‘TunnelVision’ Attack Leaves Nearly All VPNs Vulnerable to Spying
ID: db22fd69-b427-56db-95f2-d698c7ee3654
STIX ID: report--db22fd69-b427-56db-95f2-d698c7ee3654
Feed Name: WIRED Security
Leviathan Security researchers describe “TunnelVision”, a technique that abuses DHCP option 121 to push specific routes to a VPN client’s routing table so that VPN-protected traffic is diverted through a malicious DHCP gateway and transmitted unencrypted; Android is immune but most other OSes lack complete fixes. The report includes PoC behavior, attacker requirements (network administrative control or a rogue DHCP on the local LAN), limited mitigations (VMs with non-bridged adapters, mobile hotspots, firewall rules), and the privacy and de-anonymization risks posed by the attack.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
