Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » The NachoVPN tool exploits flaws in popular VPN clients to hack the system
Global Security

The NachoVPN tool exploits flaws in popular VPN clients to hack the system

AdminBy AdminDecember 3, 2024No Comments3 Mins Read
Severe VPN Flaws
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


December 3, 2024Ravi LakshmananEndpoint Security / Vulnerability

Serious Disadvantages of VPNs

Cybersecurity researchers have discovered a number of flaws affecting Palo Alto Networks and SonicWall virtual private network (VPN) clients that could potentially be used for remote code execution on Windows and macOS systems.

“By targeting VPN clients’ implicit trust in servers, attackers can manipulate client behavior, execute arbitrary commands, and gain high levels of access with minimal effort.” — AmberWolf. said in the analysis.

In a hypothetical attack scenario, this comes in the form of a fake VPN server that can trick customers into downloading malicious updates, which can cause unintended consequences.

The result of the investigation is a proof-of-concept (PoC) attack tool called NachoVPN which can impersonate such VPN servers and exploit vulnerabilities to achieve privileged code execution.

Cyber ​​security

The identified flaws are listed below –

  • CVE-2024-5921 (CVSS Score: 5.6) – Insufficient certificate validation vulnerability affecting Palo Alto Networks GlobalProtect for Windows, macOS, and Linux, which allows the program to connect to arbitrary servers, leading to the deployment of malware (resolved in version 6.2.6 for Windows)
  • CVE-2024-29014 (CVSS Score: 7.1) – A vulnerability affecting the SonicWall SMA100 NetExtender Windows client that could allow an attacker to execute arbitrary code when processing an End Point Control (EPC) client update. (Affects 10.2.339 and earlier, addressed in 10.2.341)

Palo Alto Networks emphasized that an attacker must either have access as a local non-administrative operating system user or be on the same subnet to install malicious root certificates on an endpoint and install malware signed by those root certificates on it. end point.

Serious Disadvantages of VPNs

By doing so, the GlobalProtect app can be a weapon to steal a victim’s VPN credentials, execute arbitrary code with elevated privileges, and install malicious root certificates that can be used to facilitate other attacks.

Similarly, an attacker could trick a user into connecting their NetExtender client to a malicious VPN server and then deliver a fake EPC client update that is signed with a valid but stolen certificate to eventually execute code with SYSTEM privileges.

Cyber ​​security

“Attackers can use a custom URI handler to force a NetExtender client to connect to their server,” said AmberWolf. “Users only need to visit a malicious website and accept a browser prompt or open a malicious document for the attack to be successful.”

Although there is no evidence that these flaws have been exploited in the wild, users of Palo Alto Networks GlobalProtect and SonicWall NetExtender are encouraged to apply the latest patches to protect against potential threats.

Development is underway as researchers from Bishop Fox in detail his approach to decrypting and analyzing the firmware embedded in SonicWall firewalls to further assist in vulnerability research and create fingerprinting capabilities to assess the current security posture of SonicWall firewalls based on Internet images.

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025

Meta adds support to logy for Android and iOS users

June 19, 2025

Linux’s new drawbacks provide complete root access via PAM and Udisks in major distributions

June 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025

Meta adds support to logy for Android and iOS users

June 19, 2025

Linux’s new drawbacks provide complete root access via PAM and Udisks in major distributions

June 19, 2025

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.