Home » GreenRocket Security Blog
GreenRocket Security Blog
GreenRocket Security Blog
The Latest
Green Rocket Security has added RadSec to the supported protocols. RadSec is a secure extension of RADIUS that uses TCP and TLS to encrypt all RADIUS communications, providing stronger protection over untrusted networks.
Overview of RADIUS
RADIUS is a widely used protocol for authentication, authorization, and accounting (AAA) in networks. It primarily operates over UDP, transmitting attribute-value pairs (AVPs) to verify user credentials and authorize network access.
Overview of RadSec
RadSec (RADIUS over TLS) is an enhancement of RADIUS designed to secure communications over untrusted networks. It uses TCP for reliable transport and TLS for encryption, ensuring that all RADIUS messages carried over the TLS connection—including authentication requests, accounting messages, and control messages—are fully encrypted. RadSec employs mutual TLS authentication, where both client and server verify each other’s certificates, help to prevent man-in-the-middle attacks and protect privacy. It is particularly useful in roaming environments where RADIUS traffic traverses multiple administrative domains or the public internet.
Key Differences
| Feature | RADIUS | RadSec |
| Transport Protocol | UDP | TCP |
| Encryption | MD5-based shared secret | TLS (full encryption of all data in the communication) |
| Security | Shared-secret-based protection, with message integrity verification when Message-Authenticator is enforced | Strong protection against privacy and security breaches |
| Use Case | Trusted internal networks | Untrusted networks, roaming |
| Performance | Fast, lightweight traffic | Higher overhead due to TCP and TLS |
| Complexity | Simple to deploy | Requires TLS certificate management and additional setup |
When to Use Each
RADIUS is suitable for internal networks with appropriate network security controls and where compatibility with legacy devices is important.
RadSec is recommended when RADIUS traffic must traverse untrusted networks, such as public internet, cloud environments, or roaming scenarios, due to its robust encryption and privacy protection.
Even if using EAP-TLS or EAP-TTLS, which encrypts client-server communication, RadSec adds an extra layer by encrypting the entire RADIUS channel, including all control and accounting messages.
Summary:
GreenRADIUS adding the RadSec protocol enhances the security of the transport layer, making it the preferred choice for modern, distributed, or high-security network environments, while GreenRADIUS classic RADIUS remains available and is a simpler option for trusted, internal deployments.
Over 30 water systems in Minnesota were targeted by a series of cyberattacks this past July. These water systems and operations were compromised, temporarily leaving some cities with a limited
We have released a new Windows Logon MFA agent version (v2.9.21-N). If your GreenRADIUS license enables the U2F Module (used for Windows Logon MFA), and you have not received the
The Belgian hospital AZ Monica was hit with a cyberattack in January, followed by a major disruption to all operations. The hospital warned patients that it was running on limited
Authentication
Thousands of school districts in the US use the software system, Power School, as a tool to manage student and teacher information. Over 60 million students have data stored with this software. This past December the system was hacked causing disruption for many school districts across the country.
Using stolen credentials a hacker or group was able to access large amounts of personal information through the customer support portal.
At least two anonymous school districts have confirmed that even historical data has been stolen from former students, as well as current.
TechCrunch states that, “PowerSchool have told TechCrunch that hackers accessed ‘all’ of their historical student and teacher data.” From some commentary by RootED’s executive chief, the article continues that, “some school districts are reporting the number of affected students in the range of four- to 10-times higher than the number of actively enrolled students in their district.”
Another source claimed that data has been stolen even prior to December. On top of this, it has been found that school districts which only formerly used PowerSchool have also been affected by this breach.
Some accusations claim that PowerSchool failed to implement basic software protection, such as multi-factor authentication. When TechCrunch reached out to a PowerSchool spokesperson, she answered that their software did have MFA but did not make any further comment.
The scale of this data breach remains unknown, although multiple school districts have disclosed their effects, and more continue to do so as well.
To prevent such disaster, secure the data under your charge with multi-factor authentication. Contact us to find out how GreenRADIUS can provide this safety for your customers and your team.
A large-scale cyber-attack was confirmed earlier this week that includes breaches into United States federal government agencies. On Monday, SolarWinds confirmed that Orion – its flagship network management software – had served as the unwitting...
Weak passwords and cross-site password reuse are two of the most common ways to break into a WordPress installation. Fortunately, WordPress plugins are able to augment the system’s default authentication. Our GreenRADIUS WordPress Authentication Plugin...
General
At Green Rocket Security, we’re constantly striving to improve our product to meet and exceed users’ expectations. Here are some highlights from 2025’s product developments:
- The LDAP Authenticator Module has been enhanced to support a wider variety of integrations, such as SolarWinds
- RADIUS settings for token types, group membership, VSAs, and group prioritization are now at the RADIUS client level rather than the domain level
- RADIUS ports can be used to enforce different Multi-Factor policies (password + token, password + PIN + token, PIN + token, token only) and different token types (YubiKeys, Authenticator app tokens, etc.)
- Added support for ECC certificates
- GreenRADIUS now provides broader support for OATH tokens (HOTP and TOTP) from any manufacturer by eliminating manufacturer-specific constraints
- GreenRADIUS now supports IPv6
Thank you to all our customers and partners. We look forward to further improvements in 2026!
Checking the National Day Calendar today, I see that it is World Password Day. I found it interesting that the primary website dedicated to this seems not to have been updated since last year (maybe...
I’m sure you’ve heard about the numerous cyber attacks on big businesses like Target, Chase Bank, Equifax, and Sony, and other large organizations like the U.S. Government. These are big enterprises that have the resources...
News
Cyber attacks are on the rise. Schools from, elementary to university-level, are especially vulnerable for multiple reasons.
The Guardian reported that schools were nearly twice as likely as private businesses to experience data breaches.
NPR breaks down why that could be the case.
https://www.npr.org/2024/03/11/1236995412/cybersecurity-hackers-schools-ransomware
Schools rely heavily on computer systems for a variety of functions, from taking attendance to uploading grades. They’re often among the largest employers especially in smaller communities; school records contain large amounts of sensitive information about students and employees. Hence, data breaches on schools can have catastrophic domino effects leading to identity theft and financial losses, either through theft itself or the cost of recovery.
Whether it’s through a ransomware attack or some other method, attackers exploit key vulnerabilities especially related to identity and access management (IAM). Preventing hacks in this area is as simple as using strong passwords, keeping software up to date, and most importantly using two-factor authentication. 2FA could be a physical token like a YubiKey, user verification through fingerprints or other biometrics, or a one-time password through an app like Google or Microsoft Authenticator.
Green Rocket Security understands that keeping your school’s data safe should be simple and affordable. Contact us today for a demo.
The recent discovery of the Blast-RADIUS vulnerability (CVE-2024-3596) poses a significant risk to networks worldwide. This flaw in the RADIUS authentication protocol can be exploited by attackers to gain unauthorized access, launch denial-of-service attacks, and...
SUMMARY This notice covers CVE-2024-6387 OpenSSH vulnerability (nicknamed “regreSSHion”) and its impact related to GreenRADIUS. GreenRADIUS is accessed using SSH from an internal (on prem) origin and therefore normally protected by an external firewall. This...
New Threats
Are you using a password manager to securely store all of your passwords? The use of password managers has become very common. It allows people to keep track of a variety of passwords, which are unique enough to protect their networks.
Although the purpose of this is to keep your passwords together in a secure manner, cases have been found in which these password managers have mistakenly leaked credentials. This flaw in the system has been named “AutoSpill”.
TechSpot recently reported that the way this happens is, “When the password manager is prompted to fill in the credentials, the expected behavior is that it’ll autofill them in the right fields of the WebView interface. However, it will sometimes expose your credentials to the base app instead.”
In this case there is no phishing or trick that the user can avoid, the mistake is automatically done through the password manager itself.
Having multi-factor authentication protects your network against the AutoSpill glitch or in any situation where your password has been exposed. This is because the password itself is not sufficient to gain access to your sensitive information.
Green Rocket Security specializes in multi-factor authentication by which users can have access to an Authenticator app or a physical token, such as a YubiKey. If you are looking for network protection beyond just your passwords, contact us to learn more about our GreenRADIUS solution.
Summary CVE-2021-44228 and CVE-2021-45046 (Log4Shell or LogJam) are both zero-day vulnerabilities in the widely used Apache Log4j Java-based logging library. Since it is widely used in many popular products, customers have contacted Green Rocket Security...
LokiBot Trojan Malware (a.k.a LukiBot, Lokibot, Loki PWS, and Loki-bot) is active again stealing sensitive information such as usernames, passwords, cryptocurrency wallets, and other credentials. It was first discovered in 2015 and has been used...