[ Updated : Added "10 Common Mistakes of Incident Responders" at the bottom]
[Start of Excerpt]
Alit-Reza Anghaie |
I'm not quite sure of the right format but I'm going with a Top Twenty - so I'll keep on the biggest pain points as I see them.
[ Updated : Added "10 Common Mistakes of Incident Responders" at the bottom]
Alit-Reza Anghaie |
A post within the "straight to the meat" category :
There was a talk at Defcon 20 entitled "Defeating PPTP VPNs and WPA2 Enterprise with MS-CHAPv2", by Moxie and David Hulton - the talk announced the implementation of a tool that reduced the security of MS-CHAPv2 to the strength of a single
DES encryption.
This post gives a quick rundown with references on what you need to know, enjoy - Thierry
History :
1999 - Bruce Schneier and Mudge document the vulnerability [2]
2011 - Sogeti releases POC performing the same attack against MS-CHAPv2 [4]
2012 - Defcon Talk detailing the flaw and release of SAAS to crack the key within 23hours [3]
I recently completed my studies at the Luxembourg School of Business and began exploring how to incorporate my newfound knowledge into my fi...