Skip to content
May 23, 2025
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Primary Menu
  • Home
  • Cyber Security
  • Cybercriminals
  • Data Leak
  • Linux
  • Malware Attack
  • Open Source Tool
  • Technology
  • Vulnerability
  • Home
  • News
  • Vulnerability
  • HotSpot Shield, PureVPN, and Zenmate flaw leaks your IP address
  • Vulnerability

HotSpot Shield, PureVPN, and Zenmate flaw leaks your IP address

Ddos March 17, 2018 2 min read
Pen Test VPNs

Recently, researchers have discovered that HotSpot Shield, PureVPN, and Zenmate, three popular VPNs, have security problems that leak private information such as real ip of users and affect millions of users. After the user’s real ip is revealed, information such as real identity and physical address will be found.

It is understood that there are three serious vulnerabilities in the free HotSpot Shield Chrome plugin: Hijack all traffic (CVE-2018-7879), DNS leak (CVE-2018-7878), and real ip address leak (CVE-2018-7880). Currently, these three vulnerabilities have been fixed, and the desktop and mobile-side HotSpot Shields are not affected by the vulnerabilities.

The flaw detail is below

  • Hijack all traffic (CVE-2018-7879) — This vulnerability resided in Hotspot Shield’s Chrome extension and could have allowed remote hackers to hijack and redirect victim’s web traffic to a malicious site.
  • DNS leak (CVE-2018-7878) — DNS leak flaw in Hotspot Shield exposed users’ original IP address to the DNS server, allowing ISPs to monitor and record their online activities.
  • Real IP Address leak (CVE-2018-7880) — This flaw poses a privacy threat to users since hackers can track user’s real location and the ISP. the issue occurred because the extension had a loose whitelist for “direct connection.” Researchers found that any domain with localhost, e.g., localhost.foo.bar.com, and ‘type=a1fproxyspeedtest’ in the URL bypass the proxy and leaks real IP address.

However, the vulnerabilities in PureVPN and Zenmate have not yet been fixed, and the problem in Zenmate is the most serious.

Source: thehackernews

Rate this post

Found this helpful?

If this article helped you, please share it with others who might benefit.

Tags: ip address

Continue Reading

Previous: RottenSys malware infects nearly 5 million Android devices
Next: The first Vatican hackathon event were held successfully

Search

💙 Support Us!
We need 50 contributors this month to keep this site running.
19 of 50 supporters this month
☕ Buy Me a Coffee PayPalDonate
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    Copyright © All rights reserved.
    x