<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco Secure ACS Compromised? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-secure-acs-compromised/m-p/403127#M429206</link>
    <description>&lt;P&gt;Is anyone aware of any instances where Cisco Secure has been compromised to reveal TACACS+ user IDs/passwords?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This question stems from the issue of whether ACS servers should be added to an existing Windows domain or to a totally seperate domain of their own.  If the existing domain is compromised so that someone now has Domain Admin rights on the ACS servers (but not an ACS admin ID), could this lead to them somehow cracking TACACS+ passwords or creating their own ID?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are there any Proof-Of-Concepts out there?&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 21:08:10 GMT</pubDate>
    <dc:creator>6aganguly</dc:creator>
    <dc:date>2019-03-10T21:08:10Z</dc:date>
    <item>
      <title>Cisco Secure ACS Compromised?</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-secure-acs-compromised/m-p/403127#M429206</link>
      <description>&lt;P&gt;Is anyone aware of any instances where Cisco Secure has been compromised to reveal TACACS+ user IDs/passwords?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This question stems from the issue of whether ACS servers should be added to an existing Windows domain or to a totally seperate domain of their own.  If the existing domain is compromised so that someone now has Domain Admin rights on the ACS servers (but not an ACS admin ID), could this lead to them somehow cracking TACACS+ passwords or creating their own ID?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are there any Proof-Of-Concepts out there?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:08:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-secure-acs-compromised/m-p/403127#M429206</guid>
      <dc:creator>6aganguly</dc:creator>
      <dc:date>2019-03-10T21:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure ACS Compromised?</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-secure-acs-compromised/m-p/403128#M429209</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ACS server can be told to authenticate against the domain that it is a member of and any domains that are trusted by that domain. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 May 2005 14:06:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-secure-acs-compromised/m-p/403128#M429209</guid>
      <dc:creator>didyap</dc:creator>
      <dc:date>2005-05-06T14:06:20Z</dc:date>
    </item>
  </channel>
</rss>

