Other Attacks
Since Kerberos only provides an authentication service, there are several security threats that a Kerberos installation will not protect against. The following attacks are not attacks directly against the Kerberos system itself, but are problems related to providing a secure, available authentication service in general. These techniques can be used to attack any authentication system, and Kerberos is no exception:
- Denial of service
A denial of service attack can be mounted against your organization’s KDCs by flooding them with authentication requests. The large numbers of requests arriving can slow down response times to legitimate requests, or even, in extreme cases, crash the machines on which your KDCs reside. Kerberos cannot protect against denial of service attacks and it is generally recommended that your network, including your Kerberos KDCs, be firewalled from the Internet to prevent this type of attack. Adding additional KDCs to your network for redundancy can also mitigate the effects of a DoS attack.
- The “insider”
Kerberos cannot protect against an internal authorized user who decides to misuse their privileges. For example, a rogue Kerberos administrator could modify or remove information from the Kerberos database.
- Social engineering and password exposure
Similarly, Kerberos cannot protect against individual users who divulge their passwords to attackers, either inadvertently or as a result of a social engineering attack. The use of Kerberos does not diminish ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access