Anger implements a PPTP challenge/response sniffer. These challenge/response packets can be entered into L0phtcrack to obtain the original password. The program is also able to perform an active attack on the PPTP logon protocol (via the MS-CHAP vulnerability) to obtain the users' password hashes.
Notice that these password hashes can be also provided into a modified smbclient to logon onto a SMB sever, or into a modified PPP client for use with the Linux PPTP client.