ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

What can we learn from the Cisco fiasco?

Michael Mullins

Published: 09 Sep 2005 12:30 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

In late July, Cisco and ISS made headlines when the companies took unprecedented steps to stop a former ISS employee from disclosing Internet security vulnerabilities in Cisco's Internetwork Operating System (IOS) at the 2005 Black Hat security conference in Las Vegas. The companies took Michael Lynn to court, seeking a temporary restraining order from a US District Court and eventually agreeing on a permanent injunction that prohibits any further discussion of the presentation or dissemination of any information or recordings.

By now, you're likely to be more than a little familiar with this case. A high-profile story in the media, the controversy spurred all sorts of discussions about the legal debacle, the players involved, and the long-term ramifications. While such discussions are both interesting and relevant, that doesn't mean we can neglect the implications for the security arena.

Why was Cisco willing to take these extraordinary steps to prevent public disclosure? Let's take a closer look at the vulnerability, the issue, and a possible resolution.

The flaw
The flaw that Lynn resigned his job in order to disclose the information in his Black Hat presentation certainly wasn't new. It's rooted in an advisory that Cisco first published in April 2004, "Cisco Security Advisory: TCP Vulnerabilities in Multiple IOS-Based Cisco Products."

In his presentation, the former ISS researcher outlined a method for taking control of an IOS-based router, using this buffer overflow or a heap overflow attack. In fact, this flaw has been well-documented. In addition, depending on the version of IOS running on the router, the fixed version of the IOS was available, or Cisco made one available shortly after.

The problem
While the Cisco vulnerability was only one of several scheduled topics up for discussion at the Black Hat conference, the flaw — and the surrounding controversy — received the lion's share of attention. The disclosure of a new use for an old flaw became a hot topic, and almost everyone seems to have an opinion.

It's important to realise that not every business that runs Cisco routers reads...

For more, click here...

Next

Previous

1 2


  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
116 out of 211 people found this useful


Full Talkback thread

1 comment

  1. The idea of upgrading your Cisco IOS for every sec... Aindriu O hEithir

Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Citrix & VMWare Guru Required - Manchester - 30k

Virtualising Citrix Presentation Server 2. Presentation Server 3. Citrix Metaframe Presentation Server 3.0 8. Continuous professional development ...

Server Connectivity Principal Architect - SAN Connectivity HBA, Vendor

Server Connectivity Principal Architect, Solutions Architect, Storage Product Manager, Lead Presales Consultant - SAN Connectivity HBA - Vendor. ...

FIX CONNECTIVITY - LONDON - PERMANENT

FIX Support Engineer with strong client facing skills required for a leading boutique financial software organisation. An in-depth knowledge of FIX ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment