WebRTC Browser Vulnerability Fix

VPNUK Security and Privacy
About The Vunerability


A vulnerability has been discovered in WebRTC (Web Real Time Communication), an open-source standard that enables the browsers to make voice or video calls without needing any plug-ins. With a few lines of code websites can make requests to STUN servers and log users’ VPN IP address and the 'hidden' home IP address, as well as local network addresses. It a massive privacy hole in two very popular browsers that you should really plug!

Please be aware, this vulnerability only affects Firefox and Chrome browers and only appears to be limited to Windows machines.

How does the WebRTC vunerability work
WebRTC allows requests to be made to STUN (Session Traversal Utilities for NAT) servers which return the 'hidden' home IP address as well as local network addresses for the system that is being used by the user.

The results of the requests can be accessed using JavaScript, but because they are made outside the normal XML/HTTP request procedure, they are not visible in the developer console. This means that the only requirement for this to work is WebRTC support in the browser and JavaScript.

Browser check
1. Connect to VPNUK
2. Visit http://ipleak.net
3. If your browser is secure, you should see nothing more than VPNUK server information.
4. If your browser is affected by this issue, you’ll see information about your true IP address in the WebRTC section.

Protecting yourself
The vunerability is relatively easy to fix.

For Chrome users:
Google Chrome and other Chromium-based browser users can install the WebRTC extension ScriptSafe, which currently blocks the vulnerability.

https://chrome.google.com/webstore/detail/webrtc-leak-prevent/eiadekoaikejlgdbkbdfeijglgfdalml

For Firefox Users :
In case of Firefox, the only extensions that block these look ups are JavaScript blocking extensions such as NoScript. To fix, try the following steps:

Type about:config in the browser's address bar and hit enter.
Confirm you will be careful if the prompt appears.
Search for media.peerconnection.enabled.
Double-click the preference to set it to false.
This turns off WebRTC in Firefox.

Comments

No comments yet.

Add Comment

* Required information
(will not be published)
blank
Enter the fourth letter from the word vpnuk
blank
Enter answer:
blank
Freedom of Information
An account with VPNUK will help keep your online communications private and safe by creating a secure tunnel through which all of your encrypted data travels! A VPNUK account will help you bypass all types of enforced censorship and geographical restrictions giving you back your world wide web freedom and unrestricted access to the internet.
VPNUK Payment Methods
Order VPN Accounts
Which type of account would you like to create?
Shared IP account Our Most popular account offering multi user access to over 100 servers in 24 countries.
Dedicated IP account We have two types of Dedicated IP account which providers users with a totally unique, static ip address.

 

Order Shared IP VPN Accounts
Number of Users
Account Duration
Fee £
Type of Payment

 

Order Dedicated IP VPN Accounts
Server Location
Number of Users
Account Duration
Fee £
Type of Payment
VPNUK SSL
Secure Account Management
Your online security and privacy is the most important aspect of the VPNUK service, we do not cut any corners where our clients online security is concerned and we always ensure you are always in full control of your account. Should you ever need our help and assistance, or if you ever have any questions we will always be here for you, it what defines the VPNUK service and makes us so special, it's also the reason the majority of our clients entrust us with securing their online presence.

In order to offer our valued users the most secure, private and transparent service possible we always ensure you are in total control of your account. We never directly collect or store any personal information from our clients.

Every VPNUK account comes with an advanced Control Panel from where our clients are able to view information like account expiry dates and account login information, as well as other features including monthly invoicing, Partner Program status and SmartDNS service check-in. The control Panel also allows clients to renew expired accounts and change their chosen payment method along with many other useful features.

Click here to join VPNUK and improve your online security today.

Contacts & Social
Correspondence Address:
VPNUK Limited
Office B0245
265-269 Kingston Road
Wimbledon
London
SW19 3NW
United Kingdom

Telephone Contacts
INUM: +883 510 001 193 452
UK: +44 203 608 6599
USA: +1 702 9240633
Spain: +34 902 848 027

Social Media
Join the discussions with VPNUk on Twitter Follow us on Facebook Follow us on Google Plus Watch out setup tutorials on the VPNUK You Tube channel Connect with VPNUK on Linkedin Connect with VPNUK on instagram

Servers
UK - USA - Switzerland
Germany - Spain
Australia - Canada
Netherlands - France
Italy - Hong Kong
Denmark - Ireland
Sweden - Russia
Luxembourg - Poland
Singapore - Iceland
Panama - Egypt
Israel - India - Japan

Translate

Newsletter
Sign up to our newsletter and we will keep you up to date with all the latest news, reviews and service updates.


Services
Static VPN IP Accounts
Dynamic VPN IP Accounts
Online TV Film & Sport
SmartDNS Services
Live TV Service
Online Security
Geo Location
Personal Firewall

Copyright © VPNUK Limited 2017 | Registered in Belize Company No 144643