Partner With Us
























Possible PPTP Flaw Could Leave VPNs Open

A German security firm warns of a possible flaw in the PPTP service that secures VPNs in both Windows 2000 and Windows XP.

  • Industry Group to Pen Bug-Reporting Standards
  • September 27, 2002
    By Thor Olavsrud: More stories by this author:

    A possible flaw in the point-to-point tunneling protocol (PPTP) in both Windows 2000 and Windows XP could leave corporate intranets vulnerable to attack, German security firm Phion Information Technologies warned Thursday.

    Phion said it had contacted Microsoft about the vulnerability before issuing its security advisory Thursday morning. Microsoft has not confirmed the flaw.

    PPTP is used to secure virtual private networks (VPNs) by allowing two Internet hosts to communicate over a secure channel utilizing authentication and encryption. Phion claimed that the PPTP Service shipping with Windows 2000 and Windows XP contains a remotely exploitable pre-authentication buffer overflow, which could allow a malicious hacker to overwrite kernel memory with a specially crafted PPTP packet.

    Phion said it has verified a denial-of-service lockup on both Windows 2000 SP3 and Windows XP, and noted that a remote compromise should be possible through the use of proper shellcode. Additionally, it said clients are vulnerable, because the service constantly listens to port 1723 on any interface of the machine, making the vulnerability of special concern to DSL users utilizing PPTP to connect to their modems.

    On the client side, Phion suggested firewalling the PPTP port in the Internet Connection Firewall for Windows XP. It had no suggestions for server-side solutions.







    Developer Archives | 7 Day InternetNews Summary | Contact Thor Olavsrud | Back to top

    Add internetnews.com
    to your browser search box.

    IE 7 | Firefox 2.0 | Firefox 1.5.x
    Receive news
    via our XML/RSS:
    feed



    More InternetNews.com


    Hardware Software Mobility Web Content
    Search Government Developer Business
    Storage E-Commerce Networking Security



    internet.commediabistro.comJusttechjobs.comGraphics.com

    Search:

    WebMediaBrands Corporate Info

    Legal Notices, Licensing, Reprints, Permissions, Privacy Policy.
    Advertise | Newsletters | Shopping | E-mail Offers | Freelance Jobs