Shall we disable scripts (run by openvpn.exe) by default ?
Nobody has claimed this yet.
- Dominant language
- C
- Stars
- 1.8k
- Forks
- 465
- PR merge metrics
- No merged PRs in 30d
Description
Considering the recent report on newer ways to exploit scripts in the ovpn file, I propose to disable all such scripts when a connection is started using the GUI (easy to do). We can still allow scripts that are executed by the GUI itself as those require explicitly named batch files to exist in the config folder.
Note that, in 2.4.x releases, we use the interactive service to start openvpn.exe, so privilege escalation though scripts is not a concern[*]. But exploits through commands embedded in the config (.ovpn) files is a valid threat as we currently do not have a way of signing config files.
[*] Some other GUI implementations disable scripts because of the possibility of privilege escalation as they run openvpn.exe with high privileges even if the user does not have those rights.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by tracing how the GUI starts openvpn.exe and how scripts from .ovpn files are handled. Confirm the intended boundary between disabled configuration-embedded scripts and explicitly named GUI batch files; done means the GUI enforces that distinction when a connection starts.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- c
- Domain
- desktop, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100