address, as this is required for the VPN connection to work," Perfect Privacy wrote in a blog post on Thursday.

Also Read: This $10 Device Can Guess and Steal Your Next Credit Card Number before You have Received It

Port Fail affects all VPN protocols including…

OpenVPN

IPSec

…as well as applies to all operating systems, posing a huge privacy risk.

How Does 'Port Fail' Work?

A successful IP address leak attack requires an attacker to be on the same VPN network as the victim and to know the victim's VPN exit IP address, which could be discovered by tricking a victim into visiting a website control controlled by the attacker.

For example, an attacker with port forwarding enabled can see the request from the victim's actual IP addresses by tricking the victim into opening an image file.

The same attack is possible for BitTorrent users, but, in this case, there is no need for the attacker to redirect the victim to their page.

In this case, the attacker only with the activated port forwarding for the default BitTorrent port, can expose the real IP-address of a VPN user on the same network.

Also Read:Dell - Laptops are infected with Superfish-Like pre-installed Malware​

Affected VPN Providers

The flaw affected various large VPN providers. Perfect Privacy tested nine VPN providers out of which five were found to be vulnerable to this flaw and were alerted last week.

VPN providers including Private Internet Access (PIA), Ovpn.to and nVPN have fixed the issue before publication.

However, the company warned, "other VPN providers may be vulnerable to this attack as we could not possibly test all."

VPN aims to make you sure that your real identity remains anonymous on the Internet so that nobody could track the origin of your connection back to you, but this newly discovered flaw shows that it's quite easy to bypass this on some VPN providers.

 



WITH THE LENOVO RAZER EDITION PC, TWO COMPANIES LAUNCH A GAMING HARDWARE PARTNERSHIP
WITH THE LENOVO RAZER EDITION PC, TWO COMPANIES LAUNCH A GAMING HARDWARE PARTNERSHIP
WITH THE LENOVO RAZER EDITION PC, TWO COMPANIES LAUNCH A GAMING HARDWARE PARTNERSHIP

.
First trailer Rampage : New Adventure For The Rock fights giant beasts
First trailer Rampage : New Adventure For The Rock fights giant beasts

Sit back, relax and watch the 30-foot wolf and 1,000-pound gorilla wreck Chicago as the 1986 arcade game comes to life.   (adsbygoog


First trailer Rampage : New Adventure For The Rock fights giant beasts
The 4 Best Eating Plans You Need in Place This Thanksgiving

In the week leading up to Thanksgiving, I talk to many patients about how to approach the big day in a way that balances their two competing prioritie


First trailer Rampage : New Adventure For The Rock fights giant beasts
USA Senators troll Facebook with fake ad campaign

Senators Mark Warner (Va.) and Amy Klobuchar (Minn.) created a Facebook page for a fictional political group — Americans for Disclosure Solution


First trailer Rampage : New Adventure For The Rock fights giant beasts
10 Picture Of The Newest Lamborghini Most Outrageous Super Extreme Idea

he newest, most outrageous, “super extreme” idea from Lamborghini is a box. Well, metaphorically. The Italian supercar giant unveiled a


First trailer Rampage : New Adventure For The Rock fights giant beasts
Apple tactics to let developers offer discounts on in-app subscriptions

Apple plans to give developers more freedom over the introductory pricing levels of in-app subscriptions. As referenced in the iOS 11.2 beta release n


First trailer Rampage : New Adventure For The Rock fights giant beasts
SAMSUNG Given $120 M To APPLE in slide-to-unlock patent battle

After many years of fighting in the courts, Apple has finally claimed victory over Samsung to the count of $120 million. The case revolved aro



© 2013-2017 best of geeks. All rights reserved.