L2TP and SSTP are both carried by something else, and they inherit that carrier's weaknesses. L2TP provides no confidentiality on its own and is almost always deployed as L2TP/IPsec, where IPsec supplies the encryption using a pre-shared key; that PSK is frequently weak, default, or shared widely, and is captured and cracked exactly as any IKE PSK, after which the user credentials (PPP/MS-CHAP inside) are the next target. SSTP tunnels PPP over a TLS connection (TCP 443), so its security is TLS's: weak cipher suites, protocol downgrade, and especially unverified or self-signed certificates let a positioned attacker intercept, and the inner PPP authentication (often MS-CHAPv2) is then exposed.
# L2TP/IPsec: attack the IPsec PSK first (aggressive mode, if offered)
ike-scan -A -M -P psk.hash <target>; psk-crack -d wordlist.txt psk.hash
# SSTP (TLS on 443): grade the TLS and check certificate validation
nmap -p443 --script ssl-enum-ciphers <target>
openssl s_client -connect <target>:443 | openssl x509 -noout -issuer -subject
# inner PPP/MS-CHAPv2 (both protocols) is crackable if captured (see PPTP)
Exploitation notes#
- L2TP's security is entirely IPsec's: a weak/default L2TP/IPsec PSK is the same attack as IPsec IKE and weak pre-shared keys; a single shared PSK across all users is common and is the foothold.
- SSTP's security is entirely TLS's: unverified/self-signed certificates and weak ciphers enable MITM and interception, so assess it like any weak-TLS endpoint.
- Both commonly carry MS-CHAPv2 inside the PPP layer, which is crackable from a captured handshake like PPTP; so even after the outer layer, the inner authentication is attackable.
- The inherited nature means these are rarely novel: attack the carrier (IPsec PSK or TLS), then the inner PPP credentials.