
A delicious, but malicious SSL-VPN server 🌮
NachoVPN is a Proof of Concept that demonstrates exploitation of SSL-VPN clients, using a rogue VPN server.
It uses a plugin-based architecture so that support for additional SSL-VPN products can be contributed by the community. It currently supports various popular corporate VPN products, such as Cisco AnyConnect, SonicWall NetExtender, Palo Alto GlobalProtect, and Ivanti Connect Secure.
For further details, see our blog post, and HackFest Hollywood 2024 presentation [slides|video].
NachoVPN is built and tested on Ubuntu 22.04.
Install python3-nftables and nftables
Optionally use setcap to avoid sudo requirement:
sudo setcap 'cap_net_raw,cap_net_bind_service,cap_net_admin=eip' /usr/bin/python3.10
Enable IP forwarding:
sudo sysctl -w net.ipv4.ip_forward=1
NachoVPN can be installed from GitHub using pip. Note that this requires git to be installed.
First, create a virtual environment.
On Linux, ensure that the virtual env has access to the system site-packages, so that nftables works:
python3 -m venv env --system-site-packages
source env/bin/activate
On Windows, nftables (and thus packet forwarding) is disabled, so use:
python -m venv env
.\env\Scripts\activate
Then, install NachoVPN:
pip install git+https://github.com/AmberWolfCyber/NachoVPN.git
If you prefer to use Docker, then you can pull the container from the GitHub Container Registry:
docker pull ghcr.io/AmberWolfCyber/nachovpn:release
First, clone this repository, and install setuptools and wheel via pip. You can then run the setup.py script:
git clone https://github.com/AmberWolfCyber/NachoVPN
pip install -U setuptools wheel
python setup.py bdist_wheel
This will generate a wheel file in the dist directory, which can be installed with pip:
pip install dist/nachovpn-1.0.0-py3-none-any.whl
Alternatively, for local development you can install the package in editable mode using:
pip install -e .
You can build the container image with the following command:
docker build -t nachovpn:latest .
To run the server as standalone, use:
python -m nachovpn.server
Alternatively, you can run the server using Docker:
docker run -e SERVER_FQDN=connect.nachovpn.local -e EXTERNAL_IP=1.2.3.4 -v ./certs:/app/certs -p 80:80 -p 443:443 --rm -it nachovpn
This will generate a certificate for the SERVER_FQDN using certbot, and save it to the certs directory, which we've mounted into the container.
Alternatively, for testing purposes, you can skip the certificate generation by setting the SKIP_CERTBOT environment variable.
This will generate a self-signed certificate instead.
docker run -e SERVER_FQDN=connect.nachovpn.local -e SKIP_CERTBOT=1 -e EXTERNAL_IP=1.2.3.4 -p 443:443 --rm -it nachovpn
An example docker-compose file is also provided for convenience.
You can run nachovpn with the -d or --debug command line arguments in order to increase the verbosity of logging, which can aid in debugging.
Alternatively, if the logging is too noisy, you can use the q or --quiet command line argument instead.
NachoVPN supports the following plugins and capabilities:
| Plugin | Product | CVE | Windows RCE | macOS RCE | Privileged | URI Handler | Packet Capture | Demo |
|---|---|---|---|---|---|---|---|---|
| Cisco | Cisco AnyConnect | N/A | ✅ | ✅ | ❌ | ❌ | ✅ | Windows / macOS |
| SonicWall | SonicWall NetExtender | CVE-2024-29014 | ✅ | ❌ | ✅ | ✅ | ❌ | Windows |
| PaloAlto | Palo Alto GlobalProtect | CVE-2024-5921 (partial fix) | ✅ | ✅ | ✅ | ❌ | ✅ | Windows / macOS / iOS |
| PulseSecure | Ivanti Connect Secure | CVE-2020-8241 (bypassed) | ✅ | ✅ | ✅ | ✅ (Windows only - disabled by default in 22.8R1) | ✅ | Windows |
| Netskope | Netskope | CVE-2025-0309 | ✅ | ❌ | ✅ | ❌ | ❌ | Windows |
| Delinea | Protocol Handler | CVE-2026-???? | ✅ | ✅ | ❌ | ✅ | ❌ | Windows |
/pulse URL on the NachoVPN server./sonicwall URL on the NachoVPN server. This requires that the SonicWall Connect Agent is installed on the client machine./delinea URL on the NachoVPN server.