当前位置:首页 > 报告详情

Blast-RADIUS:打破 RADIUS网络设备身份验证、授权和计费的事实标准协议.pdf

上传人: 竿*** 编号:981551 2025-11-29 38页 4.53MB

1、Blast-RADIUSBreaking Enterprise Network AuthenticationSharon Goldberg1,Miro Haller2,Nadia Heninger2,Mike Milano3,Dan Shumow4,Marc Stevens5,Adam Suhl21Cloudflare,2UC San Diego,3BastionZero,4Microsoft Research,5Centrum Wiskunde&InformaticaBlack Hat Europe 2024;December 12,2024What is RADIUS?Where is i

2、t used?XKCD from 8RADIUS:standard protocol for enterprise networkauthentication.RADIUS is everywhere:RADIUS is.supported by essentially every switch,router,access point,and VPN concentrator productsold in the past twenty-five years.(Alan DeKok 4)Used for backbone routers,non-cable ISP,IoT devices,id

3、entity providers(Okta,Duo),802.1X,enterprise WiFi,eduroam.Miro HallerBHEU 20241/22Blast-RADIUS on a Single SlideHow does RADIUS work?userRADIUS client(router)loginuser/pwRADIUS server(auth DB)Access-Requestuser/pwAccess-AcceptorAccess-Rejectaccess granted!Most RADIUS traffic is sent over UDP.Our pro

4、tocol vulnerability:MITM can change Access-Reject to Access-Accept.Impact:authenticate as any user;accelerate RADIUS/UDP deprecation.Mitigation:responsible disclosure with over 90 vendors(incl.Cisco,Microsoft,.).icons from 6Miro HallerBHEU 20242/22THE RADIUS PROTOCOLRADIUS Packet FormatsAccess-Reque

5、st=Request HeaderRequest NonceAttributes4 bytes16 random bytesUser-Name testPassword Mjg2NzU1zAccess-Accept=Accept HeaderResponse AuthenticatorAttributes4 bytes16 byte“MAC”Reply-Message Welcome test!Exec-Privilege 4Access-Reject=Reject HeaderResponse AuthenticatorAttributes4 bytes16 byte“MAC”Reply-M

6、essage Access deniedMiro HallerBHEU 20243/22Response AuthenticatorGoal:Prevent forgery of packets(e.g.,by MITM attacker).The Response Authenticator from packetResponse HeaderResponse AuthenticatorAttributesis computed asMD5(Response HeaderRequest NonceAttributesShared Secret).copied from responsecop

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
根据报告的内容,以下是全文关键点的简明概括: 1. **RADIUS协议**:RADIUS是用于企业网络认证的标准协议,广泛应用于各种网络设备。 2. **Blast-RADIUS攻击**:一种通过MD5碰撞攻击RADIUS认证的方法,允许攻击者伪造认证信息。 3. **攻击原理**:攻击者通过创建MD5碰撞,使得Access-Accept和Access-Reject产生相同的响应认证器,从而绕过认证。 4. **影响**:攻击影响PAP、CHAP、MS-CHAP等模式,可能影响包括云服务和电信网络在内的多个部署。 5. **缓解措施**:包括使用HMAC-MD5的Message-Authenticator属性和将所有RADIUS流量封装在(D)TLS隧道中。 6. **攻击成功案例**:攻击已成功针对FreeRADIUS、Okta、Cisco ASA等系统。 7. **长期解决方案**:正在标准化使用(D)TLS加密RADIUS流量。
"RADIUS安全漏洞,你了解多少?" "MD5碰撞攻击,RADIUS如何应对?" "Blast-RADIUS攻击,企业网络如何自保?"
客服
商务合作
小程序
服务号
折叠