No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

AtlasVPN Linux Zero-Day Disconnects Users, Reveals IP Addresses

September 6, 2023
in Protection
0
informa



A security researcher has published exploit code for AtlasVPN for Linux, which could enable anybody to disconnect a user and reveal their IP address simply by luring them to a website.

AtlasVPN is a “freemium” virtual private network (VPN) service owned by NordVPN. Despite being just 4 years old, according to its website, it’s used by more than 6 million people worldwide.

On Sept. 1, after receiving no response from the vendor, an unidentified researcher (referred to by their Full Disclosure mailing list username, “icudar”) posted exploit code for AtlasVPN Linux to the Full Disclosure mailing list and Reddit. By simply copying and pasting this code to their own site, any odd hacker could disconnect any AtlasVPN user from their private network, and reveal their IP address in the process.

“Since the entire purpose of the VPN is to mask this information, this is a pretty significant problem for users,” says Shawn Surber, senior director of technical account management at Tanium.

How the AtlasVPN Exploit Works

The issue with AtlasVPN’s Linux client boils down to a lack of proper authentication.

“The client does not connect via a local socket or any other secure means but instead it opens an API on localhost on port 8076. It does not have ANY authentication,” icudar wrote in his online posts. “This port can be accessed by ANY program running on the computer, including the browser.”

Surber guesses that “this vulnerability appears to be caused by the assumption that Cross-Origin Resource Sharing (CORS) protection would prevent it.” CORS is a mechanism by which one domain can request resources from another.

As other researchers have pointed out, though, the exploit easily slips past CORS by sending a type of request it does not flag. “CORS is designed to prevent data theft and loading of outside resources. In this scenario, the attack uses a simple command, which slips through the CORS gauntlet and, in this case, turns off the VPN, immediately exposing the user’s IP and therefore general location,” Surber explains.

What This Means for VPN Users

To test the extent of the vulnerability, icudar wrote malicious JavaScript that would request port 8076 and successfully disconnect the VPN, then request to leak the user’s IP address.

“It shows that AtlasVPN does not take their [users’] safety serious, because their software security decisions suck so massively that [it’s] hard to believe this is a bug rather than a backdoor,” they wrote.

There is no evidence yet of AtlusVPN’s vulnerability being exploited in the wild. In a response via Reddit, the head of the IT department at AtlusVPN wrote that the company is fixing the issue, will notify all Linux client users, and release a patch “as soon as possible.”

In a written statement for Dark Reading, AtlusVPN could not provide an exact timeline for its patch but assured that “we are actively working on fixing the vulnerability as soon as possible.”

Editorial Team

Editorial Team

Related Posts

The LG UltraGear 39GX90SA-W Gaming Monitor Is $850 Off Right Now
Protection

The LG UltraGear 39GX90SA-W Gaming Monitor Is $850 Off Right Now

May 16, 2026
You Can Now Pre-Order XReal's R1 Gaming AR Glasses (With the ROG Control Deck)
Protection

You Can Now Pre-Order XReal’s R1 Gaming AR Glasses (With the ROG Control Deck)

May 15, 2026
10 Hacks Every Microsoft Teams User Should Know
Protection

10 Hacks Every Microsoft Teams User Should Know

May 15, 2026
I Tried These Four Fitness Watches to See Which Was Best for Hyrox Training
Protection

I Tried These Four Fitness Watches to See Which Was Best for Hyrox Training

May 15, 2026
Chatbots May Be Giving Out Your Phone Number
Protection

Chatbots May Be Giving Out Your Phone Number

May 15, 2026
Here Are the Best Early Memorial Day Sales so Far
Protection

Here Are the Best Early Memorial Day Sales so Far

May 15, 2026
Load More
Next Post
T-Mobile Will Start to Pay a Dividend. Why the Stock Is Dropping.

T-Mobile Will Start to Pay a Dividend. Why the Stock Is Dropping.

Popular News

  • How to Hire an Accountant

    How to Hire an Accountant

    0 shares
    Share 0 Tweet 0
  • What cybersecurity pros can learn from first responders

    0 shares
    Share 0 Tweet 0
  • Sports betting weighs on consumers’ credit health

    0 shares
    Share 0 Tweet 0
  • Analyst Report: AbbVie Inc

    0 shares
    Share 0 Tweet 0
  • Bond Markets Are on Edge. Today’s Treasury Auction Announcement Might Not Calm Nerves.

    0 shares
    Share 0 Tweet 0

Latest News

Donald J. Trump secures historic trade deals with China

Donald J. Trump secures historic trade deals with China

May 17, 2026
0

The US and China just shook hands on what the White House is calling a landmark trade agreement. The deal...

Director, Career Development - HigherEdJobs

Director, Career Development – HigherEdJobs

May 17, 2026
0

Institution: Black Hills State UniversityPosting Number: NFE03064PDepartment: BHSU - Enrollment ManagementPhysical Location of Position (City): SpearfishPosting TextBlack...

Bitcoin

Bitcoin MVRV Pattern Predicts Major Downswing Ahead – Details

May 17, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Bitcoin (BTC) is trading around $78,000, as...

Cointelegraph

Poland Approves Crypto Bill Amid Looming MiCA Deadline

May 17, 2026
0

Polish lawmakers approved a government-backed bill Friday to bring the country’s crypto market under the European Union’s Markets in Crypto-Assets...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.