Note: if blocking ports to stop msblast.exe, do not block 4444 UDP

From: Jeffrey Altman (jaltman_at_COLUMBIA.EDU)
Date: 08/12/03

  • Next message: Brian S. Bergin: "Re: reports of DCOM worm on the loose...Report #4"
    Date:         Tue, 12 Aug 2003 15:45:52 -0400
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    Jeffrey Altman wrote:

    A reminder for those environments using Kerberos V authentication with
    the krb524 service daemon. Do not block port 4444 (UDP) on your network or
    you will prevent Kerberos clients from converting Kerberos V tickets to
    Kerberos IV tickets. The ability to convert to Kerberos IV tickets is a
    requirement for many services include Zephyr and AFS.

    Jeffrey Altman
    MIT Kerberos Development team

    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
    Are You "Certifiable"? Summer's Hottest Certification Just Got HOTTER!

    With a growth rate exceeding 110%, the TICSA security practitioner
    certification is one of the hottest IT credentials available. And now, for
    a limited time, you can save 33% off of the TICSA certification exam! To
    learn more about the TICSA certification, and to register as a TICSA
    candidate online, just go to

    http://www.trusecure.com/offer/s0100/

    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo


  • Next message: Brian S. Bergin: "Re: reports of DCOM worm on the loose...Report #4"

    Relevant Pages

    • Attacks on Kerberos V in a Windows 2000 Environment.
      ... Attacks on Kerberos V in a Windows 2000 Environment. ... Summer's Hottest Certification Just Got HOTTER! ... you can save 33% off of the TICSA certification exam! ...
      (NT-Bugtraq)
    • RE: Kerberos 5 certified under NIST 140-2.
      ... Kerberos 5 certified under NIST 140-2. ... Appendix A describes the documentation that is necessary. ... These practices are probably a bit out of date, ... certification. ...
      (comp.protocols.kerberos)
    • Re: Kerberos 5 certified under NIST 140-2.
      ... our Certification and Accreditation and use Kerberos 5, ... Appendix A describes the documentation that is necessary. ... These practices are probably a bit out of date, ...
      (comp.protocols.kerberos)
    • Re: Kerberos 5 certified under NIST 140-2.
      ... our Certification and Accreditation and use Kerberos 5, ... of open-source software the clearly has never been certified under ... FIPS 140-2 (well, okay, they don't use crypto modules which have ... but I do not believe any implementation of Kerberos ...
      (comp.protocols.kerberos)
    • Kerberos 5 certified under NIST 140-2.
      ... I work at the U.S. Census Bureau and would like to use Kerberos 5 as our ... network authentication protocol. ... our Certification and Accreditation and use Kerberos 5, ...
      (comp.protocols.kerberos)