VPN

A remote-access VPN gateway sits on the internet and authenticates remote users into the internal network, so compromising one is a direct route from outside to inside, which is why VPN appliances are among the most exploited initial-access targets. The surface spans authentication (pre-shared keys, passwords, certificates, and the MFA often bolted on), crypto negotiation and downgrade, enumeration of the service and its protocols, protocol-specific weaknesses (IPsec/IKE aggressive mode, OpenVPN and PPTP flaws), traffic-handling leaks (DNS, routes, split tunneling), and, most consequentially, the pre-authentication vulnerabilities in the major SSL-VPN appliances.

bash
# identify VPN services
nmap -sU -p500,4500 <target>                   # IKE/IPsec
nmap -p1723,443,1194 -sV <target>              # PPTP, SSL-VPN/portal, OpenVPN
ike-scan <target>                              # IKE handshake fingerprint

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more