networking-forum.com
Community BlogCommunity Wiki * Register  * Search  * Login
View unanswered postsView active topics

All times are UTC - 6 hours [ DST ]



Post new topic Reply to topic  [ 4 posts ] 
Author Message
PostPosted: Tue Jul 31, 2012 7:29 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Tue Aug 21, 2007 2:15 pm
Posts: 8457
Location: Frederick MD
Certs: Instanity
yikes

directly from the ISC

Moxie Marlinspike and David Hulton gave a talk at Defcon 20 on a presentation on cracking MS-CHAPv2 with 100% success rate. This protocol is still very much in use with PPTP VPNs, and WPA2 Enterprise environments for authentication.

Moxie's recommendations [1]:

1- All users and providers of PPTP VPN solutions should immediately start migrating to a different VPN protocol. PPTP traffic should be considered unencrypted.
2- Enterprises who are depending on the mutual authentication properties of MS-CHAPv2 for connection to their WPA2 Radius servers should immediately start migrating to something else.

Knowing that MS-CHAPv2 can now be cracked, what alternatives are you considering to secure your now insecure communications? The two alternatives suggested by Moxie are "[...] OpenVPN configuration, or IPSEC in certificate rather than PSK mode."

[1] https://www.cloudcracker.com/blog/2012/ ... s-chap-v2/
[2] https://github.com/moxie0/chapcrack

_________________
"If you're good at anticipating the human mind. It leaves nothing to chance."
-Jigsaw


Top
 Profile  
 
PostPosted: Tue Jul 31, 2012 1:18 pm 
Offline
Post Whore
Post Whore

Joined: Sun May 15, 2011 4:16 pm
Posts: 1439
Location: Belgium
Certs: CCNA Security, CCNP
Thanks for the info. Smart thinking there.

_________________
http://reggle.wordpress.com


Top
 Profile  
 
PostPosted: Fri Aug 03, 2012 8:04 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Sat Oct 20, 2007 11:05 am
Posts: 1953
Location: Plano, TX
Certs: CCNA
Would this effect WPA if you are using EAP-PEAP? Wouldn't the the MS-CHAPv2 negotiation be encrypted by TLS which shouldn't be a problem as long as server certificate validation is configured properly?


Top
 Profile  
 
PostPosted: Fri Aug 03, 2012 10:41 am 
Offline
Senior Member
Senior Member
User avatar

Joined: Thu Nov 17, 2011 6:09 pm
Posts: 498
Location: Portland, OR
texanmutt wrote:
Would this effect WPA if you are using EAP-PEAP? Wouldn't the the MS-CHAPv2 negotiation be encrypted by TLS which shouldn't be a problem as long as server certificate validation is configured properly?


Correct. The crack does not affect MS-CHAPv2 that is encrypted with TLS in a EAP\PEAP session.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 4 posts ] 

All times are UTC - 6 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group