Penetration Testing mailing list archives

Re: MS VPN


From: "mjc001 () juno com" <mjc001 () juno com>
Date: Tue, 5 Dec 2006 15:02:53 GMT

Ok, will do. Thought I would "go fish" on the first pass. 

-- "Michael" <anubis () citizensofgravity net> wrote:

lol, sorry man, you're into "if you have to ask..." territory. Try it 
and
see.

What would be a sample command line?

-- "Michael" <anubis () citizensofgravity net> wrote:

check out pptp-bruter by thc-- it didn't exist last time I had to 
bust
a
pptp vpn, so I forgot about it.

If you have a good password list you can really go to town.



I didn't see Brutus mentioned. Is it for Web apps only?

-- "Michael Kozakavich" <blackavar () citizensofgravity com> wrote:

Old but still useful overview:

http://www.sans.org/resources/malwarefaq/pptp-vpn.php?
portal=611617edcb55ca29863b5f7536ba98d1

More recent, I have never used ASLEAP so I can't comment.

http://blogs.zdnet.com/Ou/index.php?p=21

If you can capture a client session recovery of the client password
should
be relatively trivial. If you don't have access to a client session
it
used to be eminently brute-forceable because it would never lock you
out,
you could just keep grinding away.



What is the tool of choice to attempt to penetrate the Microsoft 
VPN
(port 1723), with or without a user name?







_______________________________________________________________________
_
Try Juno Platinum for Free! Then, only $9.95/month!
Unlimited Internet Access with 1GB of Email Storage.
Visit http://www.juno.com/value to sign up today!



-------------------------------------------------------------------
-
-
---
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?
camp=701600000008bOW
-------------------------------------------------------------------
-
-
---





--
"Proceeds the Weedian... Nazareth!"
-Sleep




_______________________________________________________________________
_
Try Juno Platinum for Free! Then, only $9.95/month!
Unlimited Internet Access with 1GB of Email Storage.
Visit http://www.juno.com/value to sign up today!






--



_______________________________________________________________________
_
Try Juno Platinum for Free! Then, only $9.95/month!
Unlimited Internet Access with 1GB of Email Storage.
Visit http://www.juno.com/value to sign up today!





-- 
"Proceeds the Weedian... Nazareth!"
-Sleep


________________________________________________________________________
Try Juno Platinum for Free! Then, only $9.95/month!
Unlimited Internet Access with 1GB of Email Storage.
Visit http://www.juno.com/value to sign up today!



------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------


Current thread: