Skip to main content

Update: Actually, Hola’s security issues aren’t even worse than feared

further research reveals holas security issues are even worse than feared vpnheader
Vallepu
Update 6/3/2015 1:23 PM: Hola has informed us that Vectra’s claims have been partially retracted by the security firm. Vectra has clarified that Hola is not a botnet, but rather can be used to enable a botnet. Further, it appears that attack samples cited earlier only indicate attempted attacks against Hola users, not attacks proven to be successful.

As a result of these changes, Vectra has rescinded its broad recommendation that users uninstall Hola. Instead, the firm says “we highly encourage organizations to determine if Hola is active in their network and decide whether the risks highlighted in this blog are acceptable.” You can read the full post detailing those risks here.

Original text: Last week the free VPN service Hola Unblocker was revealed by security researchers to be acting as a botnet and selling its free users’ bandwidth through a premium service called Luminati. The security concerns meant someone could possibly gain control of your computer or carry out man-in-the-middle attacks.

A second team of researchers at cybersecurity firm Vectra has now published its own findings into the unblocking service, which it calls “both intriguing and troubling.”

According to Vectra, Hola not only acts like a botnet but has allegedly been designed to be able to carry out a “targeted, human-driven cyber attack on the network in which an [sic] Hola user’s machine resides.”

The researchers found that the VPN features a built-in console, or zconsole, that remains active even when the user is not currently browsing via Hola, allowing a malicious actor to list and kill any running process or open a socket to any “IP address, device, guid, alias or Windows name.” They could also install more software on the user’s computer without her knowing, says the report, and potentially bypass antivirus checks.

“These capabilities enable a competent attacker to accomplish almost anything,” says Vectra. “This shifts the discussion away from a leaky and unscrupulous anonymity network, and instead forces us to acknowledge the possibility that an attacker could easily use Hola as a platform to launch a targeted attack within any network containing the Hola software.”

Furthermore, Vectra analyzed the protocol used by Hola with the VirusTotal tool, which scans for malware. The researchers found five different malware samples that had existed on Hola before the recent news broke. “Unsurprisingly, this means that bad guys had realized the potential of Hola before the recent flurry of public reports by the good guys,” they wrote.

In response to the initial report from Adios, Hola!, who made the botnet claims against the VPN, Hola’s CEO Ofer Vilenski said on Monday that the company had patched two vulnerabilities identified in the report and that a vulnerability “has happened to everyone.”

Adios, Hola in its own reply said that it had in fact identified six vulnerabilities, not two, and rejected the claim that mistakes can happen. “As we have pointed out from the start, the security issues with Hola are of such a magnitude that it cannot be attributed to ‘oversight’; rather, it’s straight-out negligence,” they said. “They are not comparable to the others mentioned – they are much worse.”

The researchers have called for greater transparency from the Israeli company on its security issues. Vilenski added that Hola will launch a bug bounty program soon to identify any more vulnerabilities in the software.

Both Adios, Hola and Vectra are urging users to uninstall the program immediately. The plug-in or add-on has roughly 46 million users globally. Users of the service can route their traffic through other Hola users’ computers. The service is popular with people looking to access streaming sites like Netflix from countries where it has yet to launch.

Editors' Recommendations

Jonathan Keane
Former Digital Trends Contributor
Jonathan is a freelance technology journalist living in Dublin, Ireland. He's previously written for publications and sites…
The HP Victus gaming PC with RTX 3060 has a $550 discount
The HP Victus 15L gaming PC in white.

Gamers don't need to spend more than $1,000 if they want to buy a new gaming PC because there are affordable options like the HP Victus 15L gaming desktop. From its original price of $1,400, you can get it for just $850 as HP has applied a $550 discount on this machine. However, you shouldn't delay your purchase because there's no assurance that the gaming PC will still be 39% off tomorrow. If you want to make sure that you get it for less than $1,000, you're going to have to complete the transaction for it within the day.

Why you should buy the HP Victus 15L gaming desktop
You shouldn't expect the HP Victus 15L gaming desktop to match the performance of the top-of-the-line models of the best gaming PCs, but it's surprisingly powerful for its cost. Inside it are the 13th-generation Intel Core i7 processor and the Nvidia GeForce RTX 3060 graphics card, with 16GB of RAM that our guide on how much RAM do you need says is the best place to start for gaming. It's enough to play today's best PC games without any issues, and it may even be capable of running the upcoming PC games of the next few years if you're willing to dial down the settings for the more demanding titles.

Read more
This 17-inch HP laptop is on sale for just $300 — but hurry!
The HP 17t-cn300 17.3-inch laptop against a white background.

If you want to buy a laptop with a relatively large screen, the good news is that you don't have to break the bank with your purchase because you can get the HP Laptop 17t for a very affordable $300. It's on sale from HP with a $200 discount on its original price of $500, but there's no telling how much time is remaining before this offer expires. We don't think it will stay available for long because laptop deals like this almost always get sold out quickly, so complete the transaction as soon as possible to make sure that you don't miss out on the savings.

Why you should buy the HP Laptop 17t
With the 17.3-inch display of the HP Laptop 17t, you'll have a lot of screen real estate to work on your projects and watch streaming shows. It's pretty affordable for a laptop with this large screen, which offers HD+ resolution for sharp details and vibrant colors. However, despite its big display, the HP Laptop 17t maintains portability because it's only 0.78 of an inch thick, which makes it easy to slide into your bag when you're on the go, and it won't be too heavy to carry around because it only weighs about 4.6 pounds.

Read more
What to do if your Intel CPU keeps crashing
Pins on Core i9-12900K.

Despite being among the best processors you can buy, some high-end Intel CPUs have faced a wave of instability over the past few months. Intel is investigating the problem, but the company and its motherboard partners have already worked toward some temporary fixes to improve stability on high-end Intel CPUs -- even if it comes at a performance cost.

Before getting into the fixes, keep in mind that they are temporary. Intel will release a statement on the instability soon, likely with more direct guidance on what affected users should do. In addition, the scope of the problem isn't clear -- if you're not experiencing issues, you shouldn't have anything to worry about.
Who's affected

Read more