Client-Side Vulnerabilities in Commercial VPNs

  • Thanh BuiEmail author
  • Siddharth Rao
  • Markku Antikainen
  • Tuomas Aura
Conference paper
Part of the Lecture Notes in Computer Science book series (LNCS, volume 11875)


Internet users increasingly rely on commercial virtual private network (VPN) services to protect their security and privacy. The VPN services route the client’s traffic over an encrypted tunnel to a VPN gateway in the cloud. Thus, they hide the client’s real IP address from online services, and they also shield the user’s connections from perceived threats in the access networks. In this paper, we study the security of such commercial VPN services. The focus is on how the client applications set up VPN tunnels, and how the service providers instruct users to configure generic client software. We analyze common VPN protocols and implementations on Windows, macOS and Ubuntu. We find that the VPN clients have various configuration flaws, which an attacker can exploit to strip off traffic encryption or to bypass authentication of the VPN gateway. In some cases, the attacker can also steal the VPN user’s username and password. We suggest ways to mitigate each of the discovered vulnerabilities.


  1. 1.
  2. 2.
  3. 3.
  4. 4.
  5. 5.
  6. 6.
    SoftEther VPN project.
  7. 7.
  8. 8.
  9. 9.
  10. 10.
  11. 11.
    Aboba, B., Blunk, L., Vollbrecht, J., Carlson, J., Levkowetz, H.: Extensible authentication protocol (EAP). RFC 3748 (2004)Google Scholar
  12. 12.
    Appelbaum, J., Ray, M., Koscher, K., Finder, I.: vpwns: virtual pwned networks. In: USENIX Workshop on Free and Open Communications on the Internet. USENIX Association (2012)Google Scholar
  13. 13.
    Atkinson, R., Kent, S.: Security architecture for the Internet protocol. RFC 4301 (1998)Google Scholar
  14. 14.
    Bui, T., Rao, S.P., Antikainen, M., Bojan, V.M., Aura, T.: Man-in-the-machine: exploiting ill-secured communication inside the computer. In: USENIX Security 2018. USENIX Association (2018)Google Scholar
  15. 15.
  16. 16.
    Fazal, L., Ganu, S., Kappes, M., Krishnakumar, A.S., Krishnan, P.: Tackling security vulnerabilities in VPN-based wireless deployments. In: ICC (2004)Google Scholar
  17. 17.
    Felsch, D., Grothe, M., Schwenk, J., Czubak, A., Szymanek, M.: The dangers of key reuse: practical attacks on IPsec IKE. In: USENIX Security 2018. USENIX Association (2018)Google Scholar
  18. 18.
    Hamzeh, K., Pall, G., Verthein, W., Taarud, J., Little, W., Zorn, G.: Point-to-point tunneling protocol (PPTP). RFC 2637 (1999)Google Scholar
  19. 19.
    Horst, M., Grothe, M., Jager, T., Schwenk, J.: Breaking PPTP VPNs via RADIUS encryption. In: Foresti, S., Persiano, G. (eds.) CANS 2016. LNCS, vol. 10052, pp. 159–175. Springer, Cham (2016). Scholar
  20. 20.
    Hurst, R., Palekar, A.: Microsoft EAP CHAP extensions. IETF Draft (2007)Google Scholar
  21. 21.
    Kaufman, C., Hoffman, P., Nir, Y., Eronen, P., Kivinen, T.: Internet key exchange protocol version 2 (IKEv2). RFC 7296 (2014)Google Scholar
  22. 22.
    Marlinspike, M., Ray, M.: Divide and conquer: Cracking MS-CHAPv2 with a 100% success rate (2012).
  23. 23.
    Microsoft: Routing and remote access service.
  24. 24.
  25. 25.
    Microsoft: Secure Socket Tunneling Protocol (SSTP).
  26. 26.
    Mudge, Schneier, B.: Cryptanalysis of microsoft’s point-to-point tunneling protocol (PPTP). In: Proceedings of the 5th ACM Conference on Communications and Computer Security. ACM Press (1998)Google Scholar
  27. 27.
    Nafeez, A.: Compression Oracle attacks on VPN networks. Blackhat, USA (2018)Google Scholar
  28. 28.
    Pall, G., Zorn, G.: Microsoft point-to-point encryption (MPPE) protocol. RFC 3078 (2001)Google Scholar
  29. 29.
    Pereira, R., Beaulieu, S.: Extended Authentication within ISAKMP/Oakley (XAUTH). IETF Draft (1999)Google Scholar
  30. 30.
    Perta, V.C., Barbera, M.V., Tyson, G., Haddadi, H., Mei, A.: A glance through the VPN looking glass: IPv6 leakage and DNS hijacking in commercial VPN clients. In: Proceedings on Privacy Enhancing Technologies (2015)CrossRefGoogle Scholar
  31. 31.
    Schneier, B., Mudge, Wagner, D.: Cryptanalysis of Microsoft’s PPTP authentication extensions (MS-CHAPv2). In: Secure Networking–CQRE. LNCS, vol. 1740, pp. 192–203. Springer, Heidelberg (1999). Scholar
  32. 32.
    Simpson, W.: The point-to-point protocol (PPP). RFC 1661 (1994)Google Scholar
  33. 33.
    Wood, D., Stoss, V., Chan-Lizardo, L., Papacostas, G.S., Stinson, M.E.: Virtual private networks. In: International Conference on Private Switching Systems and Networks (1988)Google Scholar

Copyright information

© Springer Nature Switzerland AG 2019

Authors and Affiliations

  • Thanh Bui
    • 1
    Email author
  • Siddharth Rao
    • 1
  • Markku Antikainen
    • 1
  • Tuomas Aura
    • 1
  1. 1.Aalto UniversityEspooFinland

Personalised recommendations