Received: from SOUTH-STATION-ANNEX.MIT.EDU by po7.MIT.EDU (5.61/4.7) id AA06209; Sat, 24 Feb 96 16:37:27 EST
Received: by MIT.EDU 
	id AA06922; Sat, 24 Feb 96 16:37:01 EST
Date: Sat, 24 Feb 96 16:37:01 EST
From: MAILER-DAEMON@MIT.EDU (Mail Delivery Subsystem)
Subject: Returned mail: Cannot send message for 3 days
Message-Id: <9602242137.AA06922@MIT.EDU>
To: <owner-kerberos@MIT.EDU>
To: hartmans@PO9.LOCAL
To: proven@PO7.LOCAL
To: tytso@PO9.LOCAL
To: basch@lehman.com
To: jis@E40-PO.LOCAL
To: tlyu@PO9.LOCAL

   ----- Transcript of session follows -----
421 sci.uma.es.tcp... Deferred: Address family not supported by protocol family
451 jcrey@sci.uma.es... Cannot send message for 3 days
jcrey@sci.uma.es... Cannot send message for 3 days

   ----- Unsent message follows -----
Received: from pad-thai.cam.ov.com by MIT.EDU with SMTP
	id AA22867; Wed, 21 Feb 96 16:32:57 EST
Received:  by pad-thai.cam.ov.com (8.6.12/)
	id <QAA15401@pad-thai.cam.ov.com>; Wed, 21 Feb 1996 16:37:04 -0500
Received: from GATEWAY by pad-thai.cam.ov.com with netnews
	for kerberos-wrapper@cam.ov.com (kerberos@mit.edu)
To: kerberos@MIT.EDU
Date: 21 Feb 1996 19:57:45 GMT
From: Ray Kaplan <ray@rayk.com>
Message-Id: <4gftfp$60o@stratus.skypoint.net>
Organization: SkyPoint Communications, Inc.
Sender: usenet@cam.ov.com
References: <4gd97f$gdi@srvr1.engin.umich.edu>, <4gdc46$9tn@narnia.cs.purdue.edu>, <312AA5FD.2E1A@dnai.com>
Subject: Re: Kerberos Weakness (COAST Findings)

Michael Sierchio <kudzu@dnai.com> wrote:
>Steve Lodin wrote:
>> 
>> There is information available on the Kerberos vulnerability incident at:
>
>I am not sure, but I believe that this is nothing new.  Steve Bellovin at
>AT&T had a paper a number of years ago on weaknesses in the Kerberos
>Authentication Suite.

Yep - for those who lost track of it (as I did), it can be found at:

ftp.research.att.com - /papers/kerblimit.usenix.ps (note, they apparently 
have no /pub directory)

For clarity, this is Steve Bellovin's 1991 USENIX paper pointing out 
weaknesses in the Version 5, Draft 3 spec for Kerberos at the time.  As time 
permits, I am picking my way thought the copious details to see if I can get 
some ideas about exactly what in the heck this V5 "theoretical vulnerability" 
might be.  So far, it looks like those who are serious about security 
protocols (some, but not all commercial Kerberos vendors included) have beat 
the heck out of the V5 spec since this 1991 Bellovin paper.

Hope *someone* will post *some* details *soon* so some of us can return to 
the normal din of the day-to-day ;)  Until then, Seems to be the same old 
story, eh?  Those that are serious about security leave few rocks unturned?


RayK 8)         Ray Kaplan
Security Services - P.O Box 23210 - Richfield, MN USA 55423
(612) 861-7198 - FAX (612) 861-3736 - www: http://www.rayk.com/rayk
ray@rayk.com - Not an expert, just a battered vet.


