[2338] in Kerberos
Re: Local password validation (was: kerberizing xlock)
daemon@ATHENA.MIT.EDU (smb@ulysses.att.com)
Thu Nov 5 03:26:48 1992
From: smb@ulysses.att.com
To: Greg Wohletz <greg@duke.cs.unlv.edu>
Cc: Barry Jaspan <bjaspan@Athena.MIT.EDU>, hendrick@neptune.ctron.com,
Date: Thu, 05 Nov 92 03:08:49 EST
OK, now I see what your getting at, and I agree that it is
theoretically possible to accomlish this. I think that V could be
designed and located on the network in such a way as to make this
attact extremely difficult, if not impossible
Anyone who thinks that active spoofing of a server is impossible or
even prohibitively difficult should read ``A Unix Network Protocol
Security Study: Network Information Service'', by Hess, Safford, and
Pooch, in the October '92 (vol 22, no 5) issue of Computer
Communications Review.
--Steve Bellovin