Wednesday, 23 April 2025

Blast-RADIUS: Breaking RADIUS, the de facto standard protocol for authentication, authorization...

RADIUS is used to support remote access for diverse use cases including network routers, industrial control systems, VPNs, enterprise Wi-Fi including the Eduroam network, Linux Pluggable Authentication Modules, and mobile roaming and Wi-Fi offload. This talk presents the Blast-RADIUS vulnerability which allows a man-in-the-middle attacker to authenticate themselves to a device using RADIUS. Many of the above-mentioned applications still run RADIUS over UDP within an enterprise network (and in some cases even over the public Internet), and are hence affected by this vulnerability. Only deployments using the EAP authentication method or the not-yet-standardized RADIUS over TLS are unaffected.... By: Miro Haller Full Abstract and Presentation Materials: https://ift.tt/1axKtvL

source https://www.youtube.com/watch?v=dagyATfzRFo

No comments:

Post a Comment