150 likes | 343 Views
One Time Password. Onno W. Purbo Onno@indo.net.id. Referensi. Buku “Keamanan Jaringan Internet”, Elexmedia Komputindo. Login Normal. Red Hat Linux release 6.0 (Hedwig) Kernel 2.2.5-15 on an i486 tony login:. Problem. Password & userid plan text Rentan sniffer Solusi
E N D
One Time Password Onno W. Purbo Onno@indo.net.id
Referensi • Buku “Keamanan Jaringan Internet”, Elexmedia Komputindo
Login Normal Red Hat Linux release 6.0 (Hedwig) Kernel 2.2.5-15 on an i486 tony login:
Problem • Password & userid plan text • Rentan sniffer Solusi • Password hanya digunakan satu kali • Password berubah setiap kali
Penemu .. • Ide • Leslie Lamport • Software OTP – S/KEY 1991 • Phil Karn, KA9Q – Bellcore • Neil Haler • John Walden
Challenge Red Hat Linux release 6.0 (Hedwig) Kernel 2.2.5-15 on an 1486 tony login: Challenge:994 672jar Password:
Challenge dari Server • Iterasi • Seed
Kalkulator Pada Client • Seed • Iterasi • Frasa rahasia client
Responds .. • Tiap client / user akan memberikan kalkulasi responds yang beda karena frasa rahasianya berbeda.
Red Hat Linux release 6.0 (Hedwig) Kernel 2.2.5-15 on an i486 tony login: tony Challenge:994 672jar Password: Login incorrect login: tony Challenge:983 672jar Password: (turning echo on) Password:was leo cal amy tire of Last login:Sun Nov 21 23:03:19 from tony [tony @ tony tony]$
Instalasi OTP • Mendapatkan installer OTP untuk sistem • Mendapatkan kalkulator untuk client • Mengkompile dan melakukan instalasi komponen-komponen OTP • Melakukan inisialisasi user dengan kunci masing-masing • Meng-enable OTP
Inisialisasi OTP tony.cisitu.net > keyinit Adding wanda: Reminder you need the 6 english words from the skey command Enter sequence count from 1 to 9999: 1000 Enter new key [default nd12043]: heather S/key 1000 heather S/key access password: ORB HURD LENT CRAM MELD HOSE ID wanda s/key is 1000 heather ORB HURD LENT CRAM MELD HOSE
X Windows tony.cisitu.net login:tony Callenge:974 672jar Password: