Skip to Content [alt-c]

Andrew Ayer


Hardening OpenVPN for DEF CON

Comment by Reader Victor Dorneanu

This comment is owned by whoever posted it. I am not responsible for it in any way.

Hi Andrew!

First thanks for this excellent article. I was playing around with your hook script and then I've noticed that nothing really happens. Having a look at your script I've seen this one:

/sbin/ip route show dev $dev table main | while read route

In my client conf I have:

# Add extra client protection script-security 2 setenv OPENVPN_ROUTE_TABLE 94 route-noexec route-up /usr/local/bin/route route

The connection is being successfully established, however the tun0 device has no ip routes at all, so in that case

/sbin/ip route show dev $dev table main | while read route

will cause nothing to happen.

Any ideas?

Cheers, Victor

| Posted on 2015-11-15 at 16:26:34 UTC by Reader Victor Dorneanu | Reply to This

Post a Reply

Your comment will be public. If you would like to contact me privately, please email me. Please keep your comment on-topic, polite, and comprehensible. Use the "Preview" button to make sure your comment is properly formatted. Name and email address are optional. If you specify an email address it will be kept confidential.

Post Comment

(Optional; will be published)

(Optional; will not be published)

(Optional; will be published)

  • Blank lines separate paragraphs.
  • Lines starting with ">" are indented as block quotes.
  • Lines starting with two spaces are reproduced verbatim.
  • Text surrounded by *asterisks* is italicized.
  • Text surrounded by `back ticks` is monospaced.
  • URLs are turned into links.