How unsecure is PPTP for my use?

jkroeder

Member
Dec 7, 2009
165
0
71
On my home router with Tomato firmware, I have two options of setting up a VPN. I can use OpenVPN or PPTP. I'm aware that the consensus between the two is that OpenVPN is the winner by far.

However, all I'm trying to do with this is to have an encrypted tunnel to use on the rare occasion I need it on a wifi hotspot or similar situation. So, if the password is strong enough (more than 12 characters, random, etc), all traffic is forwarded through the connection, and MPPE-128 encryption is used, is it good enough for this use?



I realize I could just do it right and use OpenVPN. I've been trying to do just that. I've just been having issues generating certificates, specifically the server cert. I think it's an issue with index.txt file which I'm looking into.

Thanks
 
Last edited:

matricks

Member
Nov 19, 2014
194
0
0
I don't know what index.txt file you are talking about. I've just used the EasyRSA scripts, they've never failed me (I've run my own OpenVPN gateways with certificate authentication since OpenVPN 2.0 days).

You ask if PPTP is secure enough. How secure do you need it to be? Is it OK if some geek dedicates a few hours of his computer resources to decrypt your traffic? There are ready-made tools for cracking PPTP, all a malicious guy needs is some actual data to work with.

I would never use PPTP unless my only goal was to form a tunnel to a remote point, not having to care at all about who could potentially read my communication. If the certificates are your only issue, just figure them out.
 

Chaosblade02

Senior member
Jul 21, 2011
304
0
0
Its fine if you're just looking to hide your real IP address for random internet related tasks, but its not secure for someone who is willing to put forth the time and effort into finding out your information. But hey, at least they have to work for it. I'm flattered if some random geek wants to dedicate hours of their time for little old me.

I like open VPN better, and there are some free VPN services like vpnbook that have open VPN profiles you can use. Its simple enough where a novice user could set this up.
 
Last edited:

jkroeder

Member
Dec 7, 2009
165
0
71
This was the index.txt error I was referring to.
https://forums.openvpn.net/topic7551.html

I should be able to put some more time into it and get OpenVPN working then.

So, to use a different networking analogy, it'd be like using WEP on a wireless network then.


Thanks for the PPTP info guys. I won't use it much longer then.
 

jkroeder

Member
Dec 7, 2009
165
0
71
So, I was able to get the certificates generated after I got that issue fixed.

I have the OpenVPN server and client to route all traffic through the VPN. One issue I'm having now is that I'm getting DNS leaks. I do however get the correct home IP address.

If i go to dnsleaktest.com or ipleak.net, it clearly shows the DNS servers of my current connection and not the home connection. Whereas with the PPTP connection, I don't have any DNS leak.

Any ideas what I should be looking for?

my opvn file

client
dev tun
proto tcp
remote ipaddressofserver 1194
resolv-retry infinite
nobind
persist-key
persist-tun

ca ca.crt
cert client1.crt
key client1.key
ns-cert-type server
cipher AES-128-CBC
comp-lzo
verb 4
 

matricks

Member
Nov 19, 2014
194
0
0
Show your server config as well. Do you push DNS addresses to your clients?
Code:
server
proto udp
port 1194
[and]
[so]
[on]

push "dhcp-option DNS 77.109.148.136"
push "dhcp-option DNS 77.109.148.137"
 

mxnerd

Diamond Member
Jul 6, 2007
6,799
1,101
126
Every website you visit can use tools to do ip lookup, check with ARIN and find your ISP IP block and your ISP DNS.

The websites that use "leak" in their name just trying to sell you VPN service.
 
Last edited:
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |