Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
NachoVPN — A delicious, but malicious SSL-VPN server 🌮 | Kitploit
Tools/GitHubGitHub/amberwolfcyber/nachovpn
Privilege EscalationVulnerability AnalysisExploitationNetwork SecurityPenetration TestingRed TeamingPayload DevelopmentAdversarial Attack
GitHubamberwolfcyber/nachovpn

NachoVPN

A delicious, but malicious SSL-VPN server 🌮

View Repository
26731117 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

NachoVPN 🌮🔒

NachoVPN is a Proof of Concept that demonstrates exploitation of SSL-VPN clients, using a rogue VPN server.

It uses a plugin-based architecture so that support for additional SSL-VPN products can be contributed by the community. It currently supports various popular corporate VPN products, such as Cisco AnyConnect, SonicWall NetExtender, Palo Alto GlobalProtect, and Ivanti Connect Secure.

For further details, see our blog post, and HackFest Hollywood 2024 presentation [slides|video].

Installation

Prerequisites

  • Python 3.9 or later
  • Docker (optional)
  • osslsigncode (Linux only)
  • msitools (Linux only)
  • python3-netfilter (Linux only)
  • git

Linux Setup

NachoVPN is built and tested on Ubuntu 22.04.

  • Install python3-nftables and nftables

  • Optionally use setcap to avoid sudo requirement:

    sudo setcap 'cap_net_raw,cap_net_bind_service,cap_net_admin=eip' /usr/bin/python3.10
    
  • Enable IP forwarding:

    sudo sysctl -w net.ipv4.ip_forward=1
    

Installing from source

NachoVPN can be installed from GitHub using pip. Note that this requires git to be installed.

First, create a virtual environment.

On Linux, ensure that the virtual env has access to the system site-packages, so that nftables works:

python3 -m venv env --system-site-packages
source env/bin/activate

On Windows, nftables (and thus packet forwarding) is disabled, so use:

python -m venv env
.\env\Scripts\activate

Then, install NachoVPN:

pip install git+https://github.com/AmberWolfCyber/NachoVPN.git

If you prefer to use Docker, then you can pull the container from the GitHub Container Registry:

docker pull ghcr.io/AmberWolfCyber/nachovpn:release

Building for distribution

Building a wheel file

First, clone this repository, and install setuptools and wheel via pip. You can then run the setup.py script:

git clone https://github.com/AmberWolfCyber/NachoVPN
pip install -U setuptools wheel
python setup.py bdist_wheel

This will generate a wheel file in the dist directory, which can be installed with pip:

pip install dist/nachovpn-1.0.0-py3-none-any.whl

Building for local development

Alternatively, for local development you can install the package in editable mode using:

pip install -e .

Building a container image

You can build the container image with the following command:

docker build -t nachovpn:latest .

Running

To run the server as standalone, use:

python -m nachovpn.server

Alternatively, you can run the server using Docker:

docker run -e SERVER_FQDN=connect.nachovpn.local -e EXTERNAL_IP=1.2.3.4 -v ./certs:/app/certs -p 80:80 -p 443:443 --rm -it nachovpn

This will generate a certificate for the SERVER_FQDN using certbot, and save it to the certs directory, which we've mounted into the container.

Alternatively, for testing purposes, you can skip the certificate generation by setting the SKIP_CERTBOT environment variable.

This will generate a self-signed certificate instead.

docker run -e SERVER_FQDN=connect.nachovpn.local -e SKIP_CERTBOT=1 -e EXTERNAL_IP=1.2.3.4 -p 443:443 --rm -it nachovpn

An example docker-compose file is also provided for convenience.

Debugging

You can run nachovpn with the -d or --debug command line arguments in order to increase the verbosity of logging, which can aid in debugging.

Alternatively, if the logging is too noisy, you can use the q or --quiet command line argument instead.

Plugins

NachoVPN supports the following plugins and capabilities:

PluginProductCVEWindows RCEmacOS RCEPrivilegedURI HandlerPacket CaptureDemo
CiscoCisco AnyConnectN/A✅✅❌❌✅Windows / macOS
SonicWallSonicWall NetExtenderCVE-2024-29014✅❌✅✅❌Windows
PaloAltoPalo Alto GlobalProtectCVE-2024-5921 (partial fix)✅✅✅❌✅Windows / macOS / iOS
PulseSecureIvanti Connect SecureCVE-2020-8241 (bypassed)✅✅✅✅ (Windows only - disabled by default in 22.8R1)✅Windows
NetskopeNetskopeCVE-2025-0309✅❌✅❌❌Windows
DelineaProtocol HandlerCVE-2026-????✅✅❌✅❌Windows

URI handlers

  • The Ivanti Connect Secure (Pulse Secure) URI handler can be triggered by visiting the /pulse URL on the NachoVPN server.
  • The SonicWall NetExtender URI handler can be triggered by visiting the /sonicwall URL on the NachoVPN server. This requires that the SonicWall Connect Agent is installed on the client machine.
  • The Delinea URI handler can be triggered by visiting the /delinea URL on the NachoVPN server.

Operating Notes

Download Tool