{"id":331706,"date":"2019-12-06T10:23:09","date_gmt":"2019-12-06T08:23:09","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=331706"},"modified":"2019-12-06T10:23:59","modified_gmt":"2019-12-06T08:23:59","slug":"security-flaw-lets-attackers-hijack-vpn-connections","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/331706-security-flaw-lets-attackers-hijack-vpn-connections.html","title":{"rendered":"Security flaw lets attackers hijack VPN connections"},"content":{"rendered":"<p>A <a href=\"https:\/\/seclists.org\/oss-sec\/2019\/q4\/122\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>research team<\/strong><\/a> has discovered a flaw in Unix-based operating systems, including Linux, Android, and macOS, which allows attackers to hijack and tamper with VPN connections.<\/p>\n<p>The vulnerability exploits how these operating systems reply to unexpected network packet requests.<\/p>\n<p>&#8220;[The flaw] allows a network adjacent attacker to determine if another user is connected to a VPN, the virtual IP address they have been assigned by the VPN server, and whether or not there is an active connection to a given website,&#8221; said the team in its report.<\/p>\n<p>&#8220;Additionally, we are able to determine the exact seq and ack numbers by counting encrypted packets and\/or examining their size. This allows us to inject data into the TCP stream and hijack connections.&#8221;<\/p>\n<p>Operating systems on which the team successfully exploited the vulnerability include:<\/p>\n<ul>\n<li>Ubuntu 19.10<\/li>\n<li>Fedora<\/li>\n<li>Debian 10.2<\/li>\n<li>Arch 2019.05<\/li>\n<li>Manjaro 18.1.1<\/li>\n<li>Devuan<\/li>\n<li>MX Linux 19<\/li>\n<li>Void Linux<\/li>\n<li>Slackware 14.2<\/li>\n<li>Deepin<\/li>\n<li>FreeBSD<\/li>\n<li>OpenBSD<\/li>\n<\/ul>\n<p>The research team said that their attack worked against several popular VPN services, including OpenVPN WireGuard,\\ and IKEv2\/IPSec.<\/p>\n<p>&#8220;The VPN technology used does not seem to matter,&#8221; said the research team.<\/p>\n<p>Jason A. Donenfeld, the creator of WireGuard, told <a href=\"https:\/\/www.zdnet.com\/article\/new-vulnerability-lets-attackers-sniff-or-hijack-vpn-connections\/\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>ZDNet<\/strong><\/a> that the issue isn&#8217;t a WireGuard vulnerability, &#8220;but rather something in the routing table code and\/or TCP code on affected operating systems.&#8221;<\/p>\n<h3 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/smartphones\/331678-apples-2021-iphone-wont-have-a-charging-port-report.html\" rel=\"bookmark\">Apple\u2019s 2021 iPhone won\u2019t have a charging port \u2013 Report<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>A security flaw has been uncovered by a research team which allows attackers to hijack and tamper with VPN connections.<\/p>\n","protected":false},"author":341039,"featured_media":89863,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[397,36544,1799,36626,62140,18448,62142],"class_list":["post-331706","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-android","tag-hijack","tag-linux","tag-macos","tag-openvpn","tag-vpn","tag-wireguard"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/331706"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341039"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=331706"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/331706\/revisions"}],"predecessor-version":[{"id":331722,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/331706\/revisions\/331722"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/89863"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=331706"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=331706"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=331706"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}