Advertisement
Promo

Security threats Toolkit in association with http://ad.doubleclick.net/clk;214682528;14505427;f?http://uk.blackberry.com/ataglance/security/

Cisco flaw creates an opening for insider attacks

Ingrid Marson ZDNet.co.uk

Published: 19 Aug 2004 16:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Cisco released a security advisory on Wednesday warning that some Cisco networks could be vulnerable to denial-of-service attacks.

The problem occurs if a malformed packet is sent to a router that has been configured for the Open Shortest Path First (OSPF) protocol. This problem is limited to versions 12.0S, 12.2, and 12.3 of Cisco's IOS routing software.

Jon Oltsik, a network security analyst at the Enterprise Strategy Group, said the vulnerable versions and configuration are in common use and the effects of a successful attack could be devastating to an enterprise.

"If a hacker puts a certain request to the main router, then it could shut down the whole network," he said. But Oltsik believes that in practice the vulnerability requires both inside knowledge and Cisco expertise, which should limit the number of attacks. The most likely threat will come from former staff with a grievance.

"It's not like a Microsoft vulnerability that anyone with Internet access can exploit. You need specific knowledge to exploit this. An attack is most likely to come from a rogue employee who knows the configuration of the company's Cisco routers," said Oltsik.

Cisco has provided a patch for the security flaw and has also provided several workarounds for the problem. The full Cisco advisory has been posted here.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
116 out of 215 people found this useful


Full Talkback thread

1 comment

  1. Although Cisco have stated that this flaw is only... John Bradley
Video icon

Video

Sentry Posts Blog

Behind the Scenes: Next Gen Mobile Tec...

Behind the Scenes: Next Gen Mobile Technology Author: Eric Everson, Founder MyMobiSafe.com With infrastructure speeds continually improving at the network level of the world’s leading... More

Post a comment

Nasa hacker petition presented to Numb...

Sting's wife Trudie Styler and Janis Sharp have presented a petition to Number 10 calling for Nasa hacker Gary McKinnon not to be extradited to the US. Styler, and Sharp, who is... More

Post a comment

UK to appoint cyber-sec tsar?

The UK is to appoint a cyber security tsar along the lines of the US, according to a story in the Telegraph this morning. The story is similar to one that appeared in the Guardian... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters