Showing posts with label Virtual Private Network. Show all posts
Showing posts with label Virtual Private Network. Show all posts

Saturday, 28 November 2015

Leak VPN Providers Can Reveal IP Address Users


A vulnerability in some VPN providers can ensure that the real IP address of users is revealed, warns VPN provider Perfect Privacy. A VPN (Virtual Private Network) is a secure connection between a computer and a server elsewhere on the Internet.

This connection is encrypted which others can not observe. All Internet traffic to and from the computer goes through this route shielded and can on this part will not be overheard. Additionally, VPN users can thus protect their IP address as websites visited only see the IP address of the VPN provider. According Perfect Privacy walk users of some VPN providers still risk their real IP address is known.

Port forwarding

The problem is with VPN providers offering port forwarding. It does not matter whether users of the VPN providers themselves use port forwarding, only the attacker must set it. To determine the IP address of a victim, there must be fulfilled several conditions. For example, the attacker must have an active account with the same VPN provider and the victim. The attacker must know the 'exit' IP address of the victim and the victim to open a file or page.

An attacker who port forwarding is activated can then request to see the image or website which the real IP address of the victim is from. In total, nine tested Perfect Privacy VPN providers, of which five were found vulnerable. These parties have been notified. The problem, however, with other VPN providers are not tested, warns Perfect Privacy.

BitTorrent

According to security expert Darren Martyn can leak be used to expose BitTorrent users who illegally download copyrighted material. To shield their IP address are BitTorrent users who use a VPN service. By leak holders can still see the IP addresses of illegal downloaders. Martyn expects that companies connected with suing copyright infringers concerned will use this vulnerability to sue BitTorrent users.

Monday, 12 October 2015

Companies Hacked Via Leak In Cisco Web VPN


Attackers abuse a vulnerability in the Cisco Clientless SSL VPN to hack into companies and organizations, warns security firm Volexity. The Cisco SSL VPN Service, also referred to as Cisco Web VPN, is a web-based Virtual Private Network (VPN) to employees via their browser to access the corporate network and servers can get.

To log in to the VPN, users must enter a user name and password. A vulnerability in the Cisco Web VPN, which was patched in October 8, 2014, makes it possible to add malicious code to the login page. Remote attackers can do this and have developed a password or other credentials required. Through the malicious code that is placed on the login page it possible to store the credentials of users, which the attackers themselves can then login.

Cisco warned in February this year for attacks where the vulnerability was used, but that still take place, according Volexity. Medical companies, universities, academic institutions, manufacturing companies and think tanks could now be attacked using this method worldwide.

According to the security company, it is not clear whether the vulnerability has been used for all attacks. It is not excluded that some other attacks observed the attackers themselves already had access to the login page and so could add malicious code. It does not matter if companies use two-factor authentication since the second code to be entered when logging can be intercepted using the custom login page.

Wednesday, 5 August 2015

Chinese VPN Service Uses Windows Servers Hacked



A commercial service that Chinese customers VPN connections offering appears to use dozens of hacked Windows servers of organizations and companies abroad, so claims the American security company RSA published today in a report ( pdf ).

The VPN service, which is called by RSA only by the codename "Terracotta", consists of more than 1,500 nodes worldwide.With a Virtual Private Network (VPN) make users through a secure tunnel connection to another server, for example to access the internet from there. This way, the ISP can not view the contents of the traffic, and it is possible to, for example, censored still visit web sites. The Chinese VPN service is thus offered as a way to bypass the firewall and Chinese as a way for users to protect their anonymity.

VPN services generally use their own servers where clients connect to it. In the case of going to the Terra Cotta according to RSA, inter alia, to hacked Windows-based servers from a variety of organizations. RSA researchers argue that the number of new servers from the VPN service will be expanded continuously. In addition, the attackers deliberately opt for Windows servers, because the platform includes VPN services can be configured quickly. A total of 31 Windows servers hacked discovered which were part of the VPN service. All were found to be hacked servers linked to the Internet, and did not use any hardware firewall.

Attack

To take over the servers are brute-force attacks against the administrator account. In case a working combination of username and password is found, the switch forwards a few hours later, the Windows firewall and install the Telnet service.After this, the attackers log in via Remote Desktop and then removing Windows Defender. The next step is the installation of a remote administration tool and create a new Windows account.

Finally the hacked server is configured for VPN service. According to RSA make both end users and cyber spies of the VPN service usage, which is offered in China under different names. In addition, users would not know that they are making use of hacked servers. The reason that the service servers of foreign organizations hacks would mostly related to cost savings.

Monday, 2 March 2015

Explain How They Protect Users VPN Providers

Virtual Private Networks

VPN providers have an important role to Internet users who wish to protect their IP address on the Internet, eg because of privacy reasons or to access services in another country, but which provider now goes best with the privacy and anonymity of users?

A question every year by TorrentFreak states, which give this year nearly 50 VPN providers twelve answer questions about their process. So let providers know if they store logs, under what jurisdiction they fall, what tools they use to prevent abuse, or give them to DMCA takedown requests hearing how users can pay all or whether BitTorrent traffic is permitted.

In addition, make the providers clearly what VPN-compound and encryption algorithm they recommend to users, whether they use their own DNS servers, or physical control over the VPN servers and whether they have a "canary" or warning device to alert users to the Should a court has forbidden them to communicate. It also explains what providers do when they get a court order to get user information and if this has happened before. Here let Anonymizer, BlackVPN and Mullvad know they sometimes ask investigators to get user data.

Mullvad says in these cases did not provide user information, while BlackVPN states that they can identify users only by court order and that they have never received such an order. Anonymizer claims to have received court orders, but no customer data have been transferred. In the overview of TorrentFreak only VPN providers stated that gave answer, and keep records longer than 7 days. Most VPN providers say no to retain logs, although 15 are those who do.

Sunday, 25 January 2015

Chinese Government Blocks VPN Services



The Chinese government has all kinds of VPN services blocked in the country, giving consumers no websites like Facebook and Google can visit more and particularly small foreign companies in China can not connect to their servers and enterprise networks can make abroad.

Via a Virtual Private Network (VPN), it is possible to make a computer is part of a network that is located at a different location. The traffic then runs through a specially constructed tunnel. China VPNs are used inter alia to circumvent government censorship. Using a VPN service make Chinese Internet connect on servers in Europe, from where they can then visit various Web sites that are not accessible in China. Because the traffic through the secure VPN tunnel running the Chinese authorities can not view the contents.

VPN provider Golden Frog announced that users of the VyprVPN service problems have to approach certain VPN servers abroad. The problem is as Golden Frog also with other VPN providers. "From a technical standpoint, it is not caused by server problems, but it's a network problem in China." For the time being of the company in the Netherlands and Hong Kong VPN servers would still be accessible for Chinese users.

According to Richard Robinson, a foreign entrepreneur in China, it is especially small and medium-sized foreign companies that makes the VPN blockade. Many larger companies have in fact direct connections to servers outside the country, so let him across the Associated Press know. In recent weeks, the Chinese government also decided to block all access to Gmail.Similarly, a measure which affects small businesses according to Robinson, as they often use the mail service from Google.