Re: freeradius denial of service in authentication flow

Florian Weimer <[email protected]> Sat, 15 Feb 2014 21:14:39 +0100
Newsgroups gmane.os.freebsd.bugbusters
Message-ID <[email protected]>
* Alan DeKok:

>   That's an issue, but a rare one IMHO.  The user has to exist on the
> system.  So this isn't a remote DoS.

Could you elaborate on this assessment?  Is this because typical data
sources for SSHA passwords limit the length of the salt and thus the
length of the SSHA hash?

Florian
(Debian security team)
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-bugbusters
To unsubscribe, send any mail to "[email protected]"