USENIX Security2023Top-tier venue
Bypassing Tunnels: Leaking VPN Client Traffic by Abusing Routing Tables
Nian Xue, Yashaswi Malla, Zihang Xia, Christina Pöpper, Mathy Vanhoef
Abstract
Virtual Private Networks (VPNs) authenticate and encrypt network traffic to protect users' security and privacy, and are used in professional and personal settings to defend against malicious actors, circumvent censorship, remotely work from home, etc. It is therefore essential that VPNs are secure. In this paper, we present two novel attacks that cause VPN clients to leak traffic outside the protected VPN tunnel. The root cause of both attacks is a widespread design flaw in how clients configure the Operating System (OS) to route all traffic through the VPN tunnel. This is typically done by updating the system's IP routing tables such that all traffic will first pass through the VPN client. However, some routing exceptions are added to ensure the system keeps functioning properly, namely that traffic to the local network, and to the VPN server itself, is sent outside the VPN tunnel. We show that by setting up a Wi-Fi access point or by spoofing DNS responses, an adversary can manipulate these exceptions to make the victim send arbitrary traffic in plaintext outside the VPN tunnel. We confirm our findings in practice by conducting 248 experiments against 67 of the most representative VPN providers on Windows, macOS, iOS, Linux, and Android. Our experimental results reveal that a significant number (126 and 39) and proportion (64.6% and 73.6%) of free, paid, open-source, corporate, and built-in VPN clients are vulnerable to (variants of) our two attacks respectively, suffering from leaky traffic. We discuss countermeasures to mitigate the vulnerabilities and confirm the effectiveness of selected defenses in practice.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2222ecb9-5e99-4333-8f64-fd538930bf64Cited by top-tier papers3
- Detecting Tunneled Flooding Traffic via Deep Semantic Analysis of Packet Length PatternsChuanpu Fu, Qi Li, Meng Shen, Ke XuCCS 2024 · 13 citations
- MVPNalyzer: An Investigative Framework for Auditing the Security & Privacy of Mobile VPNsWayne Wang, Aaron Ortwein, Enrique Sobrados, Robert Stanley et al.NDSS 2026 · 2 citations
- Invisible Adversaries: A Systematic Study of Session Manipulation Attacks on VPNsYuxiang Yang, Ao Wang, Xuewei Feng, Qi Li et al.INFOCOM 2026 · 1 citation
Builds on11
- WireGuard: Next Generation Kernel Network TunnelJason A. DonenfeldNDSS 2017 · 259 citations
- On the Practical (In-)Security of 64-bit Block Ciphers: Collision Attacks on HTTP over TLS and OpenVPNKarthikeyan Bhargavan, Gaëtan LeurentCCS 2016 · 180 citations
- Transcript Collision Attacks: Breaking Authentication in TLS, IKE and SSHKarthikeyan Bhargavan, Gaëtan LeurentNDSS 2016 · 128 citations
- Attacking the Network Time ProtocolAanchal Malhotra, Isaac E. Cohen, Erik Brakke, Sharon GoldbergNDSS 2016 · 100 citations
- The Dangers of Key Reuse: Practical Attacks on IPsec IKEDennis Felsch, Martin Grothe, Jörg Schwenk, Adam Czubak et al.USENIX Security 2018 · 41 citations
Related papers
- Blind In/On-Path Attacks and Applications to VPNsWilliam J. Tolley, Beau Kujath, Mohammad Taha Khan, Narseo Vallina-Rodriguez et al.USENIX Security 2021 · 19 citations
- Back to School: On the (In)Security of Academic VPNsKa Lok Wu, Man Hong Hue, Ngai Man Poon, Kin Man Leung et al.USENIX Security 2023
- Evaluating Susceptibility of VPN Implementations to DoS Attacks Using Adversarial TestingFabio Streun, Joel Wanner, Adrian PerrigNDSS 2022
- How and Why People Use Virtual Private NetworksAgnieszka Dutkowska-Zuk, Austin Hounsel, Amy Morrill, Andre Xiong et al.USENIX Security 2022
- VPNInspector: Systematic Investigation of the VPN EcosystemReethika Ramesh, Leonid Evdokimov, Diwen Xue, Roya EnsafiNDSS 2022
