Re: pen test VPN

From: Jose Nazario (jose@biocserver.BIOC.cwru.edu)
Date: 02/26/02


Date: Mon, 25 Feb 2002 19:51:59 -0500 (EST)
From: Jose Nazario <jose@biocserver.BIOC.cwru.edu>
To: Carl Bysen <crbyme@writeme.com>

On Sun, 24 Feb 2002, Carl Bysen wrote:

> what can be done to pen test a VPN setup? Which tools are available,
> additionally does it make sense to pen-test a VPN setup (traffic is
> encrypted)?

shoten and a colleague of his did a discussion at defcon 01 where they
talked about a buffer overflow in a VPN daemon (they didn't identify which
one, but they gave enough info to those who know how their VPN system
works to know they're vulnerable). basic buffer overflow in the
authentication.

also, i have written some libnet 1.1 code for esp and ah packet creation.
between the two basic premises -- DoS/buffer overflow/etc and traffic
injection/insertion -- you should be able to have some fun with a VPN
tunnel.

____________________________
jose nazario jose@cwru.edu
                           PGP: 89 B0 81 DA 5B FD 7E 00 99 C3 B2 CD 48 A0 07 80
                                       PGP key ID 0xFD37F4E5 (pgp.mit.edu)

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • Re: pen test VPN
    ... You may also want to pen test the VPN client. ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • Re: Setup site to site VPN?
    ... If you're not familiar with VPN setup, i would discourage using routers from 2 different manufacturers. ... Use the same router at both locations and the setup should be easy, and you can call a single vendor to get support if you run into problems. ... As with just about anything in networking, there are standards for VPN, but every vendor tweaks them a little. ... DHCP and windows domain controller) on a different network address. ...
    (microsoft.public.windows.server.general)
  • VPN client can connect but no network routing
    ... I've had a Windows 2003/ISA VPN setup and working for some time, ... my XP client PCs cannot access any of the network resources after ... VPN clients from the network. ...
    (microsoft.public.isa.vpn)
  • Re: VPN client can connect but no network routing
    ... > I've had a Windows 2003/ISA VPN setup and working for some time, ... my XP client PCs cannot access any of the network resources ... > successfully logged in VPN clients from the network. ... >, DNS server IP address, and Primary WINS server ...
    (microsoft.public.isa.vpn)
  • Re: VPN and SBS2000 Part 2
    ... > my original post: ok, i had a vpn setup, everything ... > server, but now i can't browse or see shares. ...
    (microsoft.public.windows.server.sbs)