encbladexp, to security German
@encbladexp@chaos.social avatar

Schicke Seite: https://www.tunnelvisionbug.com

Mal wieder ein CVE mit Logo, ich finde das Logo aber dieses mal weniger Hübsch.

#tunnelvision #vpn #openvpn #security #privacy

governa, to random
@governa@fosstodon.org avatar

New Attack Allows Hijacking of Traffic via DHCP Manipulation

https://thehackernews.com/2024/05/new-tunnelvision-attack-allows.html

johnleonard, to privacy
@johnleonard@mastodon.social avatar

'TunnelVision' bug potentially allows snooping on all VPNs

Operating system features can be manipulated to divert traffic away from encrypted VPN tunnel

https://www.computing.co.uk/news/4205875/tunnelvision-bug-potentially-allows-snooping-vpns

#vpn #vpns #tunnelvision #privacy #infosec #technews

bortzmeyer, to random French
@bortzmeyer@mastodon.gougere.fr avatar

Je ne connaissais pas le RFC 3442.

C'est lui qui normalise l'option DHCP 121 qui permet l'attaque contre les .

https://arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose/

Doomed_Daniel, to random
@Doomed_Daniel@mastodon.gamedev.place avatar

I haven't tried to reproduce that #TunnelVision DHCP vulnerability, but as far as I can tell a good way to mitigate it could be to ignore those DHCP option type 121 settings from the server (which add static routes for IP subnets configured by the server, which could overwrite routes set by a VPN and thus circumvent the VPN) - unless those static routes are needed to reach your VPN endpoint in the first place, of course.

At https://mastodon.gamedev.place/ I wrote how this could be done on Linux.

tara, to wireguard
@tara@hachyderm.io avatar

An excellent solution from @solene 👇 to protect #Wireguard tunnels on #OpenBSD from #TunnelVision attacks.

Have a closer look at the example about rdomain 0 and rdomain 1

https://dataswamp.org/~solene/2021-10-09-openbsd-wireguard-exit.html

#bsd

scott, to random
@scott@carfree.city avatar

just watched #TunnelVision, the unauthorized #SFBART film. Highly recommend. Even my suburbanite friend who BARTed in from South City loved it. There's tickets available for a matinee this Saturday and an encore showing a week from tomorrow. https://roxie.com/film/tunnel-vision/

lauraehall, to random
@lauraehall@xoxo.zone avatar

Welcome to my Friday cabinet of curiosities, a roundup of stuff I enjoyed this week! Today’s links include the world’s last internet cafes, a secret train ride, and yes, Barbie and Oppenheimer (—but not Barbenheimer) 🖥️🚆👠

Three plastic skeletons on a colorful background

lauraehall,
@lauraehall@xoxo.zone avatar
  1. Timelapse photographer Vincent Woo attached a camera to a BART train in the Bay Area, capturing footage to create “Tunnel Vision: An Unauthorized BART Ride.”

“A hidden world is revealed through intersecting passageways, flashes of graffiti, and sections of track only witnessed by BART operators.”

Watch the the 1 hour 30 minute documentary here: https://youtu.be/3-Jrp6it9Ss

#Trains #Documentary #PublicTransportation #BART #BayArea #TunnelVision

kubikpixel, to business
@kubikpixel@chaos.social avatar

Sorry wie es momentan beworben wird war noch nie Sicher und ein klarer und nur bei den wenigsten Anbietern auch vertrauenswürdig - Da sind ganz dubiose & gruselige Firmengeflechte im Hintergrund. Dann kommen ein paar und bestätigen deine Befürchtungen. VPN macht durch aus Sinn in einem aber eben nicht so.

»21 Million VPN User Records durchgesickert; VPN am Ende?«

🕳️ https://www.borncity.com/blog/2022/05/16/21-million-vpn-user-records-durchgesickert-vpn-am-ende/

kubikpixel, (edited )
@kubikpixel@chaos.social avatar

🧵 …das VPN Internetverbindungen nicht per-se sicher sind, hatte ich schon über einem Jahr erklärt (siehe Toots oben). Doch es wird tragisch lustiger wenn jetzt sogar IT Giganten neuartig deswegen auch betroffen sind.

[ENG]
»Novel attack against virtually all VPN apps neuters their entire purpose:
TunnelVision vulnerability has existed since 2002 and may already be known to attackers.«

🔓 https://arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose/


#vpn #novel #tunnelvision #internet #it #anonymitat #privatsphare #itsicherheit

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • magazineikmin
  • khanakhh
  • mdbf
  • slotface
  • ethstaker
  • tacticalgear
  • Youngstown
  • kavyap
  • InstantRegret
  • DreamBathrooms
  • thenastyranch
  • everett
  • rosin
  • megavids
  • GTA5RPClips
  • cubers
  • Durango
  • normalnudes
  • ngwrru68w68
  • osvaldo12
  • cisconetworking
  • tester
  • modclub
  • Leos
  • provamag3
  • anitta
  • lostlight
  • All magazines