Enter your Email


Powered by FeedBlitz
Ted Demopoulos Ted's contact info
Ted lives in Durham, New Hampshire, USA, with his wife Margaret, children Jamie, Amelia, Anastasia, and dog Tyler. He consults and gives keynotes on Technology, Security, and Business. He loves flyfishing, ham radio, and great food and wine.

Main Website

Keynote Speeches

Free Articles

securITy Newsletter

More about Ted

Atom/RSS feed

Add to My Yahoo!

Subscribe with Bloglines

Subscribe in NewsGator Online

•Profitable College Speaking Bootcamp

•Striped Bass Fly Fishing

•College Speaker

•Shopping Carts for Blogs and Websites

•Book Reviews

•SANS Network Security 2008

•Need a Shopping Cart?

•Security Laboratory

•Become a Published Author and Public Speaker

•SANS Security Training

•Geekonomics

•Security Thought Leader

ex ISS Researcher Lynn details Cisco Vulnerability at Black Hat

Cisco routers run the Internet. Just as Microsoft Windows rules and runs the desktop, Cisco routers rule and run the Internet. They control the basic flow of Internet traffic.

A successful attack to Cisco router's operating system, IOS, is very serious and can bring the entire Internet to its knees. IOS attacks are less frequent for a number of reasons, including that most hackers have less familiarity with IOS than Windows, and IOS is simpler than Windows and hence tends to be more secure. But nothing is totally secure, including Cisco routers and IOS.

Internet Security Systems' Michael Lynn found a bug in IOS that allowed him to shut down Cisco routers. The bug has been long since patched, since April, although many routers have not had the patch implemented yet.

Lynn was going to detail his Cisco attack at the Black Hat conference, but the talk was canceled due to pressure from Cisco. Since many routers still not updated, the attack IS viable.

Lynn quit his job at ISS and gave the presentation anyways! This guy has got balls! He explained that giving the talk was "the right thing to due," citing concerns over the misconception that Cisco's products are somehow less vulnerable to attacks than Windows.

Both Cisco and ISS allegedly threatened him with legal action if he proceeded and gave his talk.

Not publicizing the attack details, as Lynn did, makes sense. Many routers are still vulnerable. However raising the awareness of security issues, including debunking a false sense that routers are close to invulnerable, is a noble act. I wasn't there and don't have all the details, but certainly can see both sides of the issue.

Lynn also voiced his opinion with concerns about Cisco's IOS getting more complex in subsequent releases.

INCREASING SOFTWARE COMPLEXITY is a MAJOR ISSUE with most software and I agree whole heartedly!! More complexity = less reliable and less secure!

Comments on "ex ISS Researcher Lynn details Cisco Vulnerability at Black Hat"

 

post a comment

      
      

Most Internet users have been targeted by criminal phishing emails, yet less than one third have any idea what phishing is, and only 3.5% have changed their habits due to the threat of phishing!

Risks include Identity Theft, Credit Card fraud, and more.

Download Results (pdf)