Re: [HACKERS] Fwd: SSPI authentication ASC_REQ_REPLAY_DETECT flag

2015-03-31 Thread Stephen Frost
Jacobo, * Jacobo Vazquez (jvazq...@denodo.com) wrote: >Am I misunderstanding something or is this the expected behavior? This > not means a replay attack risk? I think that if SSL is not used by the > connection, a malicious user could capture the authentication package which > the client serv

[HACKERS] Fwd: SSPI authentication ASC_REQ_REPLAY_DETECT flag

2015-03-31 Thread Jacobo Vazquez
Hi all, I installed PostgreSQL 9.3 on a Windows Server 2012 and I have configured it to use SSPI authentication. The client is on a Windows 7 machine and make the connections via ODBC using a DSN with psqlodbc driver version 9.03.04.00. Authentication works in this scenario for the user authen