IPsec (and L2TP/IPsec) VPNs often authenticate the tunnel with a pre-shared key, and a weak or default PSK is recoverable. The sharpest case is IKE aggressive mode: to save a round trip, aggressive mode sends a hash computed from the PSK in the first exchange, before the key is confirmed, so an attacker who initiates an aggressive-mode handshake captures that hash and cracks the PSK offline with a wordlist or brute force. Once the PSK is recovered, the attacker completes the Phase 1 authentication (and then any XAUTH username/password, itself often weak), establishing the tunnel.
# detect and capture an aggressive-mode PSK hash
ike-scan -A -M -P psk.hash <target> # -A aggressive, -P saves the hash
# crack the captured PSK offline
psk-crack -d wordlist.txt psk.hash
psk-crack -b 8 psk.hash # brute force up to length 8
# with the PSK (and XAUTH creds if required), connect
Exploitation notes#
- Aggressive mode is the enabler: it emits the PSK-derived hash to an unauthenticated initiator, so
ike-scan -A -Pcaptures it andpsk-crackrecovers a weak key offline; main mode does not leak this, so check which modes the gateway offers. - Default PSKs (vendor defaults, documentation examples, obvious strings) and short keys fall quickly; seed the wordlist with organisation-specific terms.
- The PSK authenticates the tunnel but many deployments add XAUTH (a username/password) as a second factor; recover the PSK first, then attack XAUTH (password brute force).
- A recovered PSK plus XAUTH yields a full tunnel into the internal network; see IPsec IKE for the aggressive-mode mechanics.