Comments
Matt McLarty wrote: For more info... Follow me on Twitter See our website
Cloud Computing
Conference & Expo
November 2-4, 2009 NYC
Register Today and SAVE !..

2008 West
DIAMOND SPONSOR:
Data Direct
SOA, WOA and Cloud Computing: The New Frontier for Data Services
PLATINUM SPONSORS:
Red Hat
The Opening of Virtualization
GOLD SPONSORS:
Appsense
User Environment Management – The Third Layer of the Desktop
Cordys
Cloud Computing for Business Agility
EMC
CMIS: A Multi-Vendor Proposal for a Service-Based Content Management Interoperability Standard
Freedom OSS
Practical SOA” Max Yankelevich
Intel
Architecting an Enterprise Service Router (ESR) – A Cost-Effective Way to Scale SOA Across the Enterprise
Sensedia
Return on Assests: Bringing Visibility to your SOA Strategy
Symantec
Managing Hybrid Endpoint Environments
VMWare
Game-Changing Technology for Enterprise Clouds and Applications
Click For 2008 West
Event Webcasts

2008 West
PLATINUM SPONSORS:
Appcelerator
Get ‘Rich’ Quick: Rapid Prototyping for RIA with ZERO Server Code
Keynote Systems
Designing for and Managing Performance in the New Frontier of Rich Internet Applications
GOLD SPONSORS:
ICEsoft
How Can AJAX Improve Homeland Security?
Isomorphic
Beyond Widgets: What a RIA Platform Should Offer
Oracle
REAs: Rich Enterprise Applications
Click For 2008 Event Webcasts
In many cases, the end of the year gives you time to step back and take stock of the last 12 months. This is when many of us take a hard look at what worked and what did not, complete performance reviews, and formulate plans for the coming year. For me, it is all of those things plus a time when I u...
SYS-CON.TV
"Cisco, You Are Really Screwing Up Here" Says Security Researcher
Raven Alder Takes Cisco to Task Over Its Legal Tactics vs Michael Lynn

Security officials at Cisco have released a patch to fix the Internet Operating System (IOS) problem that resulted in 'Ciscogate' T-shirts going on sale last week in Las Vegas, after Michael Lynn — who gave a controversial presentation on Cisco security (or, rather, insecurity) at the Black Hat Security Conference — was the subject of a permanent injunction preventing him from using any Cisco code in his possession for further reverse engineering or security research or presenting the same material at the DEF CON hacker convention which followed Black Hat.

Lynn, who has an extensive background in embedded systems, including kernel development and whose research interests include signals intelligence, cryptography, VoIP, reverse engineering, "and any protocol designed by committee," had recently been concentrating his research focus on securing critical routing infrastructures. As a result, his Black Hat talk was on how the Cisco IOS — the most widely deployed network infrastructure operating system — has been perceived as impervious to remote execution of arbitrary code from stack and heap overflows...but isn't.

Lynn provided an architectural overview of IOS and explored the feasibility of code execution against Cisco routers.

This is where Cisco moved in. Wishing to curtail a sudden spate of buffer overflow exploits against the world's most widely deployed network infrastructure OS, Cisco immediately sought to silence Lynn on the basis that the information he was disseminating was "not in the best interest of protecting the Internet" and sure enough Lynn and his attorney eventually agreed to a permanent injunction that prevents him from using any Cisco code in his possession for further reverse engineering or security research.

Raven Alder (pictured), a senior security consultant and senior network engineer and speaker at the DEF CON hacker convention which followed Black Hat, then took up the issue, summarizing Lynn's findings and discussing potential vulnerabilities in Cisco's IOS that could be used to compromise the networking giant's products.

She said (to Cisco): "Hiding your head in the sand is not going to help; suing researchers is not going to help — Cisco, you are really screwing up here." The audience applause suggested Cisco would need to do a great deal to get back on cordial terms with the security research community, so the news that the company has now patched the flaw — even though it comes a day after the close of DEF CON 13 rather than while it was still running in Las Vegas — should be a good first step.

In its Security Advisory, Cisco says:

Cisco Internetwork Operating System (IOS) Software is vulnerable to a Denial of Service (DoS) and potentially an arbitrary code execution attack from a specifically crafted IPv6 packet. The packet must be sent from a local network segment. Only devices that have been explicitly configured to process IPv6 traffic are affected. Upon successful exploitation, the device may reload or be open to further exploitation.

Cisco has made free software available to address this vulnerability for all affected customers.

About Security News Desk
SYS-CON's Security News desk trawls the world of security for news of software, hardware, products, and services that seems likely to be of interest to infosec professionals and summarizes them for easy assimilation by busy IT managers and staff.

In order to post a comment you need to be registered and logged in.

Register | Sign-in

Reader Feedback: Page 1 of 1

There are outstanding issues on Cisco's 2900 switches that have been unfixed there for years.

For the record, Lynn did not disclose the details of this vulnerability at all. The presentation was merely a demonstration that IOS was exploitable just like any other OS.

I don't work for True North any more -- sorry. Please edit the article to reflect that; I don't know how True North would feel about being associated with my controversial talk. I deliberately didn't name my current employer, since I wasn't talking under their banner and wasn't sure if they wanted to be associated with my opinions on this matter.

I hope Cisco reveals the full technical details of this problem as quickly as possible. The only reason I use Cisco is for the hardware. The software is closed-source and I have to trust Cisco to keep it secure. They dropped the ball completely.

I disagree with CISCO's position and believe that every effort should be made to release this information. The more it becomes available, the sooner CISCO will fix the problem.

The (fixed) exploit Lynn mentioned was merely an example of how to get on the box, but there are obviously going to be more ways to do that and quite likely someone already knows some of them. He also explains that while this is not the end of the world, the hardware abstraction Cisco is pursuing will make this type of attack work on many more routers.

Cisco's attempts to keep this one quiet has merely resulted in various hackers working through the weekend to investigate the vulnerability further!

Michael Lynn just wanted the fame behind this exploit. Sounds like he is first a crook and secondly a major-league jerk.

Raven is right. Because of the way it has (mis)handled this, all that Cisco has achieved is that people aren't going to care to report vulnerabilities to it. Lynn should have been thanked, not sanctioned.


Your Feedback
True, but... wrote: There are outstanding issues on Cisco's 2900 switches that have been unfixed there for years.
InfoPoint wrote: For the record, Lynn did not disclose the details of this vulnerability at all. The presentation was merely a demonstration that IOS was exploitable just like any other OS.
Raven Alder wrote: I don't work for True North any more -- sorry. Please edit the article to reflect that; I don't know how True North would feel about being associated with my controversial talk. I deliberately didn't name my current employer, since I wasn't talking under their banner and wasn't sure if they wanted to be associated with my opinions on this matter.
SecureGuy wrote: I hope Cisco reveals the full technical details of this problem as quickly as possible. The only reason I use Cisco is for the hardware. The software is closed-source and I have to trust Cisco to keep it secure. They dropped the ball completely.
Look Here wrote: I disagree with CISCO's position and believe that every effort should be made to release this information. The more it becomes available, the sooner CISCO will fix the problem.
FairPlay wrote: The (fixed) exploit Lynn mentioned was merely an example of how to get on the box, but there are obviously going to be more ways to do that and quite likely someone already knows some of them. He also explains that while this is not the end of the world, the hardware abstraction Cisco is pursuing will make this type of attack work on many more routers.
backfire wrote: Cisco's attempts to keep this one quiet has merely resulted in various hackers working through the weekend to investigate the vulnerability further!
ThisSux wrote: Michael Lynn just wanted the fame behind this exploit. Sounds like he is first a crook and secondly a major-league jerk.
DangerMouse wrote: Raven is right. Because of the way it has (mis)handled this, all that Cisco has achieved is that people aren't going to care to report vulnerabilities to it. Lynn should have been thanked, not sanctioned.
SOA World Latest Stories
What do the CTO of the U.S. Dept. of Justice and the CIO of the National Reconnaissance Office have in common with the CEOs of Eucalyptus, GoGrid, ActiveState, Appcara, OpSource and Nortonworks, the CTOs of Rackspace, SoftLayer and AppZero, the Founder & General Manager of Dell Boomi, ...
The cloud has many benefits, but when it comes to application development, how does the cloud help enterprises and development teams create custom software and applications that end users actually care about? Using real world examples from Adobe, Herff Jones and Navy Federal Credit Uni...
Data centers today are stretched to the limits with fast-paced business demands. On top of that, integrating and managing IT infrastructures can pose major challenges. Organizations need a new solution that consolidates servers and workloads without breaking the bank—and Linux, togethe...
Hmm, apparently Samsung has pushed one too many of Apple’s buttons. According to DigiTimes Apple has bought up half of Elpida Memory’s total chip production of mobile DRAM rather than give the iPad and iPhone order to Samsung, its largest supplier, accused of ripping off its technolo...
The BYOD trend requires sweeping changes to the way devices are used in the workplace. Find out how to confront and manage those changes, provide a better user experience, and ensure security. Gartner Hosted BYOD VIDEO: Mobility and the Social Enterprise Technical Design Workshop VID...
Nearly every enterprise is evaluating cloud computing solutions either today or in the near term. Many have already made the leap, and many more are getting close to putting that first toe in the water. But there are key considerations that should be made, questions to be asked, and de...
Subscribe to the World's Most Powerful Newsletters
Subscribe to Our Rss Feeds & Get Your SYS-CON News Live!
Click to Add our RSS Feeds to the Service of Your Choice:
Google Reader or Homepage Add to My Yahoo! Subscribe with Bloglines Subscribe in NewsGator Online
myFeedster Add to My AOL Subscribe in Rojo Add 'Hugg' to Newsburst from CNET News.com Kinja Digest View Additional SYS-CON Feeds
Publish Your Article! Please send it to editorial(at)sys-con.com!

Advertise on this site! Contact advertising(at)sys-con.com! 201 802-3021


SYS-CON Featured Whitepapers
ADS BY GOOGLE