Penetration Testing mailing list archives

VPN server using certificates... any attack against is?


From: Danett song <danett18 () yahoo com br>
Date: Wed, 28 Feb 2007 00:42:45 -0300 (ART)

Hi guys,

All of us are aware of Aggresive mode attacks in PSK
VPN devices, like this good document show:

http://www.giac.org/certified_professionals/practicals/gcih/0541.php

However I got a case where the VPN server (appear to
be a CheckPoint with all updates) is configured to
ONLY authenticate via certificates. Are there any
attacks against VPN using only certificates to
authenticate?

Thank you.

Daniel

__________________________________________________
Fale com seus amigos  de graça com o novo Yahoo! Messenger 
http://br.messenger.yahoo.com/ 

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.

http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------


Current thread: