ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security threats Toolkit

Cisco flaw creates an opening for insider attacks

Ingrid Marson ZDNet.co.uk

Published: 19 Aug 2004 16:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Cisco released a security advisory on Wednesday warning that some Cisco networks could be vulnerable to denial-of-service attacks.

The problem occurs if a malformed packet is sent to a router that has been configured for the Open Shortest Path First (OSPF) protocol. This problem is limited to versions 12.0S, 12.2, and 12.3 of Cisco's IOS routing software.

Jon Oltsik, a network security analyst at the Enterprise Strategy Group, said the vulnerable versions and configuration are in common use and the effects of a successful attack could be devastating to an enterprise.

"If a hacker puts a certain request to the main router, then it could shut down the whole network," he said. But Oltsik believes that in practice the vulnerability requires both inside knowledge and Cisco expertise, which should limit the number of attacks. The most likely threat will come from former staff with a grievance.

"It's not like a Microsoft vulnerability that anyone with Internet access can exploit. You need specific knowledge to exploit this. An attack is most likely to come from a rogue employee who knows the configuration of the company's Cisco routers," said Oltsik.

Cisco has provided a patch for the security flaw and has also provided several workarounds for the problem. The full Cisco advisory has been posted here.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with Konica

Did you find this article useful?
116 out of 215 people found this useful


Full Talkback thread

1 comment

  1. Although Cisco have stated that this flaw is only... John Bradley

Sentry Posts Blog

Virtual Teams: Small Business Innovati...

Virtual Teams: Small Business Innovation Author: Eric Everson, Founder – MyMobiSafe.com As the founder of MyMobiSafe.com, I’ve found that because of our presence in the industry... More

Post a comment

Mobile Security and Innovation: An Ope...

Mobile Security and Innovation: An Open Case Author: Eric Everson, Founder MyMobiSafe.com The times are changing in the mobile industry as “big wireless” in the US Markets are calling... More

Post a comment

Government launches new e-crime unit

Ok, so this is outside of my main area of focus of sustainable and green tech but I do track some security issues too. I was at a meeting last week with Microsoft's security advisor... More

Post a comment