ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

ISS defends itself over Cisco flaw

Munir Kotadia and Patrick Gray ZDNet Australia

Published: 04 Aug 2005 09:40 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

ISS has hit back at critics who have accused the company of hypocrisy and thuggish behaviour following a former employee's disclosure of a serious vulnerability in Cisco's router operating system.

Kim Duffy, managing director of ISS Australia, said it was "business as usual" because the company had handled the Michael Lynn affair strictly by the book.

Last week, ISS researcher Lynn delivered a presentation on the Cisco flaw at the Black Hat conference in Las Vegas. He outlined how to attack Cisco's Internetworking Operating System (IOS) to gain control over a router. Cisco routers make up the infrastructure of the Internet and a widespread attack could cause extensive damage, according to experts attending the conference. He also told the audience he quit his job in order to deliver his findings.

Both the networking giant and ISS then took legal action against Lynn and the organisers of the conference. The dispute was settled, with Lynn agreeing not to discuss his presentation further.

"ISS has published rules for disclosure and that is what we stick to. We didn't care to publish [the disclosure] because we were not ready. We had not completed the research to our satisfaction so it was not ready to be disclosed," Duffy told ZDNet UK sister site ZDNet Australia.

Asked why Lynn felt the flaw disclosure was so important that he abruptly resigned, Duffy said: "I can't comment on what he felt. It is up to ISS staff to comply with our own rules."

However, influential names in the IT security industry have publicly criticised ISS and Cisco for the way they handled the affair.

The founder and chief executive of Check Point, Gil Shwed, accused ISS of hypocrisy and using the disclosure of vulnerabilities to drum up business. "It's not for research activities, it's not done to promote the community... it's done for marketing, it's done to promote ISS," he said at a Check Point user event in Bangkok, Thailand.

While ISS has painted Lynn as a breakaway rogue, Shwed and Check Point vice chairman Jerry Ungerman said he merely finished what ISS had started: "Lynn was their employee up until the day he wanted to present. He was working for them for six months and they knew all about it," Ungerman said.

On Cisco's view that Lynn infringed its intellectual property, Shwed said: "It's an embarrassing situation, I don't have a good solution". "I think that violating someone's intellectual property is severe... and I think that's something that every company would protect."

Shwed and Duffy agreed on this point.

"We would take action against any employee who was making unauthorised disclosures or stealing proprietary information — as would any other company," said Duffy.

Earlier this week, security experts Richard Forno and Bruce Schneier both attacked the way the affair was handled. Forno said Lynn was subjected to "heavy-handed" treatment while Schneier said Cisco's customers would not appreciate the truth being "stifled".

While Cisco had made a patch for the IOS vulnerability available months prior to Lynn's presentation, Check Point's Schwed said any effort to block Lynn's presentation was understandable. "No vendor would like to highlight [it] when something goes wrong. [But] the problem with a lot of networking gear is ... once you install it you expect it to be there operate reliably and efficiently for years and you don't want to patch it".

That means patch cycles for networking equipment are slower than traditional software applications, a possible reason Cisco wanted to hold details from the public, despite a patch for the vulnerability being available for several months. "At the same time, Cisco is not providing maybe all the tools and all the necessary things to fix, [but that] is a different issue," Shwed said.

On Tuesday, AusCERT sent out an alert to highlight the severity of the vulnerability and urge administrators to install the latest OS in their routers.

Patrick Gray travelled to Bangkok as a guest of Check Point Software.

Munir Kotadia and Patrick Gray reported for ZDNet Australia. For more ZDNet Australia stories, click here.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
67 out of 140 people found this useful


Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

SAP CRM Consultant in the UK

The core skills required for this SAP CRM consultant, this will include the SAP CRM delivery of one on one and presentation to senior managers and ...

Medical Manager - leading pharma

Representing the company to groups of experts, medical professional groups, societies, regulatory groups at international scientific meetings * ...

Senior Network Engineer Warrington 30k

Skills required include: - Demonstrated experience with TCP/IP, DHCP, WINS, DNS protocols - Strong commercial experience supporting PCs and MS ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Biometric devices. Do you need one?

When saying “biometrics” I am not thinking about law enforcement, AFIS systems, national ID and visa projects. I first think about personal solutions that will make my life easier.... More

1 comment

Barracuda launches counter-suit agains...

Court cases are never pleasant or simple. The ongoing battle between security companies Trend Micro and Barracuda Networks took a new twist on Wednesday, when Barracuda launched a counter-suit... More

Post a comment

Mobile Speed Demon: Wireless Surpasses...

Mobile Speed Demon: Wireless Surpasses Landline Author: Eric Everson, Founder MyMobiSafe.com As I look around my house and throughout my network of friends, I instantly realize... More

Post a comment