ZeroHour
Schneier on Securitypublished ()ingested Bruce Schneier

RADIUS Vulnerability

mediumVulnerabilityimportance 30
Full article119 words · extracted from schneier.com · click to collapse

New attack against the RADIUS authentication protocol:

The Blast-RADIUS attack allows a man-in-the-middle attacker between the RADIUS client and server to forge a valid protocol accept message in response to a failed authentication request. This forgery could give the attacker access to network devices and services without the attacker guessing or brute forcing passwords or shared secrets. The attacker does not learn user credentials.

This is one of those vulnerabilities that comes with a cool name, its own website, and a logo.

News article. Research paper.

Tags: academic papers, authentication, man-in-the-middle attacks, protocols, vulnerabilities

Posted on July 10, 2024 at 10:42 AM6 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2024/07/radius-vulnerability.html