Point-to-Point Tunneling Protocol

The Point-to-Point Tunneling Protocol (PPTP) is an obsolete method for implementing virtual private networks. PPTP has many well known security issues.

PPTP uses a TCP control channel and a Generic Routing Encapsulation tunnel to encapsulate PPP packets. Many modern VPNs use various forms of UDP for this same functionality.

The PPTP specification does not describe encryption or authentication features and relies on the Point-to-Point Protocol being tunneled to implement any and all security functionalities.

The PPTP implementation that ships with the Microsoft Windows product families implements various levels of authentication and encryption natively as standard features of the Windows PPTP stack. The intended use of this protocol is to provide security levels and remote access levels comparable with typical VPN products.

History

A specification for PPTP was published in July 1999 as RFC 2637[1] and was developed by a vendor consortium formed by Microsoft, Ascend Communications (today part of Nokia), 3Com, and others.

PPTP has not been proposed nor ratified as a standard by the Internet Engineering Task Force.

Description

A PPTP tunnel is instantiated by communication to the peer on TCP port 1723. This TCP connection is then used to initiate and manage a GRE tunnel to the same peer. The PPTP GRE packet format is non standard, including a new acknowledgement number field replacing the typical routing field in the GRE header. However, as in a normal GRE connection, those modified GRE packets are directly encapsulated into IP packets, and seen as IP protocol number 47. The GRE tunnel is used to carry encapsulated PPP packets, allowing the tunnelling of any protocols that can be carried within PPP, including IP, NetBEUI and IPX.

In the Microsoft implementation, the tunneled PPP traffic can be authenticated with PAP, CHAP, MS-CHAP v1/v2 .

Security

PPTP has been the subject of many security analyses and serious security vulnerabilities have been found in the protocol. The known vulnerabilities relate to the underlying PPP authentication protocols used, the design of the MPPE protocol as well as the integration between MPPE and PPP authentication for session key establishment.[2][3][4][5]

A summary of these vulnerabilities is below:

  • MS-CHAP-v1 is fundamentally insecure. Tools exist to trivially extract the NT Password hashes from a captured MSCHAP-v1 exchange.[6]
  • When using MS-CHAP-v1, MPPE uses the same RC4 session key for encryption in both directions of the communication flow. This can be cryptanalysed with standard methods by XORing the streams from each direction together.[7]
  • MS-CHAP-v2 is vulnerable to dictionary attacks on the captured challenge response packets. Tools exist to perform this process rapidly.[8]
  • In 2012, it was demonstrated that the complexity of a brute-force attack on a MS-CHAP-v2 key is equivalent to a brute-force attack on a single DES key. An online service was also demonstrated which is capable of decrypting a MS-CHAP-v2 MD4 passphrase in 23 hours.[9][10]
  • MPPE uses the RC4 stream cipher for encryption. There is no method for authentication of the ciphertext stream and therefore the ciphertext is vulnerable to a bit-flipping attack. An attacker could modify the stream in transit and adjust single bits to change the output stream without possibility of detection. These bit flips may be detected by the protocols themselves through checksums or other means.[6]

EAP-TLS is seen as the superior authentication choice for PPTP;[11] however, it requires implementation of a public-key infrastructure for both client and server certificates. As such, it may not be a viable authentication option for some remote access installations. Most networks that use PPTP have to apply additional security measures or be deemed completely inappropriate for the modern internet environment. At the same time, doing so means negating the aforementioned benefits of the protocol to some point.[12]

See also

References

  1. ^ RFC 2637
  2. ^ "Malware FAQ: Microsoft PPTP VPN". Retrieved 2017-06-29.
  3. ^ "Microsoft says don't use PPTP and MS-CHAP". Retrieved 2012-11-03.
  4. ^ "A death blow for PPTP". Retrieved 2012-11-03.
  5. ^ "Differences between PPTP and L2TP". bestvpnrating. Archived from the original on 14 September 2016. Retrieved 7 August 2016.
  6. ^ a b Bruce Schneier, Cryptanalysis of Microsoft's Point to Point Tunneling Protocol (PPTP) Archived 2011-06-04 at the Wayback Machine.
  7. ^ Bruce Schneier, Cryptanalysis of Microsoft's PPTP Authentication Extensions (MS-CHAPv2), October 19 1999.
  8. ^ Wright, Joshua. "Asleap". Retrieved 2017-11-01.
  9. ^ "Divide and Conquer: Cracking MS-CHAPv2 with a 100% success rate". Cloudcracker.com. 2012-07-29. Archived from the original on 2016-03-16. Retrieved 2012-09-07.
  10. ^ "Marlinspike demos MS-CHAPv2 crack". The Register. 2012-07-31. Retrieved 2012-09-07.
  11. ^ Choosing EAP-TLS or MS-CHAP v2 for User-Level Authentication, Microsoft TechNet, March 28, 2003
  12. ^ "VPN Protocol Comparison: IKEv2 vs IKEv1 vs OpenVPN vs L2TP vs PPTP". VPN Unlimited Blog. 2018-05-14. Retrieved 2018-06-19.

Read other articles:

Juan Castillo Castillo training with Botafogo.Informasi pribadiNama lengkap Juan Guillermo Castillo Iriart[1]Tanggal lahir 17 April 1978 (umur 45)[2]Tempat lahir Montevideo, UruguayTinggi 182 m (597 ft 1 in)Posisi bermain GoalkeeperInformasi klubKlub saat ini DanubioNomor 1Karier junior1989–1998 Santa BernardinaKarier senior*Tahun Tim Tampil (Gol)1999–2006 Defensor Sporting 122 (0)2001 → Huracán Buceo (loan) 30 (0)2006–2007 Peñarol 38 (0)2008–2009 …

EkanitSebuah Potongan kristal dari EkanitUmumKategoriMineral silikatRumus(unit berulang)Ca2ThSi8O20 atau (Ca,Fe,Pb)2(Th,U)Si8O20Klasifikasi Strunz9.EA.10Sistem kristalTetragonalKelas kristalTrapezohedral (422) simbol H-M: (4 2 2)Grup ruangI422IdentifikasiWarnaHijau, kuning, merah gelapPerawakanKristal piramida, butiran hingga masifBelahanDistinct on {101}FrakturRapuh, tidak rataKekerasan dalam skala Mohs4.5KilauKekaca-kacaanGoresPutihDiafaneitasTransparan hingga translusenBerat jenis2.95 - 3.28S…

Gravity, CompletedAlbum mini (reissue) karya KNKDirilis20 Juli 2017 (2017-07-20)Genre K-pop R&B soul dance[1] BahasaKoreaLabel YNB Entertainment CJ E&M Music (Distribution) Kronologi KNK Remain(2016)Remain2016 Gravity, Completed(2017) Singel dalam album Gravity, Completed RainDirilis: 20 Juli 2017 (2017-07-20) Gravity, Completed adalah album mini ketiga dari grup vokal pria asal Korea Selatan KNK. Album ini merupakan reissue dari singel album kedua grup ini, Gra…

Daftar Penghargaan dan Nominasi Muse Muse saat di Rotterdam 14 November 2009 Penghargaan Menang Nominasi Billboard Music Awards 0 2 BRIT Awards 2 8 Grammy Awards 1 3 Mercury Prize 0 1 Meteor Music Awards 1 3 MTV Asia Awards 1 1 MTV Europe Music Awards 5 10 NME Awards 9 25 Q Award 5 19 American Music Awards 1 1 Kerrang! Awards 4 10 MTV Video Music Awards 1 2 MTV Video Music Awards Japan 0 1 Penghargaan lainnya 6 11 Jumlah Penghargaan menang 36 Nominasi 97 Muse adalah band rock alternatif Inggris …

الدوري المنغولي لكرة القدم 2004 تفاصيل الموسم الدوري المنغولي لكرة القدم  البلد منغوليا  الدوري المنغولي لكرة القدم 2003  الدوري المنغولي لكرة القدم 2005  تعديل مصدري - تعديل   الدوري المنغولي لكرة القدم 2004 هو موسم من الدوري المنغولي لكرة القدم. فاز فيه Khangarid FC [الإن…

Artikel ini tidak memiliki referensi atau sumber tepercaya sehingga isinya tidak bisa dipastikan. Tolong bantu perbaiki artikel ini dengan menambahkan referensi yang layak. Tulisan tanpa sumber dapat dipertanyakan dan dihapus sewaktu-waktu.Cari sumber: Pepesan Kosong – berita · surat kabar · buku · cendekiawan · JSTOR Pepesan Kosong adalah serial situasi komedi yang pernah ditayangkan di TPI sejak tahun 1993 hingga 1995, setiap hari Senin–Jumat pada puk…

Final Liga Champions UEFA 2016TurnamenLiga Champions UEFA 2015–2016 Real Madrid Atlético Madrid 1 1 Setelah perpanjangan waktuReal Madrid menang 5–3 pada adu penaltiTanggal28 Mei 2016StadionSan Siro, MilanPemain Terbaik Sergio Ramos (Real Madrid)[1]WasitMark Clattenburg (Inggris)[2]Penonton71.942[3]CuacaBerawan27 °C (81 °F)Kelembaban 45%[4]← 2015 2017 → Final Liga Champions UEFA 2016 adalah pertandingan final Liga Champions UEFA 2015…

This article needs additional citations for verification. Please help improve this article by adding citations to reliable sources. Unsourced material may be challenged and removed.Find sources: Buenaventura Province – news · newspapers · books · scholar · JSTOR (September 2023) (Learn how and when to remove this template message) 1855 Buenaventura Province was one of the provinces of Gran Colombia. It belonged to the Cauca Department which was created in…

Children's book by Dr. Seuss This article includes a list of general references, but it lacks sufficient corresponding inline citations. Please help to improve this article by introducing more precise citations. (February 2017) (Learn how and when to remove this template message) The Cat in the Hat Comes Back Front coverAuthorDr. SeussIllustratorDr. SeussCountryUnited StatesLanguageEnglishGenreChildren's literaturePublisherRandom HousePublication dateSeptember 12, 1958Media typePrint (hardc…

Cet article est une ébauche concernant la Chine et l’archéologie. Vous pouvez partager vos connaissances en l’améliorant (comment ?) selon les recommandations des projets correspondants. GaochangRuines de stupa dans une constructionPrésentationType Oasis, site archéologiquePartie de Routes de la soie: le réseau de routes du corridor de Chang’an-Tian-shanSurface 4 599 700 m2 ou 512 078 000 m2Patrimonialité Partie d'un site du patrimoine mondial UNESCO (d) …

UK alternative rock band This article is about the British band. For other uses, see sports team. Sports TeamSports Team in 2022 on stage at the festival Piknik i Parken in OsloBackground informationOriginUniversity of Cambridge, Cambridge, United KingdomGenresAlternative rock · Indie rock · post-punkYears active2016 (2016)–presentLabelsIsland, Bright Antenna, Nice Swan RecordsMembersAlex RiceOli DewdneyAl GreenwoodRob KnaggsBen MackHenry YoungWebsitewww.sportsteamband.com Sports Team i…

SMA Negeri 1 KediriInformasiDidirikan9 September 1946AkreditasiANomor Statistik Sekolah103105630101Kepala SekolahWidayat, S.Pd., M.M.Jumlah kelas36 KelasJurusan atau peminatanMIPA dan IPSRentang kelasX, XI MIPA, XI IPS, XII MIPA, XII IPSKurikulumKurikulum 2013, Kurikulum MerdekaStatusNegeri‎NEM terendah34,00NEM tertinggi39,20Nilai masuk rata-rata35,67AlamatLokasiJalan Veteran no. 1, Kediri, Jawa Timur, Indonesia  IndonesiaTel./Faks.(0354)771829Koordinat7°48′42″S 112°00′1…

Town and fortress Roman-Persian Frontier in Late Antiquity. The Roman fortress is designated as Citharizum. Citharizum (Greek: Κιθαρίζων) was a town and fortress on the south arm of the Euphrates[1] in the Roman province of Armenia III. It was a place of great strength which was built by the emperor Justinian and was the residence of one of the five prefects whom that emperor placed over Roman Armenia with the title of “Dux.”[2] According to Procopius of Caesarea, th…

Humpback whalesThe calf Dawn in the Sacramento River in 2007 with the Antioch Bridge visible in the distance Delta and Dawn, also known as the Delta whales, are two humpback whales, a mother and her calf, who entered San Francisco Bay in early May 2007. They swam up the Sacramento River approximately 90 nautical miles (170 km) upstream from the Golden Gate,[1][2] about 20 miles (32 km) further inland than Humphrey the Whale had gone two decades earlier. Under the Endang…

Detective Conan名探偵コナン(Meitantei Konan)Copertina del 14º volume dell'edizione italiana, raffigurante il protagonista Conan Edogawa Generegiallo[1], thriller[1] MangaAutoreGōshō Aoyama EditoreShogakukan - Shōnen Sunday Comics RivistaWeekly Shōnen Sunday Targetshōnen 1ª edizione5 gennaio 1994 – in corso Periodicitàsemestrale Tankōbon105 (in corso) Editore it.Comic Art, Kabuki Publishing, Star Comics 1ª edizio…

Research stations built on the ice of the high latitudes of the Arctic Ocean This article needs additional citations for verification. Please help improve this article by adding citations to reliable sources. Unsourced material may be challenged and removed.Find sources: Drifting ice station – news · newspapers · books · scholar · JSTOR (July 2008) (Learn how and when to remove this message) Soviet drifting ice station depicted on a 1955 stamp. A drifting…

У этого термина существуют и другие значения, см. Чайки (значения). Чайки Доминиканская чайкаЗападная чайкаКалифорнийская чайкаМорская чайка Научная классификация Домен:ЭукариотыЦарство:ЖивотныеПодцарство:ЭуметазоиБез ранга:Двусторонне-симметричныеБез ранга:Вторичн…

保良局馬錦明夫人章馥仙中學Po Leung Kuk Mrs.Ma-Cheung Fook Sien College翻漆後的校舍東北面(2022年3月)地址 香港新界離島區大嶼山東涌富東邨类型津貼中學宗教背景無隶属保良局创办日期1997年学区香港離島區東涌校長柯玉琼女士副校长鄭健華先生,劉俊偉先生助理校长梁煥儀女士职员人数56人年级中一至中六学生人数約700人,24個班別校訓愛、敬、勤、誠校歌保良局屬下校歌分…

Luxembourgish football club Football clubFC CeBra 01Full nameFootball Club Cessange Bracarenses Grund 2001Founded2001; 23 years ago (2001)GroundComplexe Sportif Boy Konen,CessangeCapacity1,000ChairmanYves LauxHead coachChristophe BelloWebsiteClub website Football Club Cessange Bracarenses Grund 2001 is a football club, based in Cessange, in southern Luxembourg founded in 2001 after a merger between Progrès Cessange and Bracarenses Grund.[1] References ^ L'historique du…

AkuntansiKonsep dasarAkuntan · Pembukuan · Neraca percobaan · Buku besar · Debit dan kredit · Harga pokok · Pembukuan berpasangan · Standar praktik · Basis kas dan akrual · PABU / IFRSBidang akuntansiBiaya · Dana · Forensik · Keuangan · Manajemen · PajakLaporan keuanganNeraca · Laba rugi · Perubahan ekuitas · Ar…

Kembali kehalaman sebelumnya