Re: Secure and convenient protocol

James Cameron <[email protected]>
Newsgroups gmane.network.poptop
Organization Netrek Vanilla Server Dictator
Message-ID <[email protected]>
On Tue, Apr 26, 2011 at 10:28:35PM +0200, Gregoire leroy wrote:
> On Tue 26/04/11 07:18, James Cameron [email protected] wrote:
> > On Thu, Apr 21, 2011 at 04:21:05PM +0200, Gr?goire Leroy wrote:
> > > Is bruteforce attack the only problem with MSCHAPV2
> > ?
> > No, it can be transparently attacked by capture of the datastream,
> > and since the MSCHAP tokens are used as MPPE keys, and it is only
> > 128-bit encryption, and the same keys are used at each end, the data
> > is easily obtained.
> 
> I've seen kiddies video (kiddies scripts/tuto are my real target)
> which said that they forced the server to use MSCHAP-V1.  Can it work
> if we use "refuse mschap" directive ?

refuse-mschap option is the default in options.pptpd shipped in examples/ of
pptpd tar.gz, and if it were negotiated then MPPE would fail since MPPE
depends on MSCHAP V2, so if require-mppe-128 is present as it should be
the link would fail.

If you consider your attack source sufficiently unsophisticated, then
you may turn off whatever control you like.  In my experience, the most
successful attacks come from either children with a high level of
divergent thinking, or expert adults.

-- 
James Cameron
http://quozl.linux.org.au/

------------------------------------------------------------------------------
WhatsUp Gold - Download Free Network Management Software
The most intuitive, comprehensive, and cost-effective network 
management toolset available today.  Delivers lowest initial 
acquisition cost and overall TCO of any competing solution.
http://p.sf.net/sfu/whatsupgold-sd
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.