Security Issues with VPN

From: Tim Kowalsky (webmaster@deltecsolutions.com)
Date: 10/26/01


Message-ID: <012c01c15da5$2dcd2290$0a01a8c0@gotham.designby.com>
From: "Tim Kowalsky" <webmaster@deltecsolutions.com>
To: <focus-ms@securityfocus.com>
Subject: Security Issues with VPN
Date: Thu, 25 Oct 2001 17:34:14 -0500

I'm currently working on a VPN setup using Windows 2000 and have been trying
to research the security issues involved.

I've been able to find documentation about the problems with PPTP under NT4
(big problems) but have found indications that at least some of them have
been fixed in the Windows 2000 version of PPTP, provided that only MS-Chap
V2 is used rather than the older MS-Chap. What I haven't been able to find
are any specifics regarding what issues if any still remain in Windows 2000
PPTP.

Obvisously L2TP/IPSec would be a more secure option but may not be tenable
for the current situation.

Can anyone provide any input on the security on Windows 2000 Server PPTP?

Many Thanks.



Relevant Pages

  • [NT] Cumulative Security Update for Internet Explorer (MS04-025)
    ... Get your security news from a reliable source. ... * Microsoft Windows NT Workstation 4.0 Service Pack 6a ... Navigation Method Cross-Domain Vulnerability ...
    (Securiteam)
  • [NT] Vulnerability in HTML Help Allows Code Execution (MS05-001)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... * Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service ...
    (Securiteam)
  • Re: The Myth of the secure Mac
    ... OEM Windows XP Home goes for a bit under $100. ... >> secure than Home. ... Though this really has nothing to do with security. ... Microsoft counts on third-party developers to provide more ...
    (comp.sys.mac.advocacy)
  • SecurityFocus Microsoft Newsletter #120
    ... Strengthening Network Security: FREE Guide Network security is a ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft Windows File Protection Signed File Replacement... ... PlatinumFTPServer Information Disclosure Vulnerability ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter # 149
    ... MICROSOFT VULNERABILITY SUMMARY ... EveryBuddy Long Message Denial Of Service Vulnerability ... Intellitactics Network Security Manager ... Windows operating systems. ...
    (Focus-Microsoft)