Cookie Consent by Free Privacy Policy Generator Aktuallisiere deine Cookie Einstellungen ๐Ÿ“Œ Tools released at Defcon can crack widely used PPTP encryption in under a day


๐Ÿ“š Tools released at Defcon can crack widely used PPTP encryption in under a day


๐Ÿ’ก Newskategorie: IT Security Tools
๐Ÿ”— Quelle: ehackingnews.com

Security researchers released two tools at the Defcon security conference which can be used to crack the encryption of any PPTP (Point-to-Point Tunneling Protocol) as well as WPA2-Enterprise (Wireless Protected Access) sessions which use MS-CHAPv2 for authentication.


MS-CHAPv2 is an authentication protocol created by Microsoft and introduced in Windows NT 4.0 SP4. Despite its age, it is still used as the primary authentication mechanism by most PPTP virtual private network (VPN) clients.

ChapCrack can take captured network traffic that contains a MS-CHAPv2 network handshake (PPTP VPN or WPA2 Enterprise handshake) and reduce the handshake's security to a single DES (Data Encryption Standard) key.


This DES key can then be submitted to CloudCracker.com -- a commercial online password cracking service that runs on a special FPGA cracking box developed by David Hulton of Pico Computing -- where it will be decrypted in under a day.


The CloudCracker output can then be used with ChapCrack to decrypt an entire session captured with WireShark or other similar network sniffing tools.


PPTP is commonly used by small and medium-size businesses -- large corporations use other VPN technologies like those provided by Cisco -- and it's also widely used by personal VPN service providers, Marlinspike said.


The researcher gave the example of IPredator, a VPN service from the creators of The Pirate Bay, which is marketed as a solution to evade ISP tracking, but only supports PPTP.


Marlinspike's advice to businesses and VPN providers was to stop using PPTP and switch to other technologies like IPsec or OpenVPN. Companies with wireless network deployments that use WPA2 Enterprise security with MS-CHAPv2 authentication should also switch to an alternative.

...



๐Ÿ“Œ Tools released at Defcon can crack widely used PPTP encryption in under a day


๐Ÿ“ˆ 110.61 Punkte

๐Ÿ“Œ CVE-2019-15261 | Cisco Aironet Access Point PPTP VPN Packet input validation (cisco-sa-20191016-airo-pptp-do)


๐Ÿ“ˆ 45.57 Punkte

๐Ÿ“Œ Google discloses a severe flaw in widely used Libgcrypt encryption library


๐Ÿ“ˆ 30.96 Punkte

๐Ÿ“Œ Widely used medical infusion pump can be remotely hijacked


๐Ÿ“ˆ 28.39 Punkte

๐Ÿ“Œ ZuoRAT Can Take Over Widely Used SOHO Routers


๐Ÿ“ˆ 28.39 Punkte

๐Ÿ“Œ HashCat Can Now Crack An Eight-Character Windows NTLM Password Hash In Under 2.5 Hours.


๐Ÿ“ˆ 24.91 Punkte

๐Ÿ“Œ Widely-used patient care app found to include hidden 'backdoor' access


๐Ÿ“ˆ 24.24 Punkte

๐Ÿ“Œ Widely-used patient care app found to include hidden 'backdoor' access


๐Ÿ“ˆ 24.24 Punkte

๐Ÿ“Œ Why is TCPcrypt not widely used?


๐Ÿ“ˆ 24.24 Punkte

๐Ÿ“Œ Google Finds 7 Security Flaws in Widely Used Dnsmasq Network Software


๐Ÿ“ˆ 24.24 Punkte

๐Ÿ“Œ KRACK Demo: Critical Key Reinstallation Attack Against Widely-Used WPA2 Wi-Fi Protocol


๐Ÿ“ˆ 24.24 Punkte

๐Ÿ“Œ New Mirai Okiru Botnet targets devices running widely-used ARC Processors


๐Ÿ“ˆ 24.24 Punkte

๐Ÿ“Œ Tech Firms Let Russia Probe Software Widely Used by US Government


๐Ÿ“ˆ 24.24 Punkte

๐Ÿ“Œ New BLEEDINGBIT Vulnerabilities Affect Widely-Used Bluetooth Chips


๐Ÿ“ˆ 24.24 Punkte

๐Ÿ“Œ Widely Used Web Conference Service Zoom Patches Critical Flaw


๐Ÿ“ˆ 24.24 Punkte

๐Ÿ“Œ Game of Thrones Downloads Widely Used to Spread Malware


๐Ÿ“ˆ 24.24 Punkte

๐Ÿ“Œ Hackers Actively Exploiting Widely-Used Social Share Plugin for WordPress


๐Ÿ“ˆ 24.24 Punkte

๐Ÿ“Œ DEF CON report finds decade-old flaw in widely used ballot-counting machine


๐Ÿ“ˆ 24.24 Punkte

๐Ÿ“Œ University Researchers Discover Security Flaws In Widely Used Data Storage Devices


๐Ÿ“ˆ 24.24 Punkte

๐Ÿ“Œ Rogue Developer Infects Widely Used NodeJS Module to Steal Bitcoins


๐Ÿ“ˆ 24.24 Punkte

๐Ÿ“Œ Researchers have created new artificial intelligence that could spell the end for one of the most widely used website security systems.


๐Ÿ“ˆ 24.24 Punkte

๐Ÿ“Œ Critical Flaws Found in Widely Used IPTV Software for Online Streaming Services


๐Ÿ“ˆ 24.24 Punkte

๐Ÿ“Œ Alphanumeric passwords are widely used, yet enable phishing scams


๐Ÿ“ˆ 24.24 Punkte

๐Ÿ“Œ Two Widely Used Ad Blocker Extensions for Chrome Caught in Ad Fraud Scheme


๐Ÿ“ˆ 24.24 Punkte

๐Ÿ“Œ Misleading Results From Widely-Used Machine-Learning Data Analysis Techniques


๐Ÿ“ˆ 24.24 Punkte

๐Ÿ“Œ Widely Used Kiosks Compromised by Hardcoded Credentials


๐Ÿ“ˆ 24.24 Punkte

๐Ÿ“Œ Most Widely Used Plesk Extensions and Toolkits This โ€˜HoliDealsโ€™ Season (Part 2)


๐Ÿ“ˆ 24.24 Punkte

๐Ÿ“Œ Security researchers found 21 flaws in this widely used email server, so update immediately


๐Ÿ“ˆ 24.24 Punkte











matomo