Author Topic: WebRTC leak in SafeZone Browser  (Read 5552 times)

0 Members and 1 Guest are viewing this topic.

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5616
  • Spartan Warrior
WebRTC leak in SafeZone Browser
« on: May 24, 2017, 04:41:29 PM »
Used ipleak.net to detect.

WebRTC is displaying internal network ip's using SafeZone Browser.  Is there a fix or add-on that can be installed?  See attached.
Windows 10 Home 64-bit 22H2 Avast Premier Security version 24.1.6099 (build 24.1.88821.762)  UI version 1.0.797
 UI version 1.0.788.  Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.2.6105 (build 24.1.8918.827) UI version 1.0.801

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89059
  • No support PMs thanks
Re: WebRTC leak in SafeZone Browser
« Reply #1 on: May 24, 2017, 05:22:51 PM »
I could well be wrong as I don't use the SafeZone Browser so I don't know if this really is an issue, I base this comment on the text in your image:

"IPv6 test not reachable"
and
"If you are now connected to a VPN and you and you see your ISP IP, then your system is leaking WebRTC requests"

I don't see an ISP IP address in your image only the local IP address, but the SafeZone Browser isn't a VPN ?
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5616
  • Spartan Warrior
Re: WebRTC leak in SafeZone Browser
« Reply #2 on: May 25, 2017, 07:48:31 PM »
Any misunderstanding is entirely my fault.

Snipped image re external ISP ip was not snipped for privacy reasons.

No, the avast SafeZone Browser is not a VPN, merely a browser using Chromium code and maintained by Avast.

IPv6 not reachable is due to router settings set to reach IPv6 addresses via tunneling alone, enabling direct IPv6 will result in avast network code alerts when network inspector is run.
  • Not running SafeZone Browser in a VPN environment in the first post.
  • Snip is the actual WebRTC leak displayed; network ip's displayed in the attachment below above are from the internal home network and are not the actual ISP ip assigned to the home router, which is set to dynamic.
  • Actual ISP ip (IPv4) is listed above the found WebRTC leak.  You will see your ISP ip when you run the ipleak.net site in your browser.
  • Since the browser used is forward-facing, the found private information can be discoverable for malicious purposes as the browser is connecting to system(s) outside the private home network.
So, the test is specifically for browsers connecting via a VPN, but also can be used for those not connecting via a VPN.  Either way, in either mode, WebRTC leak should not occur if the browser is configured properly.  WebRTC leak shows independently of VPN or non-VPN environment.

Running avast SafeZone Browser version 3.55.2393.596.

Additional testing done today:
  • Running SafeZone Browser in Bank Mode will result in the same WebRTC leak as in standard desktop environment.
  • Running SafeZone Browser in avast VPN will also result in a WebroRTC leak, but shows the actual avast VPN ip (100.100.48.17) instead of the system ip shown in the first attachment above.
Obviously, SafeZone Browser will behave the same way outside of Bank Mode whether in VPN or not.
Just so you know, Opera browser also shows the same vulnerability whether running in VPN or outside VPN, as it also allows WebRTC to run and display.

Hope this clarifies things for you.
« Last Edit: May 25, 2017, 09:48:21 PM by mchain »
Windows 10 Home 64-bit 22H2 Avast Premier Security version 24.1.6099 (build 24.1.88821.762)  UI version 1.0.797
 UI version 1.0.788.  Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.2.6105 (build 24.1.8918.827) UI version 1.0.801

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89059
  • No support PMs thanks
Re: WebRTC leak in SafeZone Browser
« Reply #3 on: May 25, 2017, 09:59:53 PM »
It is a little clearer, now that you mention you can also run it without actually using a VPN to see if WebRTC is run.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5616
  • Spartan Warrior
Re: WebRTC leak in SafeZone Browser
« Reply #4 on: May 25, 2017, 10:08:06 PM »
Shoot, I was hoping it would be a lot clearer.   :D

Anyways, I don't think SafeZone browser should be doing this?  Either in standard desktop or Bank Mode?

If you are leery of running ipleak.net in your browser, you can do so safely via Sandboxie program, just so you know.  Set the sandbox to automatically delete on browser close.  As long as you run sandboxie, the real browser will be unchanged.  You can do things like change/disable NoScript without making permanent changes to the real browser.

[EDIT:]  Fix typo.
« Last Edit: May 25, 2017, 10:26:31 PM by mchain »
Windows 10 Home 64-bit 22H2 Avast Premier Security version 24.1.6099 (build 24.1.88821.762)  UI version 1.0.797
 UI version 1.0.788.  Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.2.6105 (build 24.1.8918.827) UI version 1.0.801

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89059
  • No support PMs thanks
Re: WebRTC leak in SafeZone Browser
« Reply #5 on: May 25, 2017, 10:55:21 PM »
The clarity is probably whizzing over the top of my head, having never used used VPN software or the SafeZone Browser. I have never considered them for my browsing habits.

Lots of people are concerned about Internet Privacy, I have taken the position that what I do in the internet is pretty much out there to be harvested, very little privacy. I take alternative measures to protect my system without worrying too much about privacy.

There are many tests that can be run and many that have been posted in the forums, but to actually run these tests, the first thing that I have to do is lower my defences to allow the test to run.

A long time ago I did have sandboxie installed but over time I found I wasn't really using it, so it went the way of other under/un used programs they were uninstalled.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5616
  • Spartan Warrior
Re: WebRTC leak in SafeZone Browser
« Reply #6 on: May 26, 2017, 04:12:53 AM »
Thank you David.   ;D

Irregardless, many users here think that SafeZone Browser is a good browser, and maybe a secure one, and maybe, for most it is.  Just pointing out a security hole I believe should not be there, especially since it is touted as a more secure browser out-of-the-box than most.

Question raised in the first post still stands:  Is there a fix or add-on available?
Windows 10 Home 64-bit 22H2 Avast Premier Security version 24.1.6099 (build 24.1.88821.762)  UI version 1.0.797
 UI version 1.0.788.  Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.2.6105 (build 24.1.8918.827) UI version 1.0.801

REDACTED

  • Guest
Re: WebRTC leak in SafeZone Browser
« Reply #7 on: May 26, 2017, 03:42:42 PM »
Hi mchain,

the latest Opera and Avast SZ Browser 3.55.2393.596 have both WebRTC options under their security settings. I actually don't understand why your Opera and SZ still leak your real ISP IP. I tested www.ipleak.net and others with my VPN (Windscribe) and my real IP was hidden. Have you used these options?

Kind regards
M2M  :)

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5616
  • Spartan Warrior
Re: WebRTC leak in SafeZone Browser
« Reply #8 on: May 27, 2017, 02:06:34 AM »
Thank you for pointing me in a direction to resolve the WebRTC issues in both SafeZone Browser and Opera.

See attached below for setting changes that can be made to both, since both are Chromium browsers, changes made are similar:

Basically, there is no user guide to show such settings that I could find, I had to open 'Settings' in both browsers and type in webrtc in the search settings field to get available options.  I could not find webrtc settings elsewhere in either settings configuration field, and I looked more than once.
  • In Avast, it was necessary to tick the 'Show Advanced Options' box to make changes needed.
I found that making these changes is not intuitive for the average user in any case. 

Windows 10 Home 64-bit 22H2 Avast Premier Security version 24.1.6099 (build 24.1.88821.762)  UI version 1.0.797
 UI version 1.0.788.  Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.2.6105 (build 24.1.8918.827) UI version 1.0.801