Potential leak of server side software at repogohi.nordvpn.com
Medium
N
Nord Security
Submitted None
Actions:
Reported by
zerody
Vulnerability Details
Technical details and impact analysis
## Summary:
I found a public Git Repository at https://repogohi.nordvpn.com/. It looks like the software components in this repository are part of the VPN Servers. So I'm afraid there's a certain risk.
The following packages are among others publicly available:
```
openvpn-xor_2.4.5-stretch1nord_amd64.deb
openvpn_2.4.5-stretch1nord_amd64.deb
squid-langpack-nord_20180226-1_all.deb
```
Furthermore I found the Origin-IP (behind Cloudflare): https://95.216.8.4/
This allows an attacker to bypass all security features of Cloudflare.
Feel free to correct my assumption and Severity of this report :)
## Impact
- Leak of server side software components (VPN Infrastructure)
- Simplifies the reengineering of the used software
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Access Control - Generic