I'm allowing only fixed IP adresses to VPN in and set up a TS server
session. http://www.securityspace.com in their online security scan can
still detect that I'm running PPTP.

In there evaluation report they adressed vulnerabilities in MS
implementation of PPTP, which I didn't know. See
http://www.schneier.com/pptp-faq.html

Are these vulnerabilities fixed by now?

TIA,

Fred Blum

Re: PPTP/VPN security by Cris

Cris
Tue Sep 13 11:29:25 CDT 2005

This is a multi-part message in MIME format.

------=_NextPart_000_0045_01C5B856.65252AC0
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Are you fully patched???

--=20
Cris Hanna [SBS-MVP]
-------------------------------------------------
Please do not email me directly for assistance. Reply only in the =
Newsgroups for the benefit of everyone
"Fred Blum" <h.f.blum@marketconnect.nlnet> wrote in message =
news:%23yLMwrGuFHA.1136@TK2MSFTNGP12.phx.gbl...

I'm allowing only fixed IP adresses to VPN in and set up a TS server=20
session. http://www.securityspace.com in their online security scan =
can=20
still detect that I'm running PPTP.

In there evaluation report they adressed vulnerabilities in MS=20
implementation of PPTP, which I didn't know. See=20
http://www.schneier.com/pptp-faq.html

Are these vulnerabilities fixed by now?

TIA,

Fred Blum


------=_NextPart_000_0045_01C5B856.65252AC0
Content-Type: text/html;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Diso-8859-1">
<META content=3D"MSHTML 6.00.2900.2722" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV><FONT face=3DArial size=3D2>Are you fully patched???</FONT></DIV>
<DIV><BR>-- <BR>Cris Hanna=20
[SBS-MVP]<BR>-------------------------------------------------<BR>Please =
do not=20
email me directly for assistance.&nbsp; Reply only in the Newsgroups for =
the=20
benefit of everyone</DIV>
<BLOCKQUOTE=20
style=3D"PADDING-RIGHT: 0px; PADDING-LEFT: 5px; MARGIN-LEFT: 5px; =
BORDER-LEFT: #000000 2px solid; MARGIN-RIGHT: 0px">
<DIV>"Fred Blum" &lt;<A=20
=
href=3D"mailto:h.f.blum@marketconnect.nlnet">h.f.blum@marketconnect.nlnet=
</A>&gt;=20
wrote in message <A=20
=
href=3D"news:%23yLMwrGuFHA.1136@TK2MSFTNGP12.phx.gbl">news:%23yLMwrGuFHA.=
1136@TK2MSFTNGP12.phx.gbl</A>...</DIV><BR>I'm=20
allowing only fixed IP adresses to VPN in and set up a TS server =
<BR>session.=20
<A =
href=3D"http://www.securityspace.com">http://www.securityspace.com</A> =
in=20
their online security scan can <BR>still detect that I'm running=20
PPTP.<BR><BR>In there evaluation report they adressed vulnerabilities =
in MS=20
<BR>implementation of PPTP, which I didn't know. See <BR><A=20
=
href=3D"http://www.schneier.com/pptp-faq.html">http://www.schneier.com/pp=
tp-faq.html</A><BR><BR>Are=20
these vulnerabilities fixed by now?<BR><BR>TIA,<BR><BR>Fred=20
Blum<BR><BR></BLOCKQUOTE></BODY></HTML>

------=_NextPart_000_0045_01C5B856.65252AC0--


Re: PPTP/VPN security by Fred

Fred
Fri Sep 16 06:05:25 CDT 2005

This is a multi-part message in MIME format.

------=_NextPart_000_000F_01C5BABF.4D8D8F90
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable


The SBS2k server is indeed fully patched.=20

Fred Blum

"Cris Hanna [SBS-MVP]" =
<crisnospamhanna@computingnospampossibilities.net> wrote in message =
news:OklKPBIuFHA.4080@TK2MSFTNGP12.phx.gbl...
Are you fully patched???

--=20
Cris Hanna [SBS-MVP]
-------------------------------------------------
Please do not email me directly for assistance. Reply only in the =
Newsgroups for the benefit of everyone
"Fred Blum" <h.f.blum@marketconnect.nlnet> wrote in message =
news:%23yLMwrGuFHA.1136@TK2MSFTNGP12.phx.gbl...

I'm allowing only fixed IP adresses to VPN in and set up a TS server =

session. http://www.securityspace.com in their online security scan =
can=20
still detect that I'm running PPTP.

In there evaluation report they adressed vulnerabilities in MS=20
implementation of PPTP, which I didn't know. See=20
http://www.schneier.com/pptp-faq.html

Are these vulnerabilities fixed by now?

TIA,

Fred Blum


------=_NextPart_000_000F_01C5BABF.4D8D8F90
Content-Type: text/html;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Diso-8859-1">
<META content=3D"MSHTML 6.00.2900.2722" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>The SBS2k server is indeed&nbsp;fully =
patched.=20
</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>Fred Blum</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<BLOCKQUOTE dir=3Dltr=20
style=3D"PADDING-RIGHT: 0px; PADDING-LEFT: 5px; MARGIN-LEFT: 5px; =
BORDER-LEFT: #000000 2px solid; MARGIN-RIGHT: 0px">
<DIV>"Cris Hanna [SBS-MVP]" &lt;<A=20
=
href=3D"mailto:crisnospamhanna@computingnospampossibilities.net">crisnosp=
amhanna@computingnospampossibilities.net</A>&gt;=20
wrote in message <A=20
=
href=3D"news:OklKPBIuFHA.4080@TK2MSFTNGP12.phx.gbl">news:OklKPBIuFHA.4080=
@TK2MSFTNGP12.phx.gbl</A>...</DIV>
<DIV><FONT face=3DArial size=3D2>Are you fully patched???</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT><BR>-- <BR>Cris Hanna=20
=
[SBS-MVP]<BR>-------------------------------------------------<BR>Please =
do=20
not email me directly for assistance.&nbsp; Reply only in the =
Newsgroups for=20
the benefit of everyone</DIV>
<BLOCKQUOTE=20
style=3D"PADDING-RIGHT: 0px; PADDING-LEFT: 5px; MARGIN-LEFT: 5px; =
BORDER-LEFT: #000000 2px solid; MARGIN-RIGHT: 0px">
<DIV>"Fred Blum" &lt;<A=20
=
href=3D"mailto:h.f.blum@marketconnect.nlnet">h.f.blum@marketconnect.nlnet=
</A>&gt;=20
wrote in message <A=20
=
href=3D"news:%23yLMwrGuFHA.1136@TK2MSFTNGP12.phx.gbl">news:%23yLMwrGuFHA.=
1136@TK2MSFTNGP12.phx.gbl</A>...</DIV><BR>I'm=20
allowing only fixed IP adresses to VPN in and set up a TS server=20
<BR>session. <A=20
=
href=3D"http://www.securityspace.com">http://www.securityspace.com</A> =
in=20
their online security scan can <BR>still detect that I'm running=20
PPTP.<BR><BR>In there evaluation report they adressed =
vulnerabilities in MS=20
<BR>implementation of PPTP, which I didn't know. See <BR><A=20
=
href=3D"http://www.schneier.com/pptp-faq.html">http://www.schneier.com/pp=
tp-faq.html</A><BR><BR>Are=20
these vulnerabilities fixed by now?<BR><BR>TIA,<BR><BR>Fred=20
Blum<BR><BR></BLOCKQUOTE></BLOCKQUOTE></BODY></HTML>

------=_NextPart_000_000F_01C5BABF.4D8D8F90--