meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, May 7th, 2024

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 7 May 2024

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. VPN Routing Leaks; Mullvad VPN Traffic Leak; Tiny Proxy unpatches RCE Vuln;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, May 7, 2020,

0:04.0

4 edition of the Sands and its Storm Center's Stormcast.

0:08.1

My name is Johannes Ulrich, and I'm recording from San Francisco, California.

0:14.1

Today we got two different VPN-related vulnerabilities.

0:18.9

The first one affects multiple VPN implementations and relies on DHCP options to configure routing.

0:28.2

The vulnerability was documented by researchers from Leviton Security Group.

0:33.5

For example, as I record this podcast, I'm connected to a hotel wireless network. To

0:40.4

connect to the network, I need to accept a DHCP lease. This lease typically includes at least

0:47.8

a default gateway, an IP address, and possibly DNS servers. The VPN is only enabled after the laptop is connected to the local network.

0:58.0

After all, it has to reach the VPN server.

1:01.9

A decent VPN will usually override the DNS servers provided by the HCP,

1:07.8

so that's not the problem here.

1:09.7

And then add a new route that will send all traffic that's not local to the VPN interface.

1:16.6

However, DHCP has an option to configure specific routes.

1:22.6

This option, option number 121, is implemented on many current operating systems.

1:29.9

I believe Android was an exception and has been around for about 20 years.

1:36.8

Linux has a feature called Network Namespaces that can be used to overwrite these routing rules.

1:43.2

So Linux can be configured to actually prevent some of the issues.

1:49.4

But basically, what's happening is that the DHCP server will advertise a more specific route

1:55.5

using Option 121.

1:58.0

Typically, if they're conflicting routes to a particular destination, the more specific one is being used.

2:04.8

And that's how an attacker who has control over the local DHCP server could trick you to leak some traffic outside of the VPN.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.