HomeSecurityAtlas VPN zero-day: Leaks users' IP addresses

Atlas VPN zero-day: Leaks users' IP addresses

A zero-day vulnerability in Atlas VPN affects the Linux , causing a user's real IP address to be leaked simply by visiting a website.

See also: Akira ransomware targets Cisco VPNs to compromise organizations

Atlas VPN

Atlas VPN is a VPN software that provides a cost-effective solution, based on WireGuard and supporting all major operating systems.

In a post , a researcher reports an example of an exploit for the Atlas VPN Linux client. Specifically, he reports that the latest version 1.0.3 has an API endpoint on localhost (127.0.0.1) via port 8076.

This API provides a command-line interface (CLI) for performing various actions. With this interface, you can disconnect a session VPN connection using the URL https://127.0.0.1:8076/connection/stop.

However, this API does not perform any authentication, allowing anyone to issue commands to the CLI, even on a website you are visiting. A user named 'Educational-Map-8145' has uploaded a PoC exploit to Reddit that exploits the Atlas VPN Linux API to reveal a user's real IP addresses.

This copy is intended to create an invisible form that will be automatically submitted via JavaScript, in order to connect to the final API URL at https://127.0.0.1:8076/connection/stop.

When you access this API endpoint, it automatically terminates any active Atlas VPN connections that are hiding a user's IP address.

See also: Meta blocks EU-based users from accessing Threads via VPN

IP address

After the VPN connection is disconnected, the PoC will connect to the URL api.ipify.org to record the visitor's real IP address.

This is a serious privacy violation for any VPN user, as it reveals their true physical location and real IP address, allowing others to track them and nullifying one of the main reasons for using a VPN provider

Chris Partridge, a cybersecurity engineer at Amazon, tested and confirmed the exploit, creating a video to demonstrate the ability to reveal an IP address. Partridge explained that the PoC bypasses existing CORS (Cross-Origin Resource Sharing) protections in web browsers. This happens because requests are sent to the Atlas VPN API as form submissions.

Normally, CORS blocks requests originating from scripts on web pages in domains other than the origin domain. In this case, we are referring to requests made from any website to the visitor's local server via the address “https://127.0.0.1:8076/connection/stop“.

However, Partridge mentioned that using a form submission to “bypass” CORS does not allow the website to receive a response from the form submission. In this case, the response is not necessary. The form submission is simply used to get the URL that will be needed to disconnect from the Atlas VPN connection on Linux.

Given the critical nature of this zero-day vulnerability, which remains exploitable until a patch is released, Linux client users are advised to take immediate preventative measures, including considering an alternative VPN solution.

See also: Microsoft Edge upgrades built-in Cloudflare VPN with 5 GB of data

Atlas VPN is a new player in the VPN world, dedicated to providing reliable, fast, and secure internet. While it offers many features, such as hiding the user’s real IP address and protecting against DNS leaks, the recent discovery of a zero-day vulnerability shows that the software is not invulnerable. It is crucial for VPN providers to patch any vulnerabilities quickly to protect data and maintain their trust.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS