Great Circle Associates Firewalls
(September 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: BoS: SecurID White Paper
From: Mike Neuman <mcn @ remise>
Date: Tue, 03 Sep 1996 23:36:07 -0600
To: Peiter Z <peiterz @ secnet . com>
Cc: firewalls @ greatcircle . com, bugtraq @ netspace . org, best-of-security @ suburbia . net
In-reply-to: peiterz's message of Wed, 04 Sep 1996 11:37:56 -0600. <199609041737 . LAA01403 @ silence . secnet . com>
Reply-to: mcn @ EnGarde . com

  I apologize for the cross post, but I believe this encompasses all of the
mailing lists to which the original announcement was sent.

>                 SecurID Vulnerabilities White-Paper
>  
> Due to increased recent interest that has been witnessed on the net
> about the SecurID token cards and potential vulnerabilities with their 
> use, we offer a white paper on some of the vulnerabilities that we believe 
> have been witnessed and/or speculated upon.

  I appreciate the conclusion of the paper which finally does proclaim that
SecureID (and other one time password tokens) are extremely vulnerable.
The vulnerabilities described seem to be overly esoteric, however.
Unmentioned is perhaps the most serious flaw in one-time password systems:
session hijacking atttacks.

  It's trivial for an intruder to monitor the network, waiting for a user
to legitimately authenticate themselves. Once authenticated, the intruder
can hijack that user's connection and assume his credentials. This type of
attack can even be automated. (If you believe hijacking is only a theoretical
attack, see http://www.engarde.com/software/ipwatcher . Versions of our
software have existed for about 4 years, and recently we've begun seeing some
public domain hijacking tools available).

  The author does mention the use of combination encrypted sessions and one 
time passwords, which seems to be the best solution at present.

-Mike
mcn @
 EnGarde .
 com



Indexed By Date Previous: Re: Dialin
From: Rabid Wombat <wombat @ mcfeely . bsfs . org>
Next: C2 Myths
From: Christopher Klaus <cklaus @ iss . net>
Indexed By Thread Previous: RE: Secure Access Firwall (Ascend)??
From: Bill Maples <Bill . Maples @ express-hr . com>
Next: C2 Myths
From: Christopher Klaus <cklaus @ iss . net>

Google
 
Search Internet Search www.greatcircle.com