
7/9/2024 · Sharon Goldberg, Miro Haller, Nadia Heninger, Michael Milano, Dan Shumow, Marc Stevens, Adam Suhl
What this post added
This post details a new 'Blast-RADIUS' attack that exploits MD5 collision vulnerabilities in RADIUS/UDP authentication modes (PAP, CHAP, MS-CHAP). The attack allows a Man-in-the-Middle to gain unauthorized administrative access to network devices by forging RADIUS responses. It highlights the protocol's reliance on outdated cryptography and proposes mitigations including using RADIUS over TLS/DTLS or disabling vulnerable authentication modes.