A remote-access VPN gateway sits on the internet and authenticates remote users into the internal network, so compromising one is a direct route from outside to inside, which is why VPN appliances are among the most exploited initial-access targets. The surface spans authentication (pre-shared keys, passwords, certificates, and the MFA often bolted on), crypto negotiation and downgrade, enumeration of the service and its protocols, protocol-specific weaknesses (IPsec/IKE aggressive mode, OpenVPN and PPTP flaws), traffic-handling leaks (DNS, routes, split tunneling), and, most consequentially, the pre-authentication vulnerabilities in the major SSL-VPN appliances.
# identify VPN services
nmap -sU -p500,4500 <target> # IKE/IPsec
nmap -p1723,443,1194 -sV <target> # PPTP, SSL-VPN/portal, OpenVPN
ike-scan <target> # IKE handshake fingerprint
Subtopics#
- Enumeration: protocol and version detection.
- Authentication: PSKs, passwords, and certificates.
- Weak cryptography: cipher and key-exchange weaknesses.
- Protocols: IPsec/IKE, OpenVPN, PPTP, WireGuard, L2TP/SSTP.
- Traffic handling: DNS, route, and split-tunnel leaks.
- SSL-VPN appliances: the pre-auth appliance exploits.