OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
New PPTP2 & RRAS20 Hotfixes
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

New PPTP2 & RRAS20 Hotfixes


  • To: NTBUGTRAQLISTSERV.NTBUGTRAQ.COM
  • Subject: New PPTP2 & RRAS20 Hotfixes
  • From: Alan Ramsbottom <acrals.co.uk>
  • Date: Sun, 31 May 1998 22:27:04 +0100
  • Comments: cc: NTSECURITYLISTSERV.NTBUGTRAQ.COM
  • Reply-To: acrals.co.uk
  • Sender: Windows NT BugTraq Mailing List <NTBUGTRAQLISTSERV.NTBUGTRAQ.COM>

The new PPTP hotfix is now on the MS server along with a new RRAS fix.

ftp://ftp.microsoft.com/bussys/winnt/winnt-
public/fixes/usa/nt40/hotfixes-postSP3/pptp2-fix

ftp://ftp.microsoft.com/bussys/winnt/winnt-
public/fixes/usa/nt40/hotfixes-postSP3/rras20-fix

Amongst other things the PPTP fix seems to implement the latest MPPE
spec functionality i.e. the fix to Aleph One's reset-request attack.
Also includes the MSCHAP change to prevent LANMAN hashes from being
sent, but only when the client is set to require 128-bit encryption.
Dunno if it does the promised "different initial RC4 key in each
direction" trick.. ;)

--Alan--
acrals.co.uk