The TunnelVision attack allows for redirection of VPN traffic through DHCP manipulation.

The TunnelVision attack method has been made public, enabling attackers with access to a local network or control over a wireless network to redirect the victim's traffic to their host, bypassing the VPN (instead of sending through the VPN, the traffic will be transmitted in clear text without tunneling to the attacker's system). Any VPN clients that do not use isolated network namespace for directing traffic to the tunnel or do not set up packet filtering rules that block routing VPN traffic through existing physical network interfaces are vulnerable to this issue.

The essence of the attack is that the attacker can run their own DHCP server and use it to send information to clients to alter routing. Specifically, the attacker can exploit the DHCP option 121 (RFC-3442, adopted in 2002), which is designed to provide information about static routes, to make changes in the routing table on the victim's machine and reroute traffic. VPNRedirection is accomplished by setting a series of routes for subnets with the prefix /1, which have a higher priority than the default route with the prefix /0 (0.0.0.0/0). Consequently, traffic that would normally go to the VPN virtual network interface will instead be directed through the physical network interface to the attacker's host on the local network.

The attack can be executed on any operating system that supports DHCP option 121, including Linux, Windows, iOS, and macOS, regardless of the VPN protocol used (Wireguard, OpenVPN, IPsec) and the cipher suite. The Android platform is not susceptible to this attack as it does not process option 121 in DHCP. However, while the attack allows access to the traffic, it does not enable interception of connections or identification of content transmitted using secure application layer protocols, such as TLS and SSH. For example, an attacker cannot determine the content of HTTPS requests but can ascertain which servers they are sent to.

To protect against attacks, outgoing packets addressed to the VPN interface can be restricted at the packet filter level through other network interfaces; block DHCP packets with option 121; use VPN within a separate virtual machine (or container) isolated from the external network, or apply special tunnel configuration modes that utilize namespaces in Linux (network namespace). A set of scripts has been published for experiments on conducting attacks.

Play video

It is worth noting that the idea of locally modifying routing is not new and has previously been used in attacks aimed at DNS server substitution. In a similar attack, TunnelCrack, where traffic redirection was achieved by replacing the default gateway, the issue affected all tested VPN clients for iOS, 87.5% of VPN clients for macOS, 66.7% for Windows, 35.7% for Linux, and 21.4% for Android. In the context of VPN and DHCP, the method has also been mentioned before; for instance, it was covered in a presentation at last year's USENIX 2023 conference (the study showed that 64.6% of the 195 tested VPN clients were vulnerable to the attack).

For route substitution, a specially designed USB drive simulating a network adapter was previously suggested, which announces itself as a gateway when connected to a computer via DHCP. Moreover, with control over the gateway (for example, when connecting the victim to a wireless network controlled by the attacker), a technique for packet substitution in the tunnel was developed, perceived in the context of the VPN network interface.

Data streams when using VPN:

The TunnelVision attack allows for redirection of VPN traffic through DHCP manipulation.

Data streams after the attack:

The TunnelVision attack allows for redirection of VPN traffic through DHCP manipulation.


Source: opennet.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster