[NEWS] Cisco IOS Exploitation Techniques (Black Hat, Michael Lynn)

From: SecuriTeam (support_at_securiteam.com)
Date: 08/01/05

  • Next message: SecuriTeam: "[NT] HP OpenView Radia Management Agent Command Execution"
    To: list@securiteam.com
    Date: 1 Aug 2005 18:42:08 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      Cisco IOS Exploitation Techniques (Black Hat, Michael Lynn)
    ------------------------------------------------------------------------

    SUMMARY

    Cisco IOS (originally Internetwork Operating System) is the operating
    system used on Cisco Systems routers and some network switches. It is a
    multitasking operating system and provides kernel services such as process
    scheduling as well as the command line interface and routing software.

    Mike Lynn, former researcher for Internet Security Systems (ISS), spoke at
    the Black Hat security conference in Las Vegas about a serious
    vulnerability that he found while reverse-engineering the operating system
    in Cisco routers.

    DETAILS

    Cisco Systems and ISS prevented Lynn and the Black Hat conference
    organizers to publish this presentation and forced to remove it from
    conference material. The material however, can be found at the following
    link: <http://www.security.nnov.ru/files/lynn-cisco.pdf>
    http://www.security.nnov.ru/files/lynn-cisco.pdf.

    ADDITIONAL INFORMATION

    The original article can be found at:
    <http://www.security.nnov.ru/Fnews57.html>
    http://www.security.nnov.ru/Fnews57.html

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[NT] HP OpenView Radia Management Agent Command Execution"

    Relevant Pages

    • [Full-Disclosure] w32.frethem.k@mm and good reading
      ... Script kiddies deface websites. ... only obfuscating your own perception of security. ... >> vulnerabilities in a particular operating system or server software ... >> Imagine a custom operating system used by only a few servers, ...
      (Full-Disclosure)
    • [Full-Disclosure] w32.frethem.k@mm and good reading
      ... Script kiddies deface websites. ... only obfuscating your own perception of security. ... >> vulnerabilities in a particular operating system or server software ... >> Imagine a custom operating system used by only a few servers, ...
      (Full-Disclosure)
    • Re: Need advice about hacking and security
      ... and look at the Received-From: ... A trojan (from Trojan horse) is a seemingly innocuous ... > systems via various security holes. ... Windows Me is the operating system. ...
      (comp.security.misc)
    • Re: [PHP] Re: hello
      ... statement regarding susceptibility, ... servers, and have a Mac running OS X for testing Safari, and use Windows ... you may well defeat any security and "intelligence" the system has in ... -like operating system. ...
      (php.general)
    • Re: on the topic of stability
      ... >> software firewalls for evaluation without problems. ... >Yeah, true, no operating system is 100% secure by itself. ... >> internet apps designed with security in mind. ... >Win98se has almost no security built into the file system. ...
      (comp.security.firewalls)

  • Quantcast