Kryptowire company specialists conducted automatic analysis of applications that were preinstalled on Android-smartphones, and discovered…
Typically, a VPN client-server architecture includes a front end (a GUI application for the user), a back end (which accepts commands from the front end), and OpenVPN (a back end managed service that is responsible for VPN connections).
Since most of the time the dedicated socket channel through which the interface controls the backend uses the cleartext protocol without any authentication, “anyone with access to the local TCP port that the backend is listening on can potentially load the OpenVPN configuration, and force the server side to create a new instance of OpenVPN with this configuration,” the experts say.
Basically, the attacker only needs to trick the victim into visiting a malicious site with JavaScript designed to send a blind POST POST request locally (to transmit commands to the VPN client server side). The company says this is a classic example of an SSRF vulnerability.
Since the backend server will automatically parse and execute any valid commands it receives, it can be instructed to load a remote configuration file containing specific commands leading to code execution or payload installation.
Fortunately, in order to remotely execute the code, the hacker will need access to the SMB server under his control, that is, the attacker must be on the same domain network as the target system, or the victim’s computer must be allowed SMB access to external servers.
Let me remind you that we also reported that Vulnerability allows attackers to listen and intercept VPN connections.
News-xheluza.cc is a domain that tries to trick you into subscribing to its browser notifications…
Initiateextremelyoriginalthe-file.top is a site that tries to trick you into subscribing to its browser notifications…
Chernars.com is a domain that tries to force you into subscribing to its browser notifications…
Eclipse-adblocker.pro is a site that tries to trick you into clik to its browser notifications…
Initiateadvancedcompletelythe-file.top is a site that tries to force you into subscribing to its browser notifications…
Pbmsoultions.com is a domain that tries to trick you into clik to its browser notifications…