From joda@pdc.kth.se Fri Aug 4 05:35:41 2000
Received: from fort-point-station.mit.edu (FORT-POINT-STATION.MIT.EDU [18.72.0.53])
by rt-11.mit.edu (8.9.3/8.9.3) with ESMTP id FAA15143
for <bugs@RT-11.MIT.EDU>; Fri, 4 Aug 2000 05:35:40 -0400 (EDT)
Received: from blubb.pdc.kth.se (blubb.pdc.kth.se [130.237.221.147])
by fort-point-station.mit.edu (8.9.2/8.9.2) with ESMTP id FAA25880
for <krb5-bugs@mit.edu>; Fri, 4 Aug 2000 05:35:39 -0400 (EDT)
Received: from joda by blubb.pdc.kth.se with local (Exim 3.13 #1)
id 13Kdru-0007EI-00; Fri, 04 Aug 2000 11:34:18 +0200
Message-Id: <xof66phcque.fsf@blubb.pdc.kth.se>
Date: 04 Aug 2000 11:34:17 +0200
From: joda@pdc.kth.se (Johan Danielsson)
To: Dug Song <dugsong@monkey.org>
Cc: heimdal-bugs@pdc.kth.se, krb5-bugs@mit.edu, security@microsoft.com,
support@transarc.com
In-Reply-To: Dug Song's message of "Fri, 4 Aug 2000 05:11:01 -0400 (EDT)"
Subject: Re: kdcspoof
References: <Pine.BSO.4.20.0008040445420.7307-100000@naughty.monkey.org>
State-Changed-From-To: open-closed
State-Changed-By: tlyu
State-Changed-When: Wed Feb 7 19:39:48 2001
State-Changed-Why:
replies should go to PR #871
No, but there are situation where you can't protect yourself, for
instance if you don't have a keytab you can use. One example of an
application that I know (might) have this problem is xdm, if it
doesn't run as root.
/Johan
Received: from fort-point-station.mit.edu (FORT-POINT-STATION.MIT.EDU [18.72.0.53])
by rt-11.mit.edu (8.9.3/8.9.3) with ESMTP id FAA15143
for <bugs@RT-11.MIT.EDU>; Fri, 4 Aug 2000 05:35:40 -0400 (EDT)
Received: from blubb.pdc.kth.se (blubb.pdc.kth.se [130.237.221.147])
by fort-point-station.mit.edu (8.9.2/8.9.2) with ESMTP id FAA25880
for <krb5-bugs@mit.edu>; Fri, 4 Aug 2000 05:35:39 -0400 (EDT)
Received: from joda by blubb.pdc.kth.se with local (Exim 3.13 #1)
id 13Kdru-0007EI-00; Fri, 04 Aug 2000 11:34:18 +0200
Message-Id: <xof66phcque.fsf@blubb.pdc.kth.se>
Date: 04 Aug 2000 11:34:17 +0200
From: joda@pdc.kth.se (Johan Danielsson)
To: Dug Song <dugsong@monkey.org>
Cc: heimdal-bugs@pdc.kth.se, krb5-bugs@mit.edu, security@microsoft.com,
support@transarc.com
In-Reply-To: Dug Song's message of "Fri, 4 Aug 2000 05:11:01 -0400 (EDT)"
Subject: Re: kdcspoof
References: <Pine.BSO.4.20.0008040445420.7307-100000@naughty.monkey.org>
Show quoted text
>Number: 872
>Category: pending
>Synopsis: Re: kdcspoof
>Confidential: yes
>Severity: serious
>Priority: medium
>Responsible: gnats-admin
>State: closed
>Class: sw-bug
>Submitter-Id: unknown
>Arrival-Date: Fri Aug 4 05:36:00 EDT 2000
>Last-Modified: Wed Feb 7 19:40:39 EST 2001
>Originator:
>Organization:
>Release:
>Environment:
>Description:
>How-To-Repeat:
>Fix:
>Audit-Trail:
>Category: pending
>Synopsis: Re: kdcspoof
>Confidential: yes
>Severity: serious
>Priority: medium
>Responsible: gnats-admin
>State: closed
>Class: sw-bug
>Submitter-Id: unknown
>Arrival-Date: Fri Aug 4 05:36:00 EDT 2000
>Last-Modified: Wed Feb 7 19:40:39 EST 2001
>Originator:
>Organization:
>Release:
>Environment:
>Description:
>How-To-Repeat:
>Fix:
>Audit-Trail:
State-Changed-From-To: open-closed
State-Changed-By: tlyu
State-Changed-When: Wed Feb 7 19:39:48 2001
State-Changed-Why:
replies should go to PR #871
Show quoted text
>Unformatted:
Dug Song <dugsong@monkey.org> writes:Show quoted text
> you guys aren't vulnerable to this, right?
No, but there are situation where you can't protect yourself, for
instance if you don't have a keytab you can use. One example of an
application that I know (might) have this problem is xdm, if it
doesn't run as root.
/Johan