ZenMate showing my real IP through another vpn

Discussion in 'privacy problems' started by Fallen, May 10, 2015.

  1. Fallen

    Fallen Registered Member

    Joined:
    May 10, 2015
    Posts:
    4
    Hello guys,

    I use CyberGhost VPN and sometimes additionally ZenMate as an addon for my Firefox. I use NoScript and changed media.peerconnection.enabled and geo.enabled values. So cloakfish.com and ipleak.net do not leak my real IP (not real, but that of my CyberGhost) while using ZenMate. I am satisfied with both services in general. BUT, just today while changing the location in ZenMate I saw that he shows my real IP on the left side. Here's the picture:
    http://image-upload.de/image/Utp1NQ/849d276d67.png
    On the lft it showed my real, german IP. On the right is my VPN's IP and location.

    First I wanted to ask how this works. When I use ZenMate over a VPN client, does ZM create an own tunnel which begins with my real IP and ends with ZM? Or does it create another tunnel which begins with CyberGhost IP and ends with ZM?

    I then enabled WebRTC and checked the leaking. ZenMate leaked my CG VPN IP. So that means the VPN is stacking up. I am using ZM over CG over my real IP. But why ZM shows me my real IP like in the picture? Where does it have from? What IP does ZM provider see? Prefect would be my ISP sees the encrypted connection to CG, CG sees the encrypted connection to ZM and ZM sees my outcome from CG, not my real IP.

    Anny suggestions?

    Best regards,

    Fallen
     
  2. Fallen

    Fallen Registered Member

    Joined:
    May 10, 2015
    Posts:
    4
    This is new, I use ZM for several weeks now and I just saw it today. On my VM was the same "issue" but now it's gone. It is showing the CG IP.
     
  3. mirimir

    mirimir Registered Member

    Joined:
    Oct 1, 2011
    Posts:
    6,030
  4. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    5,829
    Location:
    Last Breath Farm
    Indeed, the title of that thread is ZenMate leaks your IP! FIXED, if you kill Flash. I believe the conclusion was that Flash Player was the culprit.
    I now use Chrome extension FlashControl in conjunction with ZM and figure it is not leaking, but I admit to not running tests.
     
  5. MisterB

    MisterB Registered Member

    Joined:
    May 31, 2013
    Posts:
    1,103
    Location:
    Southern Rocky Mountains USA
    Try Cyberghost with generic OpenVPN software. Zenmate is untrustworthy but it should only leak the Cyberghost IP, not your real IP. I would suspect there is some flaw in the Cyberghost client software that causes this. I had a free Cyberghost subscriptions for a while and I found their client software way too bloated.

    If you started the browser before the Cyberghost client, the browser and Zenmate were exposed to your real IP and might have cached it. Zenmate is an encrypting proxy at best. You can't expect a browser extension coded in javascript to be capable of handling low level networking functions reliably.
     
  6. mirimir

    mirimir Registered Member

    Joined:
    Oct 1, 2011
    Posts:
    6,030
    Depending on killing some app-level thing is skating on some thin ice, no?
     
  7. Fallen

    Fallen Registered Member

    Joined:
    May 10, 2015
    Posts:
    4
    ZenMate is reliable. It was not leaking anything. This thread is old but if you read all of it you will see that flash and WebRTC were leaking your IP. So it doesn't matter what proxy addon you use. Even TOR leaks the same way your IPs. With FlashControl or NoScript you block flash/java scripts so no leaking here then.


    You may be right. First of all at Windows (yeah I use Windows as host....) startup CG was asking me if it's allowed to be run, what happens one or two times a week. Normally it's the first program that is establishing Internet connection. But yesterday it took a while till it was rdy to go. On my VM it also starts with an error, couldn't start a script, something with user interface, and before it connects to any VPN server it opens the browser and navigate it to CG homepage. And bcz I use ZenMate every time on my VM it established a connection from my VM's IP to ZM servers. This way it know from beginning my VM's IP. Thanks! So the issue here is indeed CyberGhost's software. I try the OpenVPN generic one.

    Thank you all for quick replies :)
     
  8. Fallen

    Fallen Registered Member

    Joined:
    May 10, 2015
    Posts:
    4
    Today I had a smooth start and ZenMate shows me the CG IP.
     
Loading...