VPN Provider Hacked, Exploited And Weaponized To Launch DDoS Attacks

Botnet operators have managed to infiltrate the servers of VPN provider Powerhouse Management, and were exploiting them to launch Distributed Denial of Service (DDoS) attacks.

To launch Distributed Denial of Service (DDoS) attacks, the perpetrator needs to bombard a target with huge amount of traffic originating from different sources.

When successful, the target can go offline, and/or with resources unavailable to its intended users.

Because DDoS is very difficult to stop, the method of attack is popular among hackers when they want to disrupt or put an online service down.

And this time, hackers have hacked and exploited a VPN provider Powerhouse Management, and weaponized its servers as the sources of their DDoS attacks.

In other words, the VPN provider became a victim as hackers turned its servers into botnets.

Powerhouse = VyprVPN and Outfox.
VyprVPN and Outfox are two of Powerhouse Management's products.

According to an anonymous security researcher that goes by the name 'Phenomite', who shared his findings to GitHub, hackers have managed to find and exploit a service running on UDP port 20811 on Powerhouse’s servers.

"Powerhouse Management products - either Outfox (a latency reduction VPN service) or VyprVPN (a general vpn service) are exposing an interesting port - port 20811 which provides a massive data and packet amplification factor when probed with any single byte request."

"Not only does this mean Powerhouse servers can be used as a DDoS amplification source, but reveals all servers around the world that are running such potential VPN services - which removes the privacy factor somewhat."

What this means, the hackers are using this particular port to bounce bloated packets to IP addresses of victims to launch DDoS attacks.

According to the researcher, a scan reveals that as many as 1,500 Powerhouse's servers are running on UDP port 20811. That many servers were exposed, and can potentially be used to launch DDoS attacks.

Powerhouse has servers all over the world. But according to the researcher, the most vulnerable seem to be "in the UK, Vienna, and Hong Kong.”

[block:block=87]

This issue is UDP-based.

By exploiting the weakness at Powerhouse, hackers can create UDP flood to launch their DDoS attacks. They can do this by flooding their targets' machines with amplified junk traffic, overwhelming their random ports.

When this attack is successful, targets that look for apps associated with the flooded datagrams will fail and will issue a “Destination Unreachable” packet back to the sender. The result of this, the victim will become irresponsive to legitimate traffic.

Hackers can also modify Powerhouse's compromised servers to contain an incorrect return IP address. This means that hackers can send a single-byte UDP packet to a Powerhouse VPN server, which then amplifies it and sends it to the IP address of a victim of a DDoS attack.

This attack is called a reflected/amplified DDoS attack.

The issue was solved on February 24.

A spokesperson for Powerhouse said that the company has responded to Phenomite's findings. Powerhouse said it has patched the issue at the source of this DDoS vector, which it identified as Chameleon, a proprietary protocol that runs on its VPN servers' 20811 port, designed to defeat censorship and VPN blocking measures.