{"id":41,"date":"2009-04-15T20:00:34","date_gmt":"2009-04-16T00:00:34","guid":{"rendered":"http:\/\/www.willhackforsushi.com\/blog\/?page_id=41"},"modified":"2009-04-15T20:10:47","modified_gmt":"2009-04-16T00:10:47","slug":"asleap","status":"publish","type":"page","link":"https:\/\/www.willhackforsushi.com\/?page_id=41","title":{"rendered":"Asleap"},"content":{"rendered":"<p>Demonstrates a serious deficiency in proprietary Cisco LEAP networks.  Since LEAP uses a variant of MS-CHAPv2 for the authentication exchange, it is susceptible to accelerated offline dictionary attacks.  Asleap can also attack the Point-to-Point Tunneling Protocol (PPTP), and any MS-CHAPv2 exchange where you can specify the challenge and response values on the command line.<\/p>\n<hr\/>\n<h2>News<\/h2>\n<p>May 28 2008<\/p>\n<p>The good folks at the <a href=\"http:\/\/backtrack.offensive-security.com\/\" target=\"_blank\">Backtrack project<\/a> pointed out that the Asleap source would not build on some Linux platforms due to an oversight on my part in an include file.  Sorry for the trouble, I&#8217;ve posted a new 2.2 version below that fixes this problem.<\/p>\n<p>July 13 2007<\/p>\n<p>Jay Beale (yes, that <a href=\"http:\/\/www.google.com\/search?q=jay+beale&#038;ie=utf-8&#038;oe=utf-8&#038;aq=t&#038;rls=org.mozilla:en-US:official&#038;client=firefox-a\" target=\"_blank\">Jay Beale<\/a>) got in touch with me and asked if Asleap could be used as a generic MS-CHAPv2 cracking tool.  The result is Asleap 2.1, which includes the \u201c-C\u201d and \u201c-R\u201d options to specify the hex-delimited bytes for the challenge and the response (respectively).  Using this option, Asleap becomes a generic MS-CHAPv2 cracking tool, and can be applied anytime you have a MS-CHAPv2 packet capture available.<\/p>\n<p>Available in the download section, below.  -Josh<\/p>\n<hr\/>\n<h2>Screenshots<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/www.willhackforsushi.com\/blog\/wp-content\/uploads\/2009\/04\/asleap1.png\" alt=\"asleap1\" title=\"asleap1\" width=\"567\" height=\"255\" class=\"aligncenter size-full wp-image-44\" srcset=\"https:\/\/www.willhackforsushi.com\/wp-content\/uploads\/2009\/04\/asleap1.png 567w, https:\/\/www.willhackforsushi.com\/wp-content\/uploads\/2009\/04\/asleap1-300x134.png 300w\" sizes=\"auto, (max-width: 567px) 100vw, 567px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/www.willhackforsushi.com\/blog\/wp-content\/uploads\/2009\/04\/asleap21.png\" alt=\"asleap21\" title=\"asleap21\" width=\"570\" height=\"133\" class=\"aligncenter size-full wp-image-46\" srcset=\"https:\/\/www.willhackforsushi.com\/wp-content\/uploads\/2009\/04\/asleap21.png 570w, https:\/\/www.willhackforsushi.com\/wp-content\/uploads\/2009\/04\/asleap21-300x70.png 300w\" sizes=\"auto, (max-width: 570px) 100vw, 570px\" \/><\/p>\n<hr\/>\n<h2>Download<\/h2>\n<p><strong>Asleap 2.2<\/strong><br \/>\n<a href=\"http:\/\/www.willhackforsushi.com\/code\/asleap\/2.2\/asleap-2.2.tgz\">Linux source<\/a> (110K, MD5: a1d06729fb2addcc5b09bfc14f9b3173)<br \/>\n<a href=\"http:\/\/www.willhackforsushi.com\/code\/asleap\/2.2\/README\">README<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Demonstrates a serious deficiency in proprietary Cisco LEAP networks. Since LEAP uses a variant of MS-CHAPv2 for the authentication exchange, it is susceptible to accelerated offline dictionary attacks. Asleap can also attack the Point-to-Point Tunneling Protocol (PPTP), and any MS-CHAPv2 &hellip; <a href=\"https:\/\/www.willhackforsushi.com\/?page_id=41\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"parent":17,"menu_order":0,"comment_status":"closed","ping_status":"open","template":"","meta":{"footnotes":""},"class_list":["post-41","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/www.willhackforsushi.com\/index.php?rest_route=\/wp\/v2\/pages\/41","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.willhackforsushi.com\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.willhackforsushi.com\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.willhackforsushi.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.willhackforsushi.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=41"}],"version-history":[{"count":5,"href":"https:\/\/www.willhackforsushi.com\/index.php?rest_route=\/wp\/v2\/pages\/41\/revisions"}],"predecessor-version":[{"id":49,"href":"https:\/\/www.willhackforsushi.com\/index.php?rest_route=\/wp\/v2\/pages\/41\/revisions\/49"}],"up":[{"embeddable":true,"href":"https:\/\/www.willhackforsushi.com\/index.php?rest_route=\/wp\/v2\/pages\/17"}],"wp:attachment":[{"href":"https:\/\/www.willhackforsushi.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=41"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}