| By Security News Desk | Article Rating: |
|
| August 1, 2005 04:00 AM EDT | Reads: |
16,109 |
Security officials at Cisco have released a patch to fix the Internet Operating System (IOS) problem that resulted in 'Ciscogate' T-shirts going on sale last week in Las Vegas, after Michael Lynn — who gave a controversial presentation on Cisco security (or, rather, insecurity) at the Black Hat Security Conference — was the subject of a permanent injunction preventing him from using any Cisco code in his possession for further reverse engineering or security research or presenting the same material at the DEF CON hacker convention which followed Black Hat.Lynn, who has an extensive background in embedded systems, including kernel development and whose research interests include signals intelligence, cryptography, VoIP, reverse engineering, "and any protocol designed by committee," had recently been concentrating his research focus on securing critical routing infrastructures. As a result, his Black Hat talk was on how the Cisco IOS — the most widely deployed network infrastructure operating system — has been perceived as impervious to remote execution of arbitrary code from stack and heap overflows...but isn't.
Lynn provided an architectural overview of IOS and explored the feasibility of code execution against Cisco routers.
This is where Cisco moved in. Wishing to curtail a sudden spate of buffer overflow exploits against the world's most widely deployed network infrastructure OS, Cisco immediately sought to silence Lynn on the basis that the information he was disseminating was "not in the best interest of protecting the Internet" and sure enough Lynn and his attorney eventually agreed to a permanent injunction that prevents him from using any Cisco code in his possession for further reverse engineering or security research.
Raven Alder (pictured), a senior security consultant and senior network engineer and speaker at the DEF CON hacker
convention which followed Black Hat, then took up the issue, summarizing Lynn's findings and discussing potential vulnerabilities in Cisco's IOS that could be used to compromise the networking giant's products.
She said (to Cisco): "Hiding your head in the sand is not going to help; suing researchers is not going to help — Cisco, you are really screwing up here." The audience applause suggested Cisco would need to do a great deal to get back on cordial terms with the security research community, so the news that the company has now patched the flaw — even though it comes a day after the close of DEF CON 13 rather than while it was still running in Las Vegas — should be a good first step.
In its Security Advisory, Cisco says:
Cisco Internetwork Operating System (IOS) Software is vulnerable to a Denial of Service (DoS) and potentially an arbitrary code execution attack from a specifically crafted IPv6 packet. The packet must be sent from a local network segment. Only devices that have been explicitly configured to process IPv6 traffic are affected. Upon successful exploitation, the device may reload or be open to further exploitation.
Cisco has made free software available to address this vulnerability for all affected customers.
Published August 1, 2005 Reads 16,109
Copyright © 2005 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
- Cisco Enters the Grid Computing Arena With $250M Acquisition
- IBM and Cisco Develop Speech-Enabled Products
- Cisco, the Linux Leviathan?
- Cisco Acquires FineGround
- Cisco To Deploy Palamida's Flagship IP Management Solution
- Cisco and Yahoo! Join to Fight Spam
- IBM WebSphere Tapped for Cisco Application-Oriented Networking
- Cisco's AON Strategy Leans on Partners
- Charles Giancarlo Made Chief Development Officer of Cisco
- Cisco Outlines Security Problem, Symantec Warns Against It
About Security News Desk
SYS-CON's Security News desk trawls the world of security for news of software, hardware, products, and services that seems likely to be of interest to infosec professionals and summarizes them for easy assimilation by busy IT managers and staff.
![]() |
True, but... 08/02/05 04:47:05 AM EDT | |||
There are outstanding issues on Cisco's 2900 switches that have been unfixed there for years. |
||||
![]() |
InfoPoint 08/02/05 04:39:54 AM EDT | |||
For the record, Lynn did not disclose the details of this vulnerability at all. The presentation was merely a demonstration that IOS was exploitable just like any other OS. |
||||
![]() |
Raven Alder 08/01/05 01:37:15 PM EDT | |||
I don't work for True North any more -- sorry. Please edit the article to reflect that; I don't know how True North would feel about being associated with my controversial talk. I deliberately didn't name my current employer, since I wasn't talking under their banner and wasn't sure if they wanted to be associated with my opinions on this matter. |
||||
![]() |
SecureGuy 08/01/05 07:11:36 AM EDT | |||
I hope Cisco reveals the full technical details of this problem as quickly as possible. The only reason I use Cisco is for the hardware. The software is closed-source and I have to trust Cisco to keep it secure. They dropped the ball completely. |
||||
![]() |
Look Here 08/01/05 06:58:39 AM EDT | |||
I disagree with CISCO's position and believe that every effort should be made to release this information. The more it becomes available, the sooner CISCO will fix the problem. |
||||
![]() |
FairPlay 08/01/05 06:53:59 AM EDT | |||
The (fixed) exploit Lynn mentioned was merely an example of how to get on the box, but there are obviously going to be more ways to do that and quite likely someone already knows some of them. He also explains that while this is not the end of the world, the hardware abstraction Cisco is pursuing will make this type of attack work on many more routers. |
||||
![]() |
backfire 08/01/05 06:35:33 AM EDT | |||
Cisco's attempts to keep this one quiet has merely resulted in various hackers working through the weekend to investigate the vulnerability further! |
||||
![]() |
ThisSux 08/01/05 06:16:46 AM EDT | |||
Michael Lynn just wanted the fame behind this exploit. Sounds like he is first a crook and secondly a major-league jerk. |
||||
![]() |
DangerMouse 08/01/05 03:24:33 AM EDT | |||
Raven is right. Because of the way it has (mis)handled this, all that Cisco has achieved is that people aren't going to care to report vulnerabilities to it. Lynn should have been thanked, not sanctioned. |
||||
- AJAX World RIA Conference & Expo Kicks Off in New York City
- Ulitzer’s Amazing First 30 Days in Public Beta
- "Government IT Expo" to Highlight Cloud Computing and SOA
- Ulitzer vs. Ning - a Quick Review
- Improving the Efficiency of SOA-Based Applications
- Make Your Design Ideas Speak: Using UML in PowerBuilder Projects
- Ted Weissman and Lois Paul & Partners PR Firm
- SOA to Reduce Complexity?
- VMware Poaches CA Exec to Run Asia Pacific
- Cisco to Buy Tidal Software
- AJAX World RIA Conference & Expo Kicks Off in New York City
- Building the Right Project Team: The Rule of Five
- Ulitzer’s Amazing First 30 Days in Public Beta
- "Government IT Expo" to Highlight Cloud Computing and SOA
- DataDirect Data Integration Suite Features XQuery 4.0, XML Converters and Stylus Studio 2009
- Reducing Development Costs with SOA
- Macrovision White Paper Showcases Digital Entertainment Media
- Software AG Releases Tamino XML Server for SOA Interface
- Dajeil Launches Xerces/Xalan Hardware Accelerator for XML and SOA
- Ulitzer vs. Ning - a Quick Review
- AJAX World RIA Conference & Expo Kicks Off in New York City
- JSON vs XML - A Jason vs Freddie Sequel
- Processing XML with C# and .NET
- i-Technology Viewpoint: The Very Confused World of 3D and XML
- BPEL Processes and Human Workflow
- Open Source Database Special Feature: An Introduction to Berkeley DB XML
- "HP's Problem Ain't the SAP Install," Says Sun's Schwartz
- eXist - An Introduction To Open Source Native XML Database
- Digitizing the Planet: Google Earth vs MSN Virtual Earth vs MapQuest
- Product Review: Altova Enterprise Suite 2005






































