Skip to main content

Update: Actually, Hola’s security issues aren’t even worse than feared

further research reveals holas security issues are even worse than feared vpnheader
Vallepu
Update 6/3/2015 1:23 PM: Hola has informed us that Vectra’s claims have been partially retracted by the security firm. Vectra has clarified that Hola is not a botnet, but rather can be used to enable a botnet. Further, it appears that attack samples cited earlier only indicate attempted attacks against Hola users, not attacks proven to be successful.

As a result of these changes, Vectra has rescinded its broad recommendation that users uninstall Hola. Instead, the firm says “we highly encourage organizations to determine if Hola is active in their network and decide whether the risks highlighted in this blog are acceptable.” You can read the full post detailing those risks here.

Recommended Videos

Original text: Last week the free VPN service Hola Unblocker was revealed by security researchers to be acting as a botnet and selling its free users’ bandwidth through a premium service called Luminati. The security concerns meant someone could possibly gain control of your computer or carry out man-in-the-middle attacks.

A second team of researchers at cybersecurity firm Vectra has now published its own findings into the unblocking service, which it calls “both intriguing and troubling.”

According to Vectra, Hola not only acts like a botnet but has allegedly been designed to be able to carry out a “targeted, human-driven cyber attack on the network in which an [sic] Hola user’s machine resides.”

The researchers found that the VPN features a built-in console, or zconsole, that remains active even when the user is not currently browsing via Hola, allowing a malicious actor to list and kill any running process or open a socket to any “IP address, device, guid, alias or Windows name.” They could also install more software on the user’s computer without her knowing, says the report, and potentially bypass antivirus checks.

“These capabilities enable a competent attacker to accomplish almost anything,” says Vectra. “This shifts the discussion away from a leaky and unscrupulous anonymity network, and instead forces us to acknowledge the possibility that an attacker could easily use Hola as a platform to launch a targeted attack within any network containing the Hola software.”

Furthermore, Vectra analyzed the protocol used by Hola with the VirusTotal tool, which scans for malware. The researchers found five different malware samples that had existed on Hola before the recent news broke. “Unsurprisingly, this means that bad guys had realized the potential of Hola before the recent flurry of public reports by the good guys,” they wrote.

In response to the initial report from Adios, Hola!, who made the botnet claims against the VPN, Hola’s CEO Ofer Vilenski said on Monday that the company had patched two vulnerabilities identified in the report and that a vulnerability “has happened to everyone.”

Adios, Hola in its own reply said that it had in fact identified six vulnerabilities, not two, and rejected the claim that mistakes can happen. “As we have pointed out from the start, the security issues with Hola are of such a magnitude that it cannot be attributed to ‘oversight’; rather, it’s straight-out negligence,” they said. “They are not comparable to the others mentioned – they are much worse.”

The researchers have called for greater transparency from the Israeli company on its security issues. Vilenski added that Hola will launch a bug bounty program soon to identify any more vulnerabilities in the software.

Both Adios, Hola and Vectra are urging users to uninstall the program immediately. The plug-in or add-on has roughly 46 million users globally. Users of the service can route their traffic through other Hola users’ computers. The service is popular with people looking to access streaming sites like Netflix from countries where it has yet to launch.

Jonathan Keane
Former Digital Trends Contributor
Jonathan is a freelance technology journalist living in Dublin, Ireland. He's previously written for publications and sites…
I tried the RayNeo Air 2s glasses and they’re on sale for Black Friday
RayNeo Air 2s on custom Steam Deck - Briley Kenney Digital Trends_edited

With the holidays coming, I've been trying a spat of unique VR and AR devices. One pair I got my hands on, called the RayNeo Air 2s, basically gives you a portable 201-inch display that you can put on and use anytime, anywhere. They work with Android, Mac, Nintendo Switch, PS5, and -- my favorite -- Steam Deck. Our team has used the RayNeo Air 2 previously and also gave them high marks. Fun Fact I learned from reading that, RayNeo is actually a TCL brand. As for what I think of them, we'll get to that. For now, I want to talk about the crazy RayNeo Black Friday deals that have just dropped.

 
RayNeo Air 2 -- $184, was $380 51% off

Read more
At basically $105, the Ryzen 5 7600X is the best gaming CPU to buy right now
The Ryzen 5 7600X sitting among thermal paste and RAM.

I don't usually get my hopes up for Black Friday CPU deals, but I found one that's just too good to pass up. Right now, you can get the Ryzen 5 7600X -- still one of the best processors for value-focused gaming -- for basically $105. No, that's not the actual price listed on Newegg where you'll find the deal, but there's a lot going on with this sale.

For starters, the CPU itself is marked down by 24%, bringing the $299 list price down to $225. Not a great deal for a last-gen chip. However, you can save an additional $30 by using the promo code BFEDY2A33, and more importantly, you'll get a free Kingston NV3 1TB hard drive with the order. That's a PCIe 4.0 SSD that normally costs $90.

Read more
This Asus laptop with Copilot+ is $350 off at Best Buy
Asus Vivobook S 15 CoPilot+ front view showing display and keyboard.

You can do quite a bit of gaming on the go these days, thanks to all the handheld consoles and gaming laptops that are on the market. Regarding the latter, we’re always on the lookout for top discounts on the gaming gear we all want to own, which leads us to this wonderful discovery:

For a limited time, when you purchase the Asus Vivobook S 15 with Copilot+ at Best Buy, you’ll pay $550. At full price, this model sells for $900. We tested this PC earlier this year, and our reviewer said the following: “The Asus Vivobook S15 is the best large-display Copilot+ laptop so far in an old-school form factor.”

Read more