Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Please solve TunnelVision attacks 1 #860

Open
1 of 2 tasks
ghost opened this issue May 8, 2024 · 1 comment
Open
1 of 2 tasks

Please solve TunnelVision attacks 1 #860

ghost opened this issue May 8, 2024 · 1 comment
Labels
bug Something isn't working reviewed

Comments

@ghost
Copy link

ghost commented May 8, 2024

Search first

  • I searched and no similar issues were found

What Happened?

https://github.com/SagerNet/sing-box/releases/tag/v1.9.0-rc.16
https://sing-box.sagernet.org/manual/misc/tunnelvision/
https://www.cve.org/CVERecord?id=CVE-2024-3661
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3661

By design, the DHCP protocol does not authenticate messages, including for example the classless static route option (121). An attacker with the ability to send DHCP messages can manipulate routes to redirect VPN traffic, allowing the attacker to read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN. Many, if not most VPN systems based on IP routing are susceptible to such attacks.

Minimal Reproducible Example (MRE)

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3661

Expected Behavior

just fix it, like singbox 1.9.0-rc16 that

Version

all version currently

Platform/OS

Android, Windows, macOS, Linux, iOS

Additional Context

No response

Application Config Options

No response

Relevant log output

No response

Are you willing to submit a PR? If you know how to fix the bug.

  • I'm willing to submit a PR (Thank you!)
@ghost ghost added the bug Something isn't working label May 8, 2024
@lymanjre
Copy link
Contributor

lymanjre commented May 9, 2024

Hi, Thanks for informing us. We will consider checking it out.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working reviewed
Projects
Status: Todo
Development

No branches or pull requests

1 participant