Microsoft pptp vpn vulnerabilities Exploits in Action



Download 2 Mb.
Pdf ko'rish
bet64/144
Sana16.01.2022
Hajmi2 Mb.
#372744
1   ...   60   61   62   63   64   65   66   67   ...   144
Bog'liq
microsoft-pptp-vpn-vulnerabilities-exploits-action 337

Description of Variants:
Anger is based partially on some of the 
contributions made by it’s predecessors deceit.c & ntpptp.c, and is very simple 
to use.
Protocol Description:
Due to weaknesses in the MS PPTP & MSCHAP 
version technologies, theses scripts can quickly crack the user’s login 
information.
How the Exploit Works:
The basic modes of Anger.c are the same in both Exploit #4 and #5.
But #5 included the additional option to attack MS-CHAP version 2 and 
NT Encryption based hashes in addition to the LANMAN based hashes.
Anger.c has several attack modes.
The most basic passive mode simply “sniffs” the traffic from a PPTP 
challenge-response event, it parses out the MS-CHAP portion and outputs the 
information to any file in a format compatible with the L0phtcrack password 
cracking tool.
Anger.c can also initiate an active attack manipulating the MS-CHAP 
version 1 protocol. It is able to initiate a “change password” request to the PPTP 
client attempting to logon to the PPTP VPN server. The user will then see a 
password change request dialog box appear on the screen. The user will then fill 
it out and submit the information, then the attacker will easily acquire this 
information. These hashes will then be formatted and output to a L0phtcrack 
compatible file for cracking. The attacker could also just use these raw hashes 
using a modified version of a PPTP client to logon directly to the VPN server.
MSCHAP version 2 client’s are NOT vulnerable to the aforementioned 
password change attack. However, the new encryption methods used do not 
0



Download 2 Mb.

Do'stlaringiz bilan baham:
1   ...   60   61   62   63   64   65   66   67   ...   144




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish