Go Back   Professional Soldiers ® > Technical FAQ Forum > Technology News and Reviews

Reply
 
Thread Tools Display Modes
Old 07-31-2012, 15:12   #1
BOfH
Guerrilla Chief
 
Join Date: Jun 2011
Location: NYC Area
Posts: 828
VPN insecurity: The end of MS-CHAPv2

Disclaimer: This is intended more or less for the security "wonks"(myself included ) on PS.com, and well, anyone else interested in this area.

In summary, MS-CHAPv2, a popular authentication mechanism used in an even more popular remote access solution, PPTP based VPN's, is officially broken. Using purpose built hardware and/or distributed computing, brute forcing the keys used for DES operations in the encryption scheme, which is also used to derive the session keys used to secure the tunnel, hence rendering the entire tunnel insecure, is trivial.

https://www.cloudcracker.com/blog/20...ng-ms-chap-v2/


In other news, the NSA went to Defcon[1]....I wonder how "spot-the-Fed"[2] went.

[1] http://www.computerworld.com/s/artic...ing_cyberspace
[2] http://www.zdnet.com/news/def-cons-s...the-fed/102697
__________________
"Crime is an extension of business through illegal means, politics is an extension of crime through *legal* means."
BOfH is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



All times are GMT -6. The time now is 04:34.



Copyright 2004-2022 by Professional Soldiers ®
Site Designed, Maintained, & Hosted by Hilliker Technologies