Slashdot Mirror


Critical Kerberos Flaw Revealed

doi writes "ZD Net is carrying a story about '...a critical flaw that could allow hackers to circumvent the secure networking system...The problem lies with software in MIT Kerberos 5 called kadmind4 (Kerberos v4 compatibility administration daemon), which allows compatibility with older administrative clients. A buffer stack overflow allows an attacker to use a specially formed request to gain access to the KDC with the privileges of a user running kadmind4.' It affects all MIT-derived versions of Kerberos 4 and 5."

17 of 197 comments (clear)

  1. haha by ArchieBunker · · Score: -1, Offtopic

    Good thing I use a secure protocol like telnet. When was the last telnet remote r00t exploit?

    --
    Only the State obtains its revenue by coercion. - Murray Rothbard
  2. Important news for nerds... by Anonymous Coward · · Score: -1, Offtopic
    1. Re:Important news for nerds... by Anonymous Coward · · Score: -1, Offtopic

      That's obviously CowboyNeil's man boobs pasted on CmdrTaco.

  3. Is it Friday already? by Jucius+Maximus · · Score: -1, Offtopic

    My, time does fly!

    1. Re:Is it Friday already? by D+iz+a+n+k+Meister · · Score: -1, Offtopic

      I'ma get you high today. 'Cause it's Friday, you ain't got no job, and you ain't got shit to do!!

      --

      He painted a unicorn in outer space. I'm askin' ya, what's it breathin'?
  4. Like the time L0rd N1k0n and I haX0r3d the g1s0n by Anonymous Coward · · Score: -1, Offtopic

    I used teh intarnate!@@!@!@ FOR HACKIGN!@# !@!@

    LOLOLOLOL!!!

    -Zero Cool, alias Dade Murphy

  5. Dollar $ign$ are 1337 by Anonymous Coward · · Score: -1, Offtopic

    Keep up the good work with the funny and original text substitution. My colleagues and I had quite a chuckle at Micro$oft's (heh heh) expense.

    I don't give a RED FUCK about any of that.

  6. Re:Is this really pertinent? by Anonymous Coward · · Score: -1, Offtopic

    Dear Sir,

    Why don't you go to your beloved bugtraq and OpenBSD security list and never return?

  7. fixed, publicized by Anonymous Coward · · Score: -1, Offtopic


    Okay, so there's a root exploit in kerberos. SHocking, I'm sure. It's not like M$ Outlook doesn't have dozens of such exploits. It's been widely publicized, the patch is available...isn't this how security administration is supposed to work?

  8. Re:Guess I was wrong... by groove10 · · Score: 0, Offtopic

    What the hell was that about... Timecube? Anyone want to fill me in on this thing? I started to read it but it really hurt my eyes to see text that big.

    --
    MMORPG fan-boy? Prove your worth
  9. Re:Is this really pertinent? by tswinzig · · Score: 1, Offtopic
    --

    "And like that ... he's gone."
  10. Re:it is only MIT Specific � by Anonymous Coward · · Score: -1, Offtopic

    And I was going to smack you in metamod just because I can.

  11. Re:Question by Anonymous Coward · · Score: -1, Offtopic

    It's not that I'm lazy, it's that I just don't care.

    -Peter Gibbons

  12. Re:is this for real [OT] by CommanderTaco · · Score: 0, Offtopic

    well, it's a bit redundant...
    today is the (car (cdr life)) would be better, or maybe
    (define today (car (cdr life)))

  13. Re:Guess I was wrong... by einhverfr · · Score: 1, Offtopic

    YES AND THERE ARE 4 24 HOUR DAYS WITH EATH EARTH ROTATION!

    Hmmm.... Call me silly,. stupid, and evil, but.... Why 4? Why not soething more tangable like 24 (1 for each general time-zone, discounting exception), or better yet, how about an infinite number of great circles passing through the poles creating an infinte number of longitude lines... Wait-- that is critical to Astrology. It must be STUPID AND EVIL even though it is true mathematically.

    --

    LedgerSMB: Open source Accounting/ERP
  14. Re:What would really be appreciated by Anonymous Coward · · Score: -1, Offtopic

    I've got a 'head up' that would like to affect your hole.

  15. Re:Question by Anonymous Coward · · Score: -1, Offtopic

    fuckin hilarious man, fuckin hilarious!