Windows 98 DUN Upgrade A Bundle of Security Enhancements Forrest Stroud
A Bundle of Security Enhancements
Microsoft's DUN client has come a long way since its early Windows 95 days, adding important new features and improved ease-of-use. As a result, the DUN client included in Windows 98 leaves little to be desired. Still, security is always an issue, and the DUN client shipped with Windows 98 includes several potential vulnerabilities associated with the Point to Point Tunneling Protocol (PPTP) implementation.
PPTP server spoofing, reuse of MPPE (Microsoft Point-to-Point Encryption) session keys, password theft, and dictionary attacks against the LAN Manager authentication information are among the most serious security risks present in the client. The downloadable Windows 98 DUN 1.3 Upgrade package addresses all of these issues, while the newer 1.4 Upgrade also adds 128-bit encryption using Microsoft Point to Point Encryption and improved stability with PPTP connections.