Re: Secure and convenient protocol
James Cameron <[email protected]>
| Newsgroups | gmane.network.poptop |
|---|---|
| Organization | Netrek Vanilla Server Dictator |
| Message-ID | <[email protected]> |
On Tue, Apr 26, 2011 at 10:28:35PM +0200, Gregoire leroy wrote: > On Tue 26/04/11 07:18, James Cameron [email protected] wrote: > > On Thu, Apr 21, 2011 at 04:21:05PM +0200, Gr?goire Leroy wrote: > > > Is bruteforce attack the only problem with MSCHAPV2 > > ? > > No, it can be transparently attacked by capture of the datastream, > > and since the MSCHAP tokens are used as MPPE keys, and it is only > > 128-bit encryption, and the same keys are used at each end, the data > > is easily obtained. > > I've seen kiddies video (kiddies scripts/tuto are my real target) > which said that they forced the server to use MSCHAP-V1. Can it work > if we use "refuse mschap" directive ? refuse-mschap option is the default in options.pptpd shipped in examples/ of pptpd tar.gz, and if it were negotiated then MPPE would fail since MPPE depends on MSCHAP V2, so if require-mppe-128 is present as it should be the link would fail. If you consider your attack source sufficiently unsophisticated, then you may turn off whatever control you like. In my experience, the most successful attacks come from either children with a high level of divergent thinking, or expert adults. -- James Cameron http://quozl.linux.org.au/ ------------------------------------------------------------------------------ WhatsUp Gold - Download Free Network Management Software The most intuitive, comprehensive, and cost-effective network management toolset available today. Delivers lowest initial acquisition cost and overall TCO of any competing solution. http://p.sf.net/sfu/whatsupgold-sd