RE: Security Problem

Franco Nogarin ( webmaster@auroranet.nt.ca )
Thu, 24 Apr 1997 13:12:18 -0600

------ =_NextPart_000_01BC50B1.239F30C0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

No, I have concurrency on and only one user may use an SA at a time, I =
have radius 1.16.xx but I will get 1.19.00 and set it up, could you =
direct me to whatever I need to learn this procedure? readme? =
changes.txt? a web page?

Thnaks to all who replied on this....
FN

-----Original Message-----
From: Dale E. Reed Jr. [SMTP:daler@iea.com]
Sent: Thursday, April 24, 1997 12:27 PM
To: emerald@emerald.iea.com
Subject: Re: Security Problem

Franco Nogarin wrote:
>=20
> Hi, I have a big problem.
>=20
> 1. It is well known in our area that we are "Easy to steal Internet =
From". I was rather shocked when I heard this, after several hours of =
pouring through logs and spot checks on modems, I have discovered only =
one thing which may or may not be the cause.
>=20
> We have 10 modems on our portmaster2e, 8 for public dialup on a hunt =
and peck with a base number of 872-5508, we also have one staff modem on =
a seperate line of 872-4437, and last but not least my administration =
modem on 872-5508 an unlisted private line.
>=20
> Some callers are starting to use this line, how this is I dont know, =
but I need a way to limit the admin modem on the portmaster to only =
accept calls from two or three SAs. This will solve my modem problem.

RadiusNT 1.19.00 has the sever port access control that will solve this.
=20
> As to the security issue, is anyone aware of a way to hack into =
radius/emerald, or of a bad configuration that will allow free access???

They could be talking about concurrency control. LIke buying one
account
and having several people use it.

--=20
Dale E. Reed Jr. (daler@iea.com)
_________________________________________________________________
IEA Software, Inc. | RadiusNT, Emerald, and NT FAQs
Internet Solutions for Today | http://www.emerald.iea.com

----------------------------------------------------------
Emerald Mailing List listserver@emerald.iea.com

------ =_NextPart_000_01BC50B1.239F30C0
Content-Type: application/ms-tnef
Content-Transfer-Encoding: base64

eJ8+IhMTAQaQCAAEAAAAAAABAAEAAQeQBgAIAAAA5AQAAAAAAADoAAEIgAcAGAAAAElQTS5NaWNy
b3NvZnQgTWFpbC5Ob3RlADEIAQ2ABAACAAAAAgACAAEEkAYAwAEAAAEAAAAQAAAAAwAAMAIAAAAL
AA8OAAAAAAIB/w8BAAAATQAAAAAAAACBKx+kvqMQGZ1uAN0BD1QCAAAAAGVtZXJhbGRAZW1lcmFs
ZC5pZWEuY29tAFNNVFAAZW1lcmFsZEBlbWVyYWxkLmllYS5jb20AAAAAHgACMAEAAAAFAAAAU01U
UAAAAAAeAAMwAQAAABgAAABlbWVyYWxkQGVtZXJhbGQuaWVhLmNvbQADABUMAQAAAAMA/g8GAAAA
HgABMAEAAAAaAAAAJ2VtZXJhbGRAZW1lcmFsZC5pZWEuY29tJwAAAAIBCzABAAAAHQAAAFNNVFA6
RU1FUkFMREBFTUVSQUxELklFQS5DT00AAAAAAwAAOQAAAAALAEA6AQAAAB4A9l8BAAAAGAAAAGVt
ZXJhbGRAZW1lcmFsZC5pZWEuY29tAAIB918BAAAATQAAAAAAAACBKx+kvqMQGZ1uAN0BD1QCAAAA
AGVtZXJhbGRAZW1lcmFsZC5pZWEuY29tAFNNVFAAZW1lcmFsZEBlbWVyYWxkLmllYS5jb20AAAAA
AwD9XwEAAAADAP9fAAAAAAIB9g8BAAAABAAAAAAAAALpXwEEgAEAFQAAAFJFOiBTZWN1cml0eSBQ
cm9ibGVtADoHAQWAAwAOAAAAzQcEABgADQAMABIABAAfAQEggAMADgAAAM0HBAAYAA0ACAA5AAQA
QgEBCYABACEAAAAwNkZGMEI5NURBQkJEMDExODgxMjAwQTAyNDc3MEQ2QQAUBwEDkAYABAkAACEA
AAALAAIAAQAAAAsAIwAAAAAAAwAmAAAAAAALACkAAAAAAAMALgAAAAAAAwA2AAAAAABAADkAQDZw
beNQvAEeAHAAAQAAABUAAABSRTogU2VjdXJpdHkgUHJvYmxlbQAAAAACAXEAAQAAABYAAAABvFDj
bWeVC/8Hu9oR0IgSAKAkdw1qAAAeAB4MAQAAAAUAAABTTVRQAAAAAB4AHwwBAAAAGgAAAHdlYm1h
c3RlckBhdXJvcmFuZXQubnQuY2EAAAADAAYQEYePlwMABxCUBQAAHgAIEAEAAABlAAAATk8sSUhB
VkVDT05DVVJSRU5DWU9OQU5ET05MWU9ORVVTRVJNQVlVU0VBTlNBQVRBVElNRSxJSEFWRVJBRElV
UzExNlhYQlVUSVdJTExHRVQxMTkwMEFORFNFVElUVVAsQ09VTAAAAAACAQkQAQAAAOMFAADfBQAA
cAkAAExaRnXodoP4dwAKAQMB9yACpAPjAgBjgmgKwHNldDAgBxOHAoMAUA72cHJxMg/2Jn0KgAjI
IDsJbzI1ZjUCgAqBdWMAUAsDYwMAQQtgbmcxMDMzgwumB7BvLCBJIA+AyHZlIAWgbmMIcAlwqRcw
eSACICAAcGQXwfZsF7IW8HUPsAXAAMAXsDcY0RfxBgBBF/AFQGEghnQHcRaHcmFkaRjQACAxLjE2
Lnh4uCBidQVAFqAD8GwDIMZnD8AbgjkuMA/gGALJD7EgaQVAdXAWgAWg1HVsGCB5CGAgG0AJcG5j
BUAHgBpAbxxgD4B0fmUW4AXAFqAYoAmAH6JspmUKwAOgdGgEACARQMxvYwmACHBlPxsQISC+ZAeA
IlAPcRVwB5AuDNBGdCJQGjB3ZWIhsGEdHMA/CqIKhAqAVGhu/GFrBCAfsQdAAyAf4B/A3wlwC1AI
kBgiIWMuJ0EkdJxGTiR6CvQmgDM2AUB/FRABQCHBIBAfUBCEG7Ag6i0qwk8FEGcLgAdABdD9B5Bz
JDEqwyR2KdQpoQsTwSnWaS0xNDQBQCaAvDE4HVAMwS5jJABGA2FqOgyDYg/gRAdAFvBFJi4H8CCi
SnIw4FtTIE1UUDpkMJFyQMkIkGEuBaBtXSR1JABfBmACMC/3JTAIcHMx8HnNFoBBEUADETI0FoAd
IEQ5NxuAMjoyNaBQ0k0y11RvL/dlB4AbIDUeoEA3hS4yVTLYdWLuah9BL/cxADoGURdBHgD9F7BQ
A2ACYDeALG8teikkvwu2J5QbIBcwH8AWYGcKwN8LgBxgKdIv8CSDPgrjQFLsSGkWhxowYiswIbI7
gv8ndUB4G5AWkB3hBCAj4ByR8Gtub3cDoD+BCGEX8B8icSFhGgEj4EVCICJFbGFzF7AfsXMgECtx
Se8CMASRHNEvsiJDsRxgRoCXGxEhcBjxcyYgY2sgsX8f4AnwFpIhISDBIYEWgGF/AYBI8iAiK3Em
IDRRF8BmHyGwCGIVcCFhA2B1Z2j/IQA/QAQgHYNMQAVAD3AFkPclcRfRBGJtSqEWpRtABPB+byAx
JqMYZSFxTJEf4Gm/D3AZEwWxGSJEkAVAYlDS7RbxYRjRQp9XFvAWwxWQf061F8JFEkxAACAAwEbx
cvIyGoE4IAIQVeE5kCaAvmMfAQdAHjAXwxawdQIw/RfzcE5BHGEhcEGyRoAW8FxudQbQGPFMETgB
wC2ZFBAwOBaARfJscx/A/xbDGJJG8ErQTCBOw1gUD7B/WQBIsRbwJoAYoVqFLnAz/jdKsRgRC2BG
8BwDUmIhEb1fgW0XsCKRC4AEAHRIsf5pTpYXwlq2GZJYgCaARvHbWOEFEHZdxlNvUwNwUvL/HJAE
kE1xRjFcYQAgTIMfwP8ZYiFzXgIWgCYgB+AhcyGR/RagZAIhRHMWgBwUIJMjwf8ZMSDiB3AeAVLS
YMNcuFLS/1YIH6IYQwDQIfAFMWWyBCD7A1IaQHdtgW1RTNAJ4BnB3yNQNCFEAhyCW6BsFuFgkZdc
xEIsJHRSGzNOVBz3/w+AJYFS4UszVfNt4wQRFxH/YTAG8EWVcJgnAyR0QIdv8P8fonRUOuUEAQpQ
FoAhkQBw+x7QGKFhSHBGMUwRamcPgO9ZIQuAH7EbJC83hRaABbHfexNZwBggFxEuMGcIcGFUv3Y4
JdFoMQNQb7F1RD+AwL0kfGUXsB50UqIHQGtMgj8BoAhgTgEXKXW1MOAgTPZJSWAcAXlMghiRJHRt
8f8IYAIwhcUYERbBTIJLNlkA/m8LUBizHfFyOyrAQIUwj9QgKDH7KSR0X4zPjd/Pju+Py3eFkTRJ
RRngZWC/AYB6whaBFzCEoZEyfISwO3MGFoBFfPYYAnNhRkH+UQ9Ad5RHV2VgCkBhYm6h/wWxNtA0
gZMDhLAVAx6QFrBBAkBwOi8vd5jALv84DimCHpA+VXeFKsObj5yff52vLEaT5gXQC3BeAUIATP9h
EZE1kTNjIhjhIDE3/ySJBRIBAKPwAAMAEBAAAAAAAwAREAAAAAADAIAQ/////0AABzCgn6b14lC8
AUAACDCgn6b14lC8AQsAAIAIIAYAAAAAAMAAAAAAAABGAAAAAAOFAAAAAAAAAwACgAggBgAAAAAA
wAAAAAAAAEYAAAAAEIUAAAAAAAADAAWACCAGAAAAAADAAAAAAAAARgAAAABShQAAtw0AAB4AJYAI
IAYAAAAAAMAAAAAAAABGAAAAAFSFAAABAAAABAAAADguMAADACaACCAGAAAAAADAAAAAAAAARgAA
AAABhQAAAAAAAAsAL4AIIAYAAAAAAMAAAAAAAABGAAAAAA6FAAAAAAAAAwAwgAggBgAAAAAAwAAA
AAAAAEYAAAAAEYUAAAAAAAADADKACCAGAAAAAADAAAAAAAAARgAAAAAYhQAAAAAAAB4AQYAIIAYA
AAAAAMAAAAAAAABGAAAAADaFAAABAAAAAQAAAAAAAAAeAEKACCAGAAAAAADAAAAAAAAARgAAAAA3
hQAAAQAAAAEAAAAAAAAAHgBDgAggBgAAAAAAwAAAAAAAAEYAAAAAOIUAAAEAAAABAAAAAAAAAB4A
PQABAAAABQAAAFJFOiAAAAAAAwANNP03AAAJfg==

------ =_NextPart_000_01BC50B1.239F30C0--