Security Basics mailing list archives

Can anyone break MD5 scheme?


From: cyber_armstrong <cyber_armstrong () yahoo co uk>
Date: Thu, 28 Nov 2002 06:03:43 +0800

I paid a high monthly fee for my PPPOE connection. The damned ISP offered only the client for M$ Windows. According to the packet dump, they use CHAP for authorization and the CHAP challenge said it used MD5. But when rp-pppoe MD5s the string of Identifier+Secret+Challenge Value, the concentrator said the response is wrong.

Apparently the ISP-offered client is not going with the RFC 1994 standard for CHAP and obviously I cannot get their source code by social engineering.

/Is there a way to break the MD5? Or anyway around ? /I need to know my ISP's digest scheme to get my Linux box online. I lived in a higly-sensored country and who knows what the offered client will do behind my back? Thanks in advance for my safety (not privay).

__________________________________________________
Do You Yahoo!?
Everything you'll ever need on one web page
from News and Sport to Email and Music Charts
http://uk.my.yahoo.com


Current thread: