PDA

View Full Version : Security Pros Warn Of Critical Flaws In Kerberos


KingFish
2 Sep 2004, 2:36am
Vulnerabilities in a technology widely used for network authentication have left computers running Unix, Linux and Apple Computer's Mac OS X potentially open to attack.

The flaws could allow an online intruder to gain access to computers running a security feature known as Kerberos. The vulnerabilities, found by the developers at the Kerberos Team at the Massachusetts Institute of Technology, should be patched as soon as possible, Sam Hartman, engineering lead for the team, said Wednesday. "I would not expect this to lead to a worm," Hartman said. "Most sites will patch it because patching is easy to do. Whereas, if you do have a compromise, it is a lot of work to recover."
Source: c|net (http://news.com.com/Security+pros+warn+of+critical+flaws+in+Kerberos/2100-1002_3-5343325.html?tag=nefd.top)

primesuspect
2 Sep 2004, 3:24am
Funny how they don't mention that Windows 2000 and up use Kerberos as well.....

QCH
2 Sep 2004, 2:29pm
For all of our Telnet connections from Windows OS to UNIX, we use MIT's Kerberos Leash32 2.501... I'll be watching MIT for the fix!!!!