Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Kerberos 4 Valid Username and Realm Disclosure Vulnerability

Kerberos is an authentication system that allows exchange of credentials across an untrusted network in a secure manner. The Kerberos system allows administrators to control what services users can attempt to use through the use of ticket granting tickets.

With a valid ticket granting ticket (tgt), an attacker can attempt to brute force authentication information with a dictionary attack. It is usually difficult, however, for 'external' attackers to obtain tgt's. The Kerberos realm name and a valid username need to be sent to the tgt server in order to obtain a tgt.

A vulnerability exists in Kerberos 4 that may allow attackers to obtain a valid username and realm name. This information can then be used to obtain a tgt.

With a legitimate TGT, an attacker may be able to obtain the users password.







 

Privacy Statement
Copyright 2009, SecurityFocus