Re: Can Kerberos be cracked??

Date: 11/01/01

Subject: Re: Can Kerberos be cracked??

One recent paper on cracking Kerberos is

"A Real-World Analysis of Kerberos Password
Security "
Thomas Wu, Computer Science Department
Stanford University

Wu manages to crack over 2,000 passwords from a
user population of 25,000 on the Stanford Kerberos
v4 network in a 2 week period. He notes that the pre-
authentication in Krb v5 strengthens the
authentication exchange somewhat, but the same
attack is possible; simply more time consuming.