DEV Community

0x57Origin
0x57Origin

Posted on

Urban VPN DNS Leak: Connected but Not Protected

WireShark Lab

UrbanVPN: Turn on wire shark and then WI-FI interface and then turn on the VPN to Belgium or something.

Now let's filter by the IP that urban VPN gave us. ip.addr == 62.72.41.185... Now first thing I saw was on the top handshake initiated. So let's right click and Follow UDP stream and look for a clear IP and see if there is a leak...Well it is all encrypted. By the way what is UDP Stream? A UDP stream isa continuous flow of data packets sent over a network using the User Datagram Protocol , prioritizing speed and low latency over guaranteed delivery...


I tried another vulnerability which is I clicked the Handshake Initiation and right clicked it then I clicked SET/UNSET Time Reference and then in the filter input I put dns.time_relative < 0 = That filter was trying to find DNS queries that happened before the VPN connection started (which would be a DNS leak).


ARP VULNERABILITY?

It is a maybe here. ARP stands for Address Resolution Protocol, a networking communication protocol used to map a logical IPv4 address to a physical MAC (Media Access Control) address on a local area network (LAN).

Now in wire shark , and in it's filter I put this arp and ip.addr == 62.72.41.185 because I wanted to see only it's ARP connections and the IP address related to the VPN. Now let's first understand what is a DNS query? A DNS query isa computer's request to a DNS server to translate a human-readable website name (like google.com) into a machine-readable IP address(like 142.250.190.46). Now in wire shark I see the DNS query is going to the local server, instead of going through the VPN tunnel. Simply means our browser activity is not fully secured. ISP can fully see which websites you are visiting even when connected to the VPN. This is a real vulnerability the application have. The app isn't properly routing DNS traffic through the encrypted tunnel, leaving our activity exposed.

wireshark_dns_leak_blurred

I went to youtube.com and yeah it is confirmed that Urban VPN is not protecting as much.

I will also write a full dns_leak_check.py to confirm anything before I blame anything on UrbanVPN.


Python Verification

I ran dns_leak_check.py twice, once with the VPN off and once with Urban VPN connected.

VPN off

Time:          2026-09-30 01:55:27
Run ID:        0bc250
Public IP:     hidden
VPN adapter:   none detected
Watched:       Wi-Fi
Lookups sent:  50
Seen on Wi-Fi: 50 (100%)
Sent to:       local DNS server (50)

BASELINE: No VPN adapter detected. 50/50 lookups seen, which is expected.
Enter fullscreen mode Exit fullscreen mode

Urban VPN connected

Time:          2026-09-30 01:55:44
Run ID:        c17e7b
Public IP:     182.54.236.194
VPN adapter:   UrbanVPN
Watched:       Wi-Fi
Lookups sent:  50
Seen on Wi-Fi: 50 (100%)
Sent to:       local DNS server (50)

DNS LEAK: VPN is connected, but 50/50 lookups left Wi-Fi in plaintext.
Enter fullscreen mode Exit fullscreen mode

With the VPN off, all 50 lookups showed up on Wi-Fi, which is normal. With Urban VPN connected, my public IP changed and the UrbanVPN adapter was up, but all 50 lookups still went out on Wi-Fi in plaintext to the same local DNS server. I ran it again with 100 lookups and got 100/100.

Urban VPN is not sending DNS through its tunnel. Anyone watching the local network can still see every site you visit while it says Connected.

Conclusion: Urban VPN says it is trusted by over 80 million users. People install it expecting privacy. In my testing on Windows, it showed "Connected" while every DNS lookup still went out over my local network in plaintext. I encourage Urban VPN to fix this and add real DNS leak protection so their users are actually protected. That is a big chunk of privacy focused people putting their trust in this company.

Top comments (0)