Possible flaw in CISCO RADIUS authentication
anomit | May 30, 2007The wi-fi connection in our hostels is controlled and billed through a login and authentication procedure using RADIUS(Remote Authentication Dial In User Service) on the CISCO IOS. Recently I happened to notice something. Suppose I log out of my account but have a program that keeps me connected to the net like Google Talk or any P2P program. Now someone else on another machine can login with the same ID and there you go, two machines on the network authenticated with the same ID. No, I don’t lose my connection.
If any experts are reading this, is it a flaw in the IOS RADIUS itself or something is wrong with its implementation on our network?








