ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Cisco flaw creates an opening for insider attacks

Ingrid Marson ZDNet.co.uk

Published: 19 Aug 2004 16:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Cisco released a security advisory on Wednesday warning that some Cisco networks could be vulnerable to denial-of-service attacks.

The problem occurs if a malformed packet is sent to a router that has been configured for the Open Shortest Path First (OSPF) protocol. This problem is limited to versions 12.0S, 12.2, and 12.3 of Cisco's IOS routing software.

Jon Oltsik, a network security analyst at the Enterprise Strategy Group, said the vulnerable versions and configuration are in common use and the effects of a successful attack could be devastating to an enterprise.

"If a hacker puts a certain request to the main router, then it could shut down the whole network," he said. But Oltsik believes that in practice the vulnerability requires both inside knowledge and Cisco expertise, which should limit the number of attacks. The most likely threat will come from former staff with a grievance.

"It's not like a Microsoft vulnerability that anyone with Internet access can exploit. You need specific knowledge to exploit this. An attack is most likely to come from a rogue employee who knows the configuration of the company's Cisco routers," said Oltsik.

Cisco has provided a patch for the security flaw and has also provided several workarounds for the problem. The full Cisco advisory has been posted here.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
116 out of 215 people found this useful


Full Talkback thread

1 comment

  1. Although Cisco have stated that this flaw is only... John Bradley

Related Jobs

NETWORK ENGINEER - CISCO SWITCHES, ROUTERS & CALL MANAGER - MIDLANDS

CCIE supported Cisco VoIP & WAN - project focused role. This is a varied & challenging role working with a wide range of Cisco technologies ...

IP Telephony Engineer - 3 month contract Cisco

Gear Router/Switches Cisco Driving license is essential If this role is of interest please apply via the link below. Working on there various sites ...

CCNA/CCNP Cisco Engineer - Routers/Switches/Firewalls - Bath

The ideal candidate will have a skill set to include as many of the following: CCNA or CCNP certified, Routers, Catalyst Switches 29xx, 35xx and ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment