PMVision 1.4 release notes (was Re: (PM) Radius Secret)

I don't work for Lucent RABU (livingston@iav.com)
Sat, 24 Apr 1999 15:31:49 -1000 (HST)

On Fri, 9 Apr 1999, Thomas C Kinnen wrote:

> I don't work for Lucent RABU wrote:
>
> > Never say never ;)
> >
> > use a sniffer on port 1645 or is it 1646 for stock LRABU? Unless you are
> > using the RFC port(s) or other... okay, so you can't see it _in/on_ the
> > PMx, but this is one method to find out what you set. Personally, I'd
> > rather just verify what is in the configuration for RADIUS and reset it on
> > the PMx... 8)
>
> That will not work. The secret is never sent on the wire. It's used on
> both ends to do the MD5 hash but not sent on the wire.
>
> However, I *THINK* (Been a long time) the old C version of pmbackup makes a
> binary file you can poke around with a hex editor in and try to find it. No
> guarantee though. I know the C version of the dump user program can get
> passwords in clear text from the user table.

Remember this thread ;)

While reading release notes for PMVision 1.4 I came across this:

As of PMVision 1.3 and ComOS 3.8.2 and later releases, RADIUS and
ChoiceNet secrets can be retrieved from the PortMaster. However, the
secrets are passed from the PortMaster to PMVision in clear text. They
are then encrypted when saved to the file.

Just FYI.

--
Aloha from Paradise,

Sherwood Got Clue? If so: ISPF! The Forum for ISPs by ISPs, <http://www.ispf.com>

- To unsubscribe, email 'majordomo@livingston.com' with 'unsubscribe portmaster-users' in the body of the message. Searchable list archive: <URL:http://www.livingston.com/Tech/archive/>