Jump to content
Not connected, Your IP: 216.73.216.108

Staff

Staff
  • Content Count

    11637
  • Joined

    ...
  • Last visited

    ...
  • Days Won

    2071

Everything posted by Staff

  1. @colorman Hello! When you get UDP send exception: send: Operation not permitted please check the firewall rules, store them and send them to us. @eburom Both cases are intended. We will check - (EDIT: bug confirmed); in general an UDP based profile is not compatible (explicit-exit-notify is incompatible with proto tcp) with protocol TCP. Maybe a better behavior might be: allow the override and let OpenVPN library throw the critical error, then exit. That's a design decision, we will check what the developer thinks about it. Kind regards
  2. @colorman Hello! The quoted error is usually caused by a firewall rule blocking UDP, can you please check? Kind regards
  3. @eburom Hello and thank you! We confirm the bug you found. It is being fixed and a new version will be released before the end of May. Kind regards
  4. @eburom Last test has showed that Hummingbird behavior is correct. Of course we can discuss ad nauseam whether an error of this kind should cause Hummingbird to exit completely or not: shall we consider the superuser responsible for his/her actions and trust that he/she does not ignore error messages, or shall we consider him/her inept for his/her role? However, your previous report should be investigated if the issue re-occurs. That, indeed, shows an unexpected outcome, but as long as you can't reproduce it we can't do anything (we could not manage to reproduce it and it never came out during alpha, beta, RC testing...). Kind regards
  5. @crypto1.0 Hello! In Raspbian 10 you don't have a module for table "security". You can safely ignore those warnings, as Network Lock rules will be set anyway, no need of that table. Kind regards
  6. @eburom Can you please post complete log? Kind regards
  7. Hello! The following article will help you resolve the issue: https://www.whatismybrowser.com/guides/how-to-enable-javascript/safari-ipad Currently javascript is essential for the Configuration Generator in our web site. Kind regards
  8. @asunder52 Hello! Hummingbird changes DNS settings at the start of the VPN connection. After that any process with root privileges can change them again. It's not that Hummingbird keeps checking DNS settings continuously: it's superuser's responsibility to be aware of who/what can change DNS settings. What is your distribution name and exact version? Log can be useful anyway, yes. Just send it in its entirety please. Also check the content of your /etc/resolv.conf file while the problem is occurring. Kind regards
  9. @jptor1234 Hello! It's a bug affecting Eddie 2.16.3, do you still see that log entry in Eddie 2.18.9 too, even if you had previously shut Eddie down properly? Kind regards
  10. @Mrd0708 Hello! Each VPN server has ONE exit-IPv4 address which normally never changes (it might change only under exceptional circumstances). As long as you connect to the same VPN server you can reach your service on the same IP address. We also provide a DDNS included in any AirVPN plan which might come handy for your needs: https://airvpn.org/faq/ddns/ Kind regards
  11. Hello! Just reflect on how the Internet works and you will find the answer: because your client tries to contact other peers and it finds peers which listen. Therefore if every and each peer could not listen, p2p could not exist. Without port forwarding you are doomed to become a parasite in the swarm because you can't be contacted by anyone asking for some chunk. More in general, if nobody could see unsolicited incoming packets, the whole Internet would not exist. Kind regards
  12. Hello! If you don't need a GUI check Hummingbird: https://airvpn.org/hummingbird/readme/ Kind regards
  13. @Saken Hello! We have multiple reports from several customers that show your very same problem. We paste below a solution from the support team which so far has worked fine for most of those customers. Kind regards ==== Please make sure that no antivirus or packet filtering tool interfere. Then, we recommend a test with the wintun driver (a new driver for the virtual tun/tap network adapter used by OpenVPN). It is remarkably more efficient than the TAP-Windows driver and it should also resolve the problem you are experiencing now. 1) Install OpenVPN 2.5 tech preview with wintun driver. You can download it from here: https://openvpn.net/download/openvpn-2-5_git-wintun-technology-preview/ Please make sure that the installer installs the wintun driver too. 2) Configure Eddie to run the new OpenVPN you have installed: from Eddie's main window select "Preferences" > "Advanced" in "OpenVPN custom path" select the proper OpenVPN binary file you have installed in point 1, through the file requester (by default and assuming that your HDD is C, it will be C:/Program Files/openvpn/bin/openvpn.exe) click "Save" 3) Configure Eddie to send a directive to OpenVPN to use the wintun driver: select "Preferences" > "OVPN Directives" from Eddie's main window in the directives field enter the following line: windows-driver wintun press ENTER at the end of the line click "Save" Test again connections to AirVPN servers via Eddie. Make sure to pick servers with high bandwidth availability, check in Eddie "Servers" window or here https://airvpn.org/status Kind regards ====
  14. @Mrd0708 Hello! By default Hummingbird enables network lock. See also --network-lock option. Another good place where you can start Hummingbird at boot is /etc/rc.local If you stop Hummingbird properly with a SIGTERM, network lock will be disabled. If you wish to test network lock when Hummingbird is not running, kill Hummingbird with no grace: sudo kill -9 `pidof hummingbird` Your system will remain with firewall's network lock rules and VPN DNS set. When you're done, to restore your previous system settings, re-run Hummingbird with --recover-network option only. Kind regards
  15. @harryhoudini Hello! You can achieve what you want in a minute or so. While Eddie is NOT running configure your firewall to block all traffic to the Internet. Make sure to allow traffic to and from localhost to avoid possible malfunction, and consider your local network too. When you run Eddie, activating Network Lock will also allow communications with Air infrastructure. When you shut down Eddie, the traffic to the Internet will be blocked again. Kind regards
  16. Hello! We're sorry, inbound port forwarding currently does not work in IPv6. Kind regards
  17. @ravenkor The surface attack would increase dramatically, therefore it's unlikely that they will be re-allowed in the future. If you know exactly what you're doing and you have understood how your scenario might be exploited to escalate privileges and gain control of your machine by an attacker who could manage to break in with limited (normal user) privileges, consider to run OpenVPN directly (without Eddie) so you can have a granular as well as thorough control of your security environment. Kind regards
  18. Unfortunately, wireguard is blocked in China, doesn't work anymore through WG protocol..................I have tested Astrill/Torguard/VPNac woth their WG protocol...........confirmed by torguard staff........ damn.......... Wireguard is not designed to bypass blocks. It's sufficient blocking UDP (or strongly shaping outgoing UDP packets) to make Wireguard unusable, and that's more and more common practice on many mobile ISPs in every continent and country. Forget connections over stunnel and don't even fantasize about connections over SSH. There are also other important limitations and concerns, anyway we will make them all very clear when we offer Wireguard. Please use OpenVPN as usual to bypass China blocks. Kind regards
  19. Hello! "up" and "down" are no more allowed by Eddie. Consider to replace them with Eddie's events (VPN Up, VPN down), so you are sure that the scripts or binaries run by the events are NOT run with superuser privileges. OpenVPN would run them with superuser privileges, which is very risky snd makes your system vulnerable to attacks aimed to privilege escalation. Kind regards
  20. Hello, in your Linux computer, check: $ sha256sum org.airvpn.eddie.apk 600e808c59d29b74ff969fac5add7afcf6ef0d89bddac403c976d3073c0693f3 org.airvpn.eddie.apk Kind regards
  21. @quorion Hello! What is your Operating System exact version? Do you experience problems with OpenVPN custom directives, events or both? About events: since Eddie 2.18 events open a shell with your user privileges and run inside that shell what you specify with your user privileges and no more with superuser privileges. It's an essential security feature, it was too reckless and dangerous to run any event with root/administrator privileges. Now it's users' responsibility to escalate privileges, when absolutely necessary, from a binary or a script linked to an event. Kind regards
  22. Hello! airvpn.dev is a web site aimed to maximum "web security" for maximum rating on SSL Labs without compromises (for example only TLS 1.3 and 1.2 are allowed and only the strongest cipher suites can be negotiated). As a result several Operating Systems can't even access that web site that remains essentially an exercise. https://www.ssllabs.com/ssltest/analyze.html?d=airvpn.dev&s=95.211.138.143 It is debatable whether re-direction from a web site to another through links published in a forum is safe or not with a specific warning. In our production web sites we allow linking, and we publish a warning before proceeding when a user clicks an URL. In airvpn.dev such operation is currently not allowed. If you want to be re-directed from airvpn.dev to an external web site, copy and paste the URL on your browser. Kind regards
  23. Hello! Maybe from inside your docker container the modification of system files is not allowed, it would sound correct under a security point of view. Changing system DNS is not a trivial operation and only a superuser can do it. Kind regards
  24. Open a ticket and receive support in a matter of a few hours, instead of spending time in a sterile controversy. Community forums are for the community by the community, we might read them or not, answer to messages or not. Kind regards
×
×
  • Create New...