Share this article

Latest news

With KB5043178 to Release Preview Channel, Microsoft advises Windows 11 users to plug in when the battery is low

Copilot in Outlook will generate personalized themes for you to customize the app

Microsoft will raise the price of its 365 Suite to include AI capabilities

Death Stranding Director’s Cut is now Xbox X|S at a huge discount

Outlook will let users create custom account icons so they can tell their accounts apart easier

Some OpenVPN configuration files may sneak malware to your PC

2 min. read

Updated onFebruary 21, 2020

updated onFebruary 21, 2020

Share this article

Read our disclosure page to find out how can you help Windows Report sustain the editorial teamRead more

If you installedOpenVPNon your computer, then you should really read this piece of news. Recent reports confirmed that certainOpenVPNconfig files may be dangerous, opening the gate for malware to enter your Windows computer.

As a quick reminder,OpenVPNconfiguration files are used to run a series ofVPNconnection instructions, such as: what crypto solution to use, which remote servers to connect to, what protocols to use, and so on. There is an important command in theOpenVPNconfig file that allows users to any binary script. This could lead to hackers generating reverse shells that are very hard to spot.

In other words, attackers can directOpenVPNtraffic to one particular IP address and then use it to run commands on the remote computer using the specially craftedOpenVPNconfiguration file.

In ablog post on Medium, Jacob Baines offers further details about this issue:

Using untrusted ovpn files is dangerous. You are allowing a stranger to execute arbitrary commands on your computer. SomeOpenVPNcompatible clients like Viscosity and Ubuntu’s Network Manager GUI disable this behavior. However, after a long discussion with[email protected], it does not seem like this behavior will ever be removed fromOpenVPNproper. As such, unless you know how to read ovpn files, I suggest you be very wary about the configuration files you are using.

So, if you’re usingOpenVPN, the best solution is to simply avoid downloading config files. You can also switch to analternative VPN solution. We recommend installingCyberghost, one of the bestVPNsoftware in the world. Follow the link available below to get at a discounted price.Smart choice!Strong features:256-bit AES encryptionOver 5600 servers worldwideGreat price plansExcellent supportGet now CyberGhost VPN

More about the topics:Cybersecurity

Madalina Dinita

Networking & Security Specialist

Madalina has been a Windows fan ever since she got her hands on her first Windows XP computer.

She is interested in all things technology, especially emerging technologies – AI and DNA computing in particular.

Prior to joining the WindowsReport team, she worked in the corporate world for a number of years.

User forum

0 messages

Sort by:LatestOldestMost Votes

Comment*

Name*

Email*

Commenting as.Not you?

Save information for future comments

Comment

Δ

Madalina Dinita

Networking & Security Specialist

Madalina is a Windows fan since forever, especially interested in AI, emerging technologies, privacy, and security.