Great Circle Associates Firewalls
(September 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: S/KEY Holes?
From: scs @ lokkur . dexter . mi . us (Steve Simmons)
Organization: Inland Sea
Date: 21 Sep 1996 11:06:03 -0400
To: firewalls @ GreatCircle . COM
Distribution: local
Newsgroups: local.firewalls
References: <199609210731 . AAA20049 @ miles . greatcircle . com>

Bill Husler <Bill @
 Husler .
 xo .
 com> writes:

>One thing that has been discussed recently, while not a "hole" in S/key, 
>is the possibility of using a "Race" attack. . .

This attack is defeated in the latest OPIE setup.  Details in the RFC,
coming soon to a NIC near you.  Basicly you use line-at-a-time telnet,
which ensures by the time they see the carriage return, it's too late.

S/Key (and OPIE) are vulnerable to `man in the middle' attacks.  This
requires the attacker to sit between the user and the host and intercept
all communication from user to host.  But most things are susceptible
to man in the middle attacks.  One of the wins with OPIE vs man in the
middle is that you lose only one session -- the password has not been
betrayed.

So I stand corrected on weaknesses in OPIE.
-- 
  "Yea, the heavens shall open and the NP-complete solution given forth.
ATT executives shall give birth to two-headed operating systems, and 
copyrights shall be expunged.  The voice of the GNU shall be heard, but
the faithless will be without transceivers."   -- me


References:
Indexed By Date Previous: Source Routing
From: "R. McMahon" <mcmr @ mailhost . net>
Next: Re: c4i-pro CIA Web Page Hacked
From: Anders Lagö <anders . lago @ mbox300 . swipnet . se>
Indexed By Thread Previous: Re: S/KEY Holes?
From: Bill Husler <Bill @ Husler . xo . com>
Next: Re: [NTSEC] RE: NT vs. UNIX white paper
From: Rey LeClerc/New York/ACMC <Rey_LeClerc @ ACML . COM>

Google
 
Search Internet Search www.greatcircle.com