Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

IETF RADIUS Dictionary Attack Vulnerability

The RADIUS Authentication protocol is a standard used for remote authentication of users. It is commonly used by ISPs to authenticate dial up users, although it has wider applications. Communication with a RADIUS server is mediated in part by a shared secret used as part of a MD5 hash.

A design flaw in the RADIUS specification allows an attacker with access to network traffic to intercept an MD5 hash containing only the shared secret and known data. This allows a brute force dictionary attack to be launched against the shared secret.







 

Privacy Statement
Copyright 2008, SecurityFocus