[787] in Info-AFS_Redistribution

home help back first fref pref prev next nref lref last post

Re: AFS version of COPS

daemon@ATHENA.MIT.EDU (Daniel Edward Lovinger)
Wed May 20 11:20:11 1992

Date: Wed, 20 May 1992 10:05:48 -0400 (EDT)
From: Daniel Edward Lovinger <dl2n+@andrew.cmu.edu>
To: Info-AFS@transarc.com, Lyle_Seaman@transarc.com
Cc: Jessica_Blackburn@alw.nih.gov
In-Reply-To: <Qe6XqGj0BwwbI0wxtz@transarc.com>

Lyle_Seaman@transarc.com writes:
> Daniel Edward Lovinger <dl2n+@andrew.cmu.edu> writes:
> >         This crack attack requires physical access to the kaserver
> > database (/usr/afs/db/kaserver.DB0), and as such cannot be used to
> > construct a remote attack mechanism. This is purely a sysadmin tool.
> 
> Of course, if somebody gets access to a kaserver backup tape...
> Not that the existence of Dan's tool changes anything, just a
> reminder to be careful with backup media.

	If someone gets access to the backup media, they have access
to the encrypted passwords - which is all they need to decrypt
tickets.  The kerberos crack just makes it easy for sysadmins to find
out who has bad passwords. If you don't have kaserver.DB0 locked down
securely, the game is quite over.

						dan

home help back first fref pref prev next nref lref last post