ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Kerberos allows attackers into corporate networks

Matthew Broersma ZDNet.co.uk

Published: 24 Oct 2002 15:43 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Kerberos has lost some of its bite, according to the US government, which on Wednesday warned of a critical flaw that could allow hackers to circumvent the secure networking system.

Kerberos was invented by MIT and is used by many large businesses as a way of keeping their networks secure. It uses strong encryption to verify the identity of any machine using a networked resource.

On Wednesday the Computer Incident Advisory Capability (CIAC) of the US government Department of Energy issued the warning, which originated at MIT. The flaw allows an attacker to gain unauthorised access to the key distribution centre (KDC), which authenticates users, effectively compromising the security of the entire network.

The problem lies with software in MIT Kerberos 5 called kadmind4 (Kerberos v4 compatibility administration daemon), which allows compatibility with older administrative clients. A buffer stack overflow allows an attacker to use a specially-formed request to gain access to the KDC with the privileges of a user running kadmind4. Since this is typically the "root" or highest-level user, the attacker would be able to run any code or make any changes to the KDC.

All releases of MIT Kerberos 5 are affected, including version 5-1.2.6. All Kerberos 4 implementations derived from MIT Kerberos 4 are also vulnerable, MIT said.

The CIAC's bulletin, with links to a patch, is available here.

MIT credited Johan Danielsson and Love Hornquist-Astrand for discovering the problem and providing the initial patch.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
41 out of 94 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Do you love SQL Server?Junior-level SQL server developer*Finance!

Do you love SQL Server? Are you currently working as a SQL Server developer seeking your career-break into the exciting and fast-paced world of ...

Love Sport? VB.Net / C#, ASP.Net Web / Mobile. Unique Opportunity 37k

Love Sport? Want to combine this with .Net development? Want to work with the top names in the sporting world? I am currently working with a unique ...

Do you love technology?? Are you a Linux/ Unix Administrator??

Do you love technology? Are you a Linux/ Unix Administrator? Are you looking for a job to make you get out of bed in the morning? SO do you want to ...

Sentry Posts Blog

Working@Home: Keeping Secure

National Work from Home Day has come and gone, with an estimated five million people skiving to enjoy the comforts of their home. However, even though employees sat comfortably, IT... More

Post a comment

Privacy International director launche...

Simon Davies, who has been involved with campaigning on privacy issues for a number of years, is launching a privacy consultancy firm called 80/20. Half of all profits will be donated... More

Post a comment

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation