<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>vulnerability Archives - Linux Windows and android Tutorials</title>
	<atom:link href="https://www.osradar.com/tag/vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.osradar.com</link>
	<description>tutorials and news and Seurity</description>
	<lastBuildDate>Fri, 06 Dec 2019 19:18:00 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=5.8.12</generator>
	<item>
		<title>VPNs can be hacked thanks to a new vulnerability</title>
		<link>https://www.osradar.com/new-linux-vulnerability-compromises-vpn/</link>
					<comments>https://www.osradar.com/new-linux-vulnerability-compromises-vpn/#respond</comments>
		
		<dc:creator><![CDATA[angeloma]]></dc:creator>
		<pubDate>Sat, 07 Dec 2019 00:02:00 +0000</pubDate>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[desktop]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[server]]></category>
		<category><![CDATA[vpn]]></category>
		<category><![CDATA[vulnerability]]></category>
		<guid isPermaLink="false">https://www.osradar.com/?p=16086</guid>

					<description><![CDATA[<p>While Unix-based systems are much safer than Windows, they are not exempt from problems. This time a new vulnerability has been reported that affects VPNs. So today we will talk to you about it. Recently, a new vulnerability has been published that affects Unix-based systems. This new vulnerability registered under the code CVE-2019-14899, shows us [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.osradar.com/new-linux-vulnerability-compromises-vpn/">VPNs can be hacked thanks to a new vulnerability</a> appeared first on <a rel="nofollow" href="https://www.osradar.com">Linux  Windows and android  Tutorials</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><strong>While Unix-based systems are much safer than Windows, they are not exempt from problems. This time a new vulnerability has been reported that affects VPNs. So today we will talk to you about it.</strong></p>
<p>Recently, a new vulnerability has been published that affects Unix-based systems. This new vulnerability registered under the code <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14899" target="_blank" rel="noopener noreferrer">CVE-2019-14899</a>, shows us that malicious users can compromise the security of VPNs. It has been reported by the University of New Mexico.</p>
<p>What do we mean by compromising security? Well, that an external user can know if a user is connected to a VPN or visiting a certain website. <strong>However, it could also hijack all TCP connections that pass through that VPN</strong>. That is to say, connections to <strong>databases, FTP servers or even entire websites of that server would be at risk.</strong></p>
<p>According to the researchers who have detected the new vulnerability, the steps for the attack are as follows:</p>
<ol>
<li>Determining the VPN client’s virtual IP address.</li>
<li>Using the virtual IP address to make inferences about active connections.</li>
<li>finally, using the encrypted replies to unsolicited packets to determine the sequence and acknowledgment numbers of the active connection to hijack the TCP session.</li>
</ol>
<h2>Which systems are affected for this new vulnerability?</h2>
<p>The affected systems are quite a lot because they cover different versions of Linux, as well as BSD and probably macOS.</p>
<p>So, the expert researchers, has drawn up a non-exhaustive list of distributions that are compromised. The list is as follows:</p>
<ul>
<li><a href="https://www.osradar.com/ubuntu-19-10-available/" target="_blank" rel="noopener noreferrer">Ubuntu 19.10</a> (systemd)</li>
<li><a href="https://www.osradar.com/tag/fedora" target="_blank" rel="noopener noreferrer">Fedora</a> (systemd)</li>
<li><a href="https://www.osradar.com/tag/buster" target="_blank" rel="noopener noreferrer">Debian 10.2</a> (systemd)</li>
<li>Arch 2019.05 (systemd)</li>
<li>Manjaro 18.1.1 (systemd)</li>
<li>Devuan (sysV init)</li>
<li>MX Linux 19 (Mepis+antiX)</li>
<li>Linux Void (runit)</li>
<li>Slackware 14.2 (rc.d)</li>
<li>Deepin (rc.d)</li>
<li>FreeBSD (rc.d)</li>
<li>OpenBSD (rc.d)</li>
</ul>
<p>So, we&#8217;re talking about a lot of Linux users.</p>
<h2>What can we do about it?</h2>
<p>This is a vulnerability that happens at a very technical level. Therefore, it is expected that Linux distributions will be launched to make the patch that definitively covers the vulnerability.</p>
<p>However, the experts give some possible temporary solutions:</p>
<ol>
<li>Turning reverse path filtering on</li>
<li>Bogon filtering</li>
<li>Encrypted packet size and timing</li>
</ol>
<p>Anyway, keep your system up to date because the patch should be here soon.</p>
<p>So, for more information, I leave you the link to the<a href="https://seclists.org/oss-sec/2019/q4/122" target="_blank" rel="noopener noreferrer"> original publication</a> of the new vulnerability. There you will find many technical details about it.</p>
<p>The post <a rel="nofollow" href="https://www.osradar.com/new-linux-vulnerability-compromises-vpn/">VPNs can be hacked thanks to a new vulnerability</a> appeared first on <a rel="nofollow" href="https://www.osradar.com">Linux  Windows and android  Tutorials</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.osradar.com/new-linux-vulnerability-compromises-vpn/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
