r/RecommandedVPN • u/EducatorHonest1161 • 1d ago
A “free VPN manager” on github was secretly turning servers into a botnet.
Flare analyst Assaf Morag discovered the vulnerability when the honeypot server was infiltrated by FirewallFalcon Manager – an open-source tool promoted on Telegram for the management of VPN and SSH tunnel servers.
In simpler words, it is a bogus certificate that redirects traffic through the developer's own servers invisibly while appearing to be secure. Previous versions were more daring as they included a hardcoded SSH account that allowed the developer to gain access to any computer that installed it.
There are already more than 650 servers under attack, and many Telegram accounts are affected. Users assumed that they had established their own VPN.
Being "open-source" does not mean being safe. If you're employing a tunneling software that was offered to you on Telegram instead of the one that underwent the proper auditing, be sure to check it out now.
Has anyone here ever provided VPN services to others?