FINDING · DETECTION

34 of 41 obfuscated OpenVPN configurations and 18 of 20 UDP configurations were co-located with vanilla TCP OpenVPN servers within the same /29 subnet; probing the /29 subnet of a suspected obfuscated or UDP endpoint revealed nearby vanilla TCP servers, enabling confirmation by 'guilt by association' even when the obfuscated endpoint itself resisted direct fingerprinting. Some providers additionally share infrastructure across different VPN brands, further compounding exposure.

From 2022-xue-openvpnOpenVPN is Open to VPN Fingerprinting · §7.5, §9.1 · 2022 · USENIX Security Symposium

Implications

Tags

censors
generic
techniques
active-probingip-blocking
defenses
bridgesrandomization

Extracted by claude-sonnet-4-6 — review before relying.