Re: A MUST READ!!!

From: Walter Roberson (roberson_at_ibd.nrc-cnrc.gc.ca)
Date: 07/29/05


Date: Fri, 29 Jul 2005 15:11:45 +0000 (UTC)

In article <bnrGe.54191$mC.13260@tornado.tampabay.rr.com>,
Imhotep <Imhotep@nospam.com> wrote:
:Todd H. wrote:

:>> http://www.securityfocus.com/n

:...the kicker is they are saying that software flaws fall under IP. That is
:crewed up as software flaws are unintentional....

No, Cisco is saying that information about the internal layout of
IOS is Trade Secret. The researcher's talk would have had to
describe essential features about the internal layout of IOS
in order to indicate how, given -any- buffer overflow, one could
consistantly take meaningful control of the device.

The internal layout of an operating system is valid IP.

Cisco wasn't objecting to the researcher publicising that
a single buffer overflow attack had been found: Cisco was objecting
that the researcher (who had access to NDA information) broke
NDA in revealing the internal organization of IOS to show how
classes of attacks would work against IOS.

-- 
  The rule of thumb for speed is:
  1. If it doesn't work then speed doesn't matter.  -- Christian Bau


Relevant Pages

  • Re: catOS on 4506
    ... Are you saying I should or should not use my 4506 as a VMPS Server running ... CatOS. ... It is shipped with IOS on it. ...
    (comp.dcom.sys.cisco)
  • Re: Is Caruso overrated?
    ... > Like Bergonzi..he ios INTERESTING!!!!!> ... > You appear to be saying that Pavarotti is not interesting, ...
    (rec.music.opera)
  • Re: Windows updates
    ... > Tom wrote: ... >> I'm saying I can't get anything, but all I want ios a fix for this ...
    (microsoft.public.windowsupdate)
  • Re: Is Caruso overrated?
    ... Like Bergonzi..he ios INTERESTING!!!!!> ... You appear to be saying that Pavarotti is not interesting, ...
    (rec.music.opera)