
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 122
serverfortheremoteusersaccordingly.
SincetheexternalpartnersandsuppliersareusingmostlyWindowsbasedclients,
MSCHAPandMSCHAPV2areselectedastheauthenticationprotocols. According
toChapter14,Lesson2oftheMicrosoftPressMCSETrainingKit—Microsoft
Windows2000NetworkInfrastructureAdministration,
“MSCHAPisavariantofCHAPthatdoesnotrequireaplaintextversionofthe
passwordontheauthenticatingserver.MSCHAPpasswordsarestoredmoresecurely
attheserverbuthavethesamevulnerabilitiestodictionaryandbruteforceattacksas
CHAP.InMSCHAPthechallengeresponseiscalculatedwitha MessageDigest4
(MD4)hashedversionofthepasswordandthenetworkaccessserver(NAS)
challenge.”
25
25
http://www.amazon.com/exec/obidos/ASIN/0735613885/qid=1018719524/sr=11/ref=sr_1_1/104955
75700347903
Kommentare zu diesen Handbüchern