[15150] in bugtraq

home help back first fref pref prev next nref lref last post

Re: An Analysis of the TACACS+ Protocol and its Implementations

daemon@ATHENA.MIT.EDU (Juan M. Courcoul)
Thu Jun 1 21:24:41 2000

Mime-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Message-Id:  <Pine.GSO.4.21.0006010936520.5439-100000@campus>
Date:         Thu, 1 Jun 2000 09:41:16 -0500
Reply-To: "Juan M. Courcoul" <courcoul@CAMPUS.QRO.ITESM.MX>
From: "Juan M. Courcoul" <courcoul@CAMPUS.QRO.ITESM.MX>
X-To:         BUGTRAQ@SECURITYFOCUS.COM
To: BUGTRAQ@SECURITYFOCUS.COM
In-Reply-To:  <200005301059.OAA05030@false.com>

On Tue, 30 May 2000, Solar Designer wrote:

> OW-001-tac_plus, revision 1
> May 30, 2000
>
>  An Analysis of the TACACS+ Protocol and its Implementations
>  -----------------------------------------------------------
...

First off, many thanks to Solar Designer for this insightful TACACS+
analysis.

For those of us who have opted to use RADIUS instead of TACACS, is there
an equivalent vulnerability analysis available somewhere ?

Thanks,

J. Courcoul                               courcoul@campus.qro.itesm.mx
Servicios Computacionales                 Directo    (4) 238-3181
ITESM Campus Queretaro                    Secretaria (4) 238-3175
Queretaro, Qro. Mexico                    Sky (800) 723-4500 PIN 5597110

home help back first fref pref prev next nref lref last post