R E L A T E D   C O N T E N T
ADVERTISEMENT

Unix red alert as Kerberos flaws are brought to light

Using the controversial security protocol Kerberos exposes network systems to attacks by hackers, a security analyst has warned.

James Middleton, Network News, Network IT Week 29 Jun 2000
ADVERTISEMENT

Using the controversial security protocol Kerberos exposes network systems to attacks by hackers, a security analyst has warned.

Researcher NTA Monitor found that current versions of Kerberos released by key developer MIT contain several high-risk security vulnerabilities.

Kerberos is widely used for secure user identification on Unix platforms.

The protocol is an open security standard for strongly encrypted user authentication. It secures passwords sent over a network by encrypting them both on and off the server.

NTA Monitor analyst Deri Jones said server components in versions four and five of Kerberos contain flaws, which potentially allow attackers to gain root access to Kerberos servers and execute shell commands. Other vulnerabilities include buffer overflow flaws and Denial of Service attacks.

Jones said that because MIT are the key developers of the protocol, "its implementation would be widespread across security products such as firewalls and VPNs." He said that if intruders are able to access dedicated Kerberos servers, it would be very embarrassing for companies" because the technology works on a client server model.

MIT has said that it plans to release a patch addressing the flaws, which will bring the version up to 5.12. Vendors who incorporate MIT's version of Kerberos into their software are also developing patches for their websites.

Jones said that MIT's patch would be the most crucial because other vendors will base theirs upon it "and are typically one or two versions behind the current anyway," he said.

Microsoft recently developed an implementation for Windows 2000, which fuelled other developers' anger because it contained modified code that Microsoft did not release to the public, theoretically breaching open source guidelines.

See also:

Analysts question software giant's motives  02 Oct 2001
While most businesses these days rely on firewalls to offer protection from external attacks on a network, the increasing availability of distributed firewalls promises to provide companies with the additional benefits of an internal security mechanism.  25 Jul 2000

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Java, J2EE, Developer, Spring, Hibernate, London, city, Graduate. This is an amazing opportunity to join a successful city based team working at the cutting edge of development. My client is looking for strong Java/J2EE developers ... more >
| Aston Carter
E-Commerce, Greenfield, Agile, Java, J2EE, , JavaScript, SQL, London, City Graduate This is an exceptional opportunity for a talented Java, J2EE developer keen to work in a successful development team within arguable the best agile ... more >
| Rullion Computer Personnel Ltd
2nd Line Support Analyst London £35, 000 to £40, 500 My client is a global market leader in the Internet Applications Industry. The company is continually progressing and looking for areas of growth and this ... more >
| Rullion Computer Personnel Ltd
Security Architect / Information Security Specialist – St Albans - Global Leader - Shine At The Highest Level Security Solution Architect / Information Security Architect required by renowned blue-chip organisation offering the finest security projects ... more >
More job opportunities