Re: (PM) Radius Secret

I don't work for Lucent RABU (livingston@iav.com)
Mon, 12 Apr 1999 04:26:17 -1000 (HST)

On Fri, 9 Apr 1999, Thomas C Kinnen wrote:

> I don't work for Lucent RABU wrote:
>
> > Never say never ;)
> >
> > use a sniffer on port 1645 or is it 1646 for stock LRABU? Unless you are
> > using the RFC port(s) or other... okay, so you can't see it _in/on_ the
> > PMx, but this is one method to find out what you set. Personally, I'd
> > rather just verify what is in the configuration for RADIUS and reset it on
> > the PMx... 8)
>
> That will not work. The secret is never sent on the wire. It's used on
> both ends to do the MD5 hash but not sent on the wire.

Ah! Can you tell I don't really do 'hacking' 8)

> However, I *THINK* (Been a long time) the old C version of pmbackup makes a
> binary file you can poke around with a hex editor in and try to find it. No
> guarantee though. I know the C version of the dump user program can get
> passwords in clear text from the user table.

Uhm, I know that PmConsole 3.5.1.4 doesn't clean up after itself and
leaves your passwords in one of the .tmp files it creates in your %tmp%.

Not sure if you do a config backup and hex that will show the PMx
secret...

--
Aloha from Paradise,

Sherwood Got Clue? If so: ISPF! The Forum for ISPs by ISPs, <http://www.ispf.com>

- To unsubscribe, email 'majordomo@livingston.com' with 'unsubscribe portmaster-users' in the body of the message. Searchable list archive: <URL:http://www.livingston.com/Tech/archive/>