Skip to main content

A Team Of Security Researchers Has Found A Bug In The Kerberos Network Authentication Protocol

A bypass bug present in the Kerberos cryptographic authentication protocol for 21 years has now been fixed in patches from Microsoft, Samba, Fedora, FreeBSD, and Debian.
A team of security researchers has found a bug in the Kerberos network authentication
protocol. Called Orpheus’ Lyre, this flaw could be used by a man-in-the-middle attacker to steal credentials, and gain escalated privileges. The fixes for the affected platforms have been released in the form of patches.
Aerberos is a computer network authentication protocol that ensures a secure communication by allowing the nodes to prove their identity to each other securely. This is done on the basis of Tickets. Kerberos is based on symmetric key cryptography and needs a trusted third-party.
A team of researchers has found a bug in the Kerberos authentication protocol. They have named this vulnerability as Orpheus’ Lyre. For those who don’t know, Orpheus was a Greek mythological musician who controlled a three-headed hound, Cerberos, with his lyre’s music. Kerberos is itself named after Cerberos.

Kerberos vulnerability explained in brief

Coming back to the flaw, it affects operating systems from the likes of Apple, Microsoft, FreeBSD, Red Hat, and Debian. This 21-year-old bug has now been fixed in the patches released by the creators of different operating systems.
This bug affects three implementations of Kerberos. Through the open source Heimdal implementation of Kerberos V5, Samba and FreeBSD are affected. It should be noted that the MIT implementation of Kerberos remains unaffected.
In Kerberos protocol, there’s an abundance unauthenticated plaintext, something which has been called cryptographic sin by the researchers. As a result, portions of messages are neither encrypted nor integrity-protected. To make sure that the protocol remains secure despite the wealth of unauthenticated plaintext, extreme care has been taken to authenticate the said plaintext.
But, one instance, the Ticket issued in KDC responses, could allow one to use a specific unauthenticated plaintext instead of authenticated copy of same text. This flaw is mitigated by the proper use of the metadata in the KCD response’s encrypted portion. However, due to the bug, that metadata could be taken from the unauthenticated plaintext.
This bug, Orpheus’ Lyre, allows a man-in-the-middle attacker to remotely steal details and gain escalated privileges. The details regarding relevant CVEs and patches can be found in the security blog post.

Comments

Follow Us

WHAT'S HOT

How To Speed Up Windows Using ReadyBoost And USB Drive? Does It Still Work?

In Microsoft Windows, ReadyBoost is a software feature that speeds up the system by storing application files and data as cache in a USB drive. This is beneficial in case the system is running a slow hard drive. The ReadyBoost works with USB drives, SD cards, and CF cards. However, it may not be able to deliver considerable performance in the

How To Install Ubuntu MATE For The Raspberry Pi 2 and Raspberry Pi 3

Ubuntu MATE:  We have done what we can to optimise the build for the Raspberry Pi 2 and Raspberry Pi 3, you can comfortably use applications such as LibreOffice and Firefox. But the microSDHC I/O throughput is a bottleneck so  we  highly  recommend that you use a Class 6 or Class 10 microSDHC  card.  Ubuntu MATE 16.04 also fully supports the built-in Bluetooth and Wifi on

Which Is The Best Operating System For Gaming Among SteamOS , Ubuntu And Windows 10

Years ago, MS-DOS was the ‘go to’ operating system when you wanted to engage in prolonged gaming sessions but its complexity required that a better alternative should be provided to the masses that will also feature a unique interface for easy use. After years of

Windows Subsystem For Linux Is Beta No More, Gets “Full Support” In Windows 10 Fall Creators Update

As we told you earlier, WSL on Windows 10  moved out of beta  in August. It still carries the beta tag in Windows 10 Creators Update. Also, it won’t require people to enable developer