IPsec uses IKE (on UDP 500, with NAT-traversal on 4500) to authenticate peers and establish keys, and IKE is the main attack surface. The signature weakness is aggressive mode: to complete Phase 1 in fewer messages, it sends a hash derived from the pre-shared key in the clear to whoever initiates, so an unauthenticated attacker captures that hash and cracks the PSK offline. IKE also fingerprints the gateway (vendor ID, transform sets), reveals weak crypto support, and, where XAUTH adds a username/password on top of the PSK, presents a second credential to attack. Main mode does not leak the PSK hash, so the gateway's mode support matters.
# fingerprint and detect aggressive mode
ike-scan -M <target> # main-mode transforms + vendor ID
ike-scan -A -M -P psk.hash <target> # aggressive mode; -P captures the PSK hash
# crack the captured PSK offline
psk-crack -d wordlist.txt psk.hash
# with the PSK, attack XAUTH credentials if required, then establish the tunnel
Exploitation notes#
- Aggressive mode is the key finding:
ike-scan -A -Pcaptures the PSK-derived hash from an unauthenticated handshake, andpsk-crackrecovers a weak key offline, see weak pre-shared keys. - The IKE fingerprint (vendor ID, transforms) identifies the device and its weak-crypto support, feeding key-exchange downgrade and device-specific exploits.
- XAUTH adds a username/password after PSK authentication; recover the PSK, then spray XAUTH credentials (password brute force).
- Group-ID/user enumeration is possible on some gateways via IKE responses; combine with the recovered PSK to complete the tunnel into the internal network.