TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Hola VPN Already Exploited by “Bad Guys”, Security Firm Says

129 pointsby fraqedalmost 10 years ago

16 comments

BoppreHalmost 10 years ago
Selling user&#x27;s bandwidth is shady, but consistent with VPN usage (i.e. traffic routing). You can present it as &quot;hey, that&#x27;s our actual business model, we just forgot to tell you guys&quot; and <i>maybe</i> get away with it.<p>But this:<p><pre><code> Hola [...] installs its own code-signing certificate on the user’s system. Hola contains a built-in console (“zconsole”) that is not only constantly active but also has powerful functions including the ability to kill running processes, download a file and run it whilst bypassing anti-virus software plus read and write content to any IP address or device. </code></pre> This is going so far into shady territory it becomes indistinguishable from actual malware. This is Lenovo&#x2F;Superfish all over again.
评论 #9645896 未加载
评论 #9647388 未加载
评论 #9645849 未加载
joshstrangealmost 10 years ago
I have zero connection to this company but if you are looking for a reliable, fast, unlimited VPN I would check out Private Internet Access (<a href="https:&#x2F;&#x2F;www.privateinternetaccess.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.privateinternetaccess.com&#x2F;</a>) I&#x27;ve got a number of friends who use this and I&#x27;ve been using it for a little over a month and have nothing but good things to say. At $40&#x2F;yr it&#x27;s well worth it IMHO and provides a native VPN client, PPTP, and Socks5 (They have mobile apps as well to make it easier but you can use PPTP directly as well).<p>I use it 100% of the time on my phone and on my laptop unless I&#x27;m at work (internal resources that I haven&#x27;t figured out how to play nice with yet).
评论 #9645741 未加载
评论 #9646384 未加载
lognalmost 10 years ago
Hola extension has been removed from Firefox and Chrome download sites. I read the source of the Firefox extension at one point and don&#x27;t remember seeing any binaries or the so-called &quot;zconsole&quot;. But <i>CSO Online</i> [1] is reporting the extensions were vulnerable (despite <i>Vectra</i> [2] not mentioning this).<p>It was also unclear to me how the browser extension could be used to share user&#x27;s traffic; it didn&#x27;t seem like the extension did that, but I didn&#x27;t read the source code too carefully.<p>Does anyone has a copy of these extensions?<p>I am disappointed the Windows and Android apps were vulnerable and that Hola didn&#x27;t market their software better. It&#x27;s probably the coolest app since Napster. Yes, it&#x27;s a botnet of sorts, but the Internet needs a way to let users disassociate themselves from IP addresses. And most proxy services are easily identified.<p>[1] <a href="http:&#x2F;&#x2F;www.csoonline.com&#x2F;article&#x2F;2928817&#x2F;vulnerabilities&#x2F;hola-vpn-client-vulnerabilities-put-millions-of-users-at-risk.html" rel="nofollow">http:&#x2F;&#x2F;www.csoonline.com&#x2F;article&#x2F;2928817&#x2F;vulnerabilities&#x2F;hol...</a><p>[2] <a href="http:&#x2F;&#x2F;blog.vectranetworks.com&#x2F;blog&#x2F;technical-analysis-of-hola" rel="nofollow">http:&#x2F;&#x2F;blog.vectranetworks.com&#x2F;blog&#x2F;technical-analysis-of-ho...</a>
评论 #9645871 未加载
评论 #9646772 未加载
Labyrinthalmost 10 years ago
Coming from the receiving end of this. As a user of a anonymous image board this happen recently. It seems that hola is selling botnet access. Of course users are &quot;vetted&quot; that they are not going to use the access for nefarious purposes before they gain access. In this case one of the &quot;vetted&quot; users decided to DDOS said anonymous image board. (Note:Could be some other actors involved, but have confirmation from other board users).<p>Update(Confirmation from TorrentFreak): <a href="http:&#x2F;&#x2F;torrentfreak.com&#x2F;hola-vpn-sells-users-bandwidth-150528&#x2F;" rel="nofollow">http:&#x2F;&#x2F;torrentfreak.com&#x2F;hola-vpn-sells-users-bandwidth-15052...</a>
评论 #9648022 未加载
ThePhysicistalmost 10 years ago
Hola is going down a dangerous route here by turning all of their users into exit nodes, but if they actually make this work it would give them a unique position among all VPN providers.<p>Legally this is a very risky endeavor though. In Germany for example (where I&#x27;m based), people are even scared of sharing their Internet contract with their neighbors since the account owner can be held responsible for any illegal activities (e.g. downloading copyrighted content) that are carried out through his&#x2F;her connection. Allowing other people to &quot;freeload&quot; on my connection would therefore be a big no-no here. The only way around this risk would be to record and attribute the connection information to each user of the service, but this would of course eliminate many of the advantages of using a VPN again (e.g. privacy).
评论 #9645541 未加载
评论 #9645544 未加载
barglalmost 10 years ago
So this is interesting to me because lately, I&#x27;ve been looking for a VPN that would work for my little brother who is trying to make it to the point that he can stream full time on Twitch. The problem is that he has been targeted by script kiddies, who found his IP address through Skype. Shame on you skype.<p>That said, I&#x27;ve been looking for a good VPN for him. It seems that ProXpn isn&#x27;t as solid as I thought it was because they found his IP there and were able to (D)DOS not sure how exactly they are doing it at this point, him. They have also been able to get him banned from Twitch via his IP. He needs a VPN with enough bandwith that he can do Twitch and Skype (under a different name), all while playing games. I figured ProXpn would be sufficient, but I&#x27;ve never loaded it like that.<p>Also, there is no guide out there for streamers, or people who are in the public eye on the internet, on how to avoid getting attacked by script kiddies. Or at least no guide that I&#x27;ve found sufficiently useful, and yes I have googled this. Does anyone here have any references they can point me to that give the &quot;what not to do&quot; for streamers, youtubers, big twitter people, etc? So far I&#x27;ve told him.<p>-Use strong passwords: LastPass and yes I know this is a point of contention but it&#x27;s better then what he is using and it&#x27;s accessible enough for him that he&#x27;ll actually use it.<p>-Don&#x27;t click links in chat: Because duh (Is there a way to verify the safety of said links first)? I know of none. -Obfuscate your Skype id: This seems to be a major tool in finding IPs.<p>-Keep a personal and a public email: Personal goes to banks and stuff, public goes to everyone else.<p>-Don&#x27;t friend people on Steam you don&#x27;t know.<p>Am I missing any major advice points that seem easy to follow?<p>Edit: formatting and added steam bullet point.
评论 #9645947 未加载
评论 #9646414 未加载
评论 #9649100 未加载
评论 #9645918 未加载
expertentippalmost 10 years ago
I wish to just use OpenVPN but it&#x27;s not so easy. Certificates - no problem. Forward DNS requests - there is an option for it in the config file. Routing entire traffic through OpenVPN - quite tricky unless you&#x27;re fluent in command line network management tools and computer networks in general.
评论 #9645620 未加载
评论 #9645675 未加载
评论 #9645786 未加载
评论 #9645748 未加载
jmknialmost 10 years ago
Hola really don&#x27;t make it clear what you are installing when you download it.<p>All you think is, &quot;I&#x27;m installing a browser add-on to watch Netflix in another country&quot;. You sort of assume it&#x27;s only actually running when you are actively using it for Netflix, but it&#x27;s running all of the time.<p>I first noticed something was up when I installed Hola (for Netflix) then all of a sudden Fiddler wouldn&#x27;t work anymore. Had me completely stumped, then somebody on StackOverflow suggested turning off Hola and that indeed sorted it. - <a href="http:&#x2F;&#x2F;stackoverflow.com&#x2F;a&#x2F;19905099&#x2F;969613" rel="nofollow">http:&#x2F;&#x2F;stackoverflow.com&#x2F;a&#x2F;19905099&#x2F;969613</a>
zimbatmalmost 10 years ago
I think that Chrome users are relatively unaffected by this if they installed the extension trough Google Play thanks to Chrome&#x27;s security model. In that case I think it&#x27;s just routing the traffic trough their proxy and not installing the shady zconsole or changing the SSL certificates.<p>Still, creating a new user profile just for watching netflix is recommended.
mediascreenalmost 10 years ago
They&#x27;ve posted some kind of explanation&#x2F;apology on their blog:<p><a href="http:&#x2F;&#x2F;hola.org&#x2F;blog&#x2F;the-recent-events-on-the-hola-network" rel="nofollow">http:&#x2F;&#x2F;hola.org&#x2F;blog&#x2F;the-recent-events-on-the-hola-network</a>
bronlundalmost 10 years ago
Israeli software with a backdoor! There&#x27;s a surprise for you %]
xaitvalmost 10 years ago
Is there a way to make sure hola uninstalling the hola extension removed everything hola related from my pc? I can imagine with the level of access this extension had(I didn&#x27;t even know Chrome extensions could have this level of access) just removing the extension isn&#x27;t enough.
jalopyalmost 10 years ago
Anyone have insights into the latest and greatest tools to search for and remove possible malware installed by Hola?
mackenzielafferalmost 10 years ago
i used Hola VPN experience . i am sorry to say used bad experience for web surfing and ip changing because show the top domain surfing our country and reconnect and reconnect the hola ip. Otherwise good system and add on but reconnect the web surfing heritage. it compare the other VPN Like Ivacy and PureVpn is Good Vpn services both experience nice, not encryption from website browsing and surfing , also secure
virmundialmost 10 years ago
This seems to be a good place to ask: can Hola do this via their plugins? I tried searching, but couldn&#x27;t find anything.
mladenkovacevicalmost 10 years ago
Anyone know of a safe VPN app to use on Android? I&#x27;ve been using Cyberghost.
评论 #9646425 未加载