Loading HuntDB...

Potential leak of server side software at repogohi.nordvpn.com

Medium
N
Nord Security
Submitted None
Reported by zerody

Vulnerability Details

Technical details and impact analysis

Improper Access Control - Generic
## Summary: I found a public Git Repository at https://repogohi.nordvpn.com/. It looks like the software components in this repository are part of the VPN Servers. So I'm afraid there's a certain risk. The following packages are among others publicly available: ``` openvpn-xor_2.4.5-stretch1nord_amd64.deb openvpn_2.4.5-stretch1nord_amd64.deb squid-langpack-nord_20180226-1_all.deb ``` Furthermore I found the Origin-IP (behind Cloudflare): https://95.216.8.4/ This allows an attacker to bypass all security features of Cloudflare. Feel free to correct my assumption and Severity of this report :) ## Impact - Leak of server side software components (VPN Infrastructure) - Simplifies the reengineering of the used software

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Access Control - Generic