A VPN authenticates remote users before granting a tunnel, and the methods, pre-shared keys, passwords, certificates, and layered MFA, are each attackable. Weak or default pre-shared keys (common in IPsec and L2TP setups) are captured and cracked offline. Passwords are brute-forced, sprayed, and credential-stuffed against the SSL-VPN portal or IKE XAUTH, and VPN portals are a prime target for stuffing because they accept corporate credentials. Certificates are stolen from clients or their validation bypassed. Because success yields a tunnel into the internal network, VPN authentication is a high-value target, and MFA, where present, is the next hurdle (sometimes itself bypassable).
ike-scan -A -M <target> # aggressive mode leaks PSK material (see IKE)
nxc <sslvpn-portal> ... # product-specific portal spraying
Subtopics#
- Weak pre-shared keys: cracking default and weak PSKs.
- Password brute force: spraying and stuffing the portal.
- Certificate abuse: stolen certificates and validation bypass.