BLOG-N-PLAY.COM
Woman (I think?) Almost Kills Baby with Diluted Formula
TODAY'S TOP SOA & WEBSERVICES LINKS



"Cisco, You Are Really Screwing Up Here" Says Security Researcher
'Ciscogate' T-shirts went on sale last week in Las Vegas, after Michael Lynn - who gave a controversial presentation on Cisco security (or, rather, insecurity) at the Black Hat Security Conference - was the subject of a permanent injunction preventing him from using any Cisco code in his possession for further reverse engineering or security research or presenting the same material at the DEF CON hacker convention which followed Black Hat.
Reader Feedback: Page 1 of 1

There are outstanding issues on Cisco's 2900 switches that have been unfixed there for years.

For the record, Lynn did not disclose the details of this vulnerability at all. The presentation was merely a demonstration that IOS was exploitable just like any other OS.

I don't work for True North any more -- sorry. Please edit the article to reflect that; I don't know how True North would feel about being associated with my controversial talk. I deliberately didn't name my current employer, since I wasn't talking under their banner and wasn't sure if they wanted to be associated with my opinions on this matter.

I hope Cisco reveals the full technical details of this problem as quickly as possible. The only reason I use Cisco is for the hardware. The software is closed-source and I have to trust Cisco to keep it secure. They dropped the ball completely.

I disagree with CISCO's position and believe that every effort should be made to release this information. The more it becomes available, the sooner CISCO will fix the problem.

The (fixed) exploit Lynn mentioned was merely an example of how to get on the box, but there are obviously going to be more ways to do that and quite likely someone already knows some of them. He also explains that while this is not the end of the world, the hardware abstraction Cisco is pursuing will make this type of attack work on many more routers.

Cisco's attempts to keep this one quiet has merely resulted in various hackers working through the weekend to investigate the vulnerability further!

Michael Lynn just wanted the fame behind this exploit. Sounds like he is first a crook and secondly a major-league jerk.

Raven is right. Because of the way it has (mis)handled this, all that Cisco has achieved is that people aren't going to care to report vulnerabilities to it. Lynn should have been thanked, not sanctioned.


FEATURED WHITE PAPERS
YOUR FEEDBACK
Harry KARADIMAS wrote: Well, there is truth in this article, but there is also truth in the developers that speak of "XML hell". XML is great when computers speak to computers, and it was made in great part for that : to quickly write reliable and fast parsers for structured documents. Unfortunately, just like when...
Java Consultant wrote: Good Post... Java Software Programmer..
Java Consultant wrote: Nice Article.... Java Programmer...
Java Consultant wrote: Good Post.... Java Consultant...
Java Consultant wrote: Great Post...... Java Consultant.....
HOT DISCUSSIONS
SUBSCRIBE TO THE WORLD'S MOST POWERFUL NEWSLETTERS


SYS-CON FEATURED WHITEPAPERS


A round-up of the many themes and topics of interest to infrastructure architects, developers and IT...
SYS-CON Events announced today that the leading global SOA, Virtualization, Cloud Computing and Open...
Cloud Computing offers significant benefits over traditional solutions for deploying production syst...
Intel has just released Intel XML Software Suite 1.2. This latest release helps maximize XML perform...
SYS-CON Events announced today that the leading global SOA, Virtualization, Cloud Computing and Open...
The events of the second half of 2008, where established financial institutions vanished overnight, ...
Data services, contends Rob Steward, Vice President of Research and Development at DataDirect Techno...
XML end-to-end architectures are a natural follow-on to SOA: XML for the user interface, XML for dat...
How can security standards such as Open Authorization and Semantics be used to bind Cloud-based serv...
DataServices World 2008 West, being held November 20 in San Jose, California, at the 14th Internatio...
In this session, a panel of instructors will conduct a Data Quality, Data Access and Data Services W...
"With proper markup/logic separation, a POJO data model, and a refreshing lack of XML…" So begins ...
"Data services and rich Internet applications are improving the usability and efficiency of browser-...
Hadoop, an open source implementation of map/reduce, has garnered tremendous momentum in large scale...
Ken North will be giving a breakout session at SYS-CON's upcoming DataServices World 2008 West in wh...
The DataServices World conference in Silicon Valley provides an opportunity on November 20, 2008 to ...
The one thing that unifies the distributed computing style known as SOA, in most of its manifestatio...
Altova (http://www.altova.com), developers of XMLSpy, an industry leading XML editor, offers Microso...
Intel, a leader in silicon innovation, develops technologies, products and initiatives to continuall...
Can high-performance XML be sexy? QuantumXML, the world’s fastest XML software, speeds through typ...
ADS BY GOOGLE