News: This forum is now permanently frozen.
Pages: [1]
Topic: PPTP password with special chars  (Read 4319 times)
« on: July 23, 2007, 14:24:26 »
rajo *
Posts: 6

Hi.
First ting first, nice work guys/(girls) for the m0n0wall product.

I have a problem with the PPTP password thingy, it seems like you can't use special chars in a password like ! # €$£@?§ and so on.

Is it my configuration or is it the m0n0wall config. or ?

Best regards

Rasmus
« Reply #1 on: April 04, 2008, 10:09:05 »
linuxamp
Guest

Rasmus,

According to the handbook, special characters are not supported in PPTP passwords.  This is a major security risk since any expert will tell you that using special characters greatly increases password strength.  The only option for strengthening your VPN in this case is to use a very long password like 20+ characters.
« Reply #2 on: April 04, 2008, 11:41:43 »
ChainSaw
Guest

from what I've read (Disclaimer: I'm no expert), special characters are good but password length is much more critical.

CS...
« Last Edit: April 04, 2008, 11:44:30 by ChainSaw »
« Reply #3 on: May 27, 2008, 10:42:18 »
rajo *
Posts: 6

Thansk for all replies, i will generate a 20+ length password. Smiley
« Reply #4 on: April 21, 2010, 19:00:45 »
ginggs *
Posts: 13

According to the handbook, special characters are not supported in PPTP passwords.  This is a major security risk since any expert will tell you that using special characters greatly increases password strength.  The only option for strengthening your VPN in this case is to use a very long password like 20+ characters.
I've just noticed this is still the case in 1.32.

I also discovered that if you really want special characters for your PPTP passwords it is possible to fool m0n0wall by backing up your configuration, editing the password in the xml config file, and then restoring your configuration.

The PPTP passwords, unlike the other passwords, are stored in plain text in the xml config file, so avoid the '<' and '&' and other characters which may be illegal in xml.

I'm wondering whether having the passwords in plain text isn't a security risk, and if they were encoded like the other passwords special characters would cease to be a problem.
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines