Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Focus on Microsoft
PPTP versus L2TP and possible attacks Feb 11 2004 07:19PM
James D. Stallard (james leafgrove com) (2 replies)
Re: PPTP versus L2TP and possible attacks Feb 12 2004 07:55PM
Patrick Power (ppower registrypro pro) (2 replies)
RE: PPTP versus L2TP and possible attacks Feb 13 2004 05:30PM
Zachary Mutrux (zmutrux compumentor org) (1 replies)
As a point of amplification, both L2TP and PPTP are tunneling protocols
without any inherent encryption built in.

In Microsoft's Windows 2K/2K3 implementation, L2TP uses IPSec for
encryption, and PPTP uses MPPE. IIRC, Microsoft's L2TP requires the use of
certificates for authentication and encryption, which means if you choose
that route you must set up a public key infrastructure. That means a little
more work, but also better security.

You might be interested in this paper by Bruce Schneier and Mudge, which
discusses some of the continuing problems with MS-CHAPv2 in conjunction with
MPPE.
http://www.schneier.com/paper-pptpv2.html

Microsoft offers other methods of authentication now in place of MS-CHAPv2,
so I'm not sure if the weaknesses Schneier and Mudge discuss are still as
much of an issue. But there is no question that IPSec based VPN are more
secure than those that use MPPE.

zm

[ reply ]
RE: PPTP versus L2TP and possible attacks Feb 16 2004 04:17PM
Laura A. Robinson (larobins bellatlantic net)
Re: PPTP versus L2TP and possible attacks Feb 12 2004 09:00PM
Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] (sbradcpa pacbell net) (2 replies)
RE: PPTP versus L2TP and possible attacks - what next? Feb 14 2004 09:52PM
James D. Stallard (james leafgrove com)
Re: PPTP versus L2TP and possible attacks Feb 12 2004 09:30PM
Patrick Power (ppower registrypro pro) (1 replies)
RE: PPTP versus L2TP and possible attacks Feb 13 2004 11:46PM
Zachary Mutrux (zmutrux compumentor org)
Re: PPTP versus L2TP and possible attacks Feb 12 2004 03:16PM
Chris Gianelloni (wolf31o2 charter net)







 

Privacy Statement
Copyright 2009, SecurityFocus