Android Private Internet Access Denial Of Service

Discussion in 'News Aggregator' started by Packet Storm, 28 Oct 2017.

  1. Packet Storm

    Packet Storm Guest

    The Android application provided by Private Internet Access (PIA) VPN service can be crashed by downloading a large file containing a list of current VPN servers. This can be exploited by an MITM attacker via intercepting and replacing this file. While the file is digitally signed, it is not served over SSL and the application did not contain logic for checking if the provided file is very large. The vendor has fixed this issue in version 1.3.3.1 and users should install the latest version.

    Continue reading...
     

Share This Page

Loading...