Some information not mentioned in Gibson's book

SHiNiNg4EvErSHiNiNg4EvEr Member Posts: 5 ■■■□□□□□□□
Hi,
After going through Comptia CertMaster, I noticed that there are some important information aren't mentioned in Gibson's book.

1. PPTP protocol is considered not-secure because it is suspectable to MITM attacks.
2. MD-5 is also not secure & shouldn't be used. Some attacks are reported.
3. Since MD-5 is not secure, CHAP and MS-CHAP is also not secure. MD-5 could be better than SHA only if performance is considered.

Maybe this book needs some updates.

Comments

  • SHiNiNg4EvErSHiNiNg4EvEr Member Posts: 5 ■■■□□□□□□□
    Also LEAP is not secure because it uses MS-CHAP
  • chrisonechrisone Member Posts: 2,278 ■■■■■■■■■□
    Certs: CISSP, EnCE, OSCP, CRTP, eCTHPv2, eCPPT, eCIR, LFCS, CEH, SPLK-1002, SC-200, SC-300, AZ-900, AZ-500, VHL:Advanced+
    2023 Cert Goals: SC-100, eCPTX
  • PseudonymPseudonym Member Posts: 341 ■■■■□□□□□□
    Hi,
    After going through Comptia CertMaster, I noticed that there are some important information aren't mentioned in Gibson's book.

    1. PPTP protocol is considered not-secure because it is suspectable to MITM attacks.
    2. MD-5 is also not secure & shouldn't be used. Some attacks are reported.
    3. Since MD-5 is not secure, CHAP and MS-CHAP is also not secure. MD-5 could be better than SHA only if performance is considered.

    Maybe this book needs some updates.

    PPTP isn't listed in the objectives.

    The security flaws of MD5 are mentioned quite extensively in the book.
    Certifications - A+, Net+, Sec+, Linux+, ITIL v3, MCITP:EDST/EDA, CCNA R&S/Cyber Ops, MCSA:2008/2012, MCSE:CP&I, RHCSA
    Working on - RHCE
Sign In or Register to comment.