Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

WARNING: this tool is not safe to use #17

Open
hyperreality opened this issue Jan 12, 2021 · 0 comments
Open

WARNING: this tool is not safe to use #17

hyperreality opened this issue Jan 12, 2021 · 0 comments

Comments

@hyperreality
Copy link

hyperreality commented Jan 12, 2021

There probably aren't many people using to encrypt their traffic any more, but in case anyone was thinking about it, please don't.

Breaking the encryption of this tool was a challenge for Real World CTF 2020.

By defaul the tunnel uses AES-CFB with a static Initialisation Vector, so multiple connections are encrypted using the same keystream. Furthermore, the streams are malleable, so an adversary can capture your traffic and decrypt it by replaying it through your own proxy server.

Here is a full writeup

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant