More Cisco/Blackhat
Cisco/Blackhat
We did receive quite a bit of input about Michael Lynn's presentation about the
Cisco flaws. Beyond what was reported in the press, we have nothing new/different
to add. It looks like things will move to the courts.
The quick summary: Michael Lynn talked about how to better exploit known
flaws in Cisco IOS. He did not talk about any new / 0 day vulnerability. However,
with his work it could be easier to write exploit code that will change router
settings or run arbitrary code. Most of these techniques have been discussed before, but the presentation put a lot of them in an easier to understand content.
What does it mean for companies running Cisco equipment: Patch. It is possible that some flaws, which where considered 'DOS only' flaws at this point, can be
used to execute code on the router. Cisco routers may attrack more attention
as a result of the presentation (not like they got left out of the games so far).
So again: Nothing fundamentally new, but a new quality of exploitation. At this point, its more of a legal issue then a technical issue.
Some links that go into more detail about the affair:
http://blogs.washingtonpost.com/securityfix/
http://www.securityfocus.com/news/11259
Feel free to voice your opinion in our , but keep it civil (the forum is moderated, and now email addresses are obfuscated).
Windows Genuine Advantage update
Update to windows genuine advantage.
One reader pointed out that despite microsoft's asserting to the contrary this "patch" could be backed out. I won't be providing the details. Donald Smith
Keywords:
0 comment(s)
×
Diary Archives
Comments
www
Nov 17th 2022
6 months ago
EEW
Nov 17th 2022
6 months ago
qwq
Nov 17th 2022
6 months ago
mashood
Nov 17th 2022
6 months ago
isc.sans.edu
Nov 23rd 2022
6 months ago
isc.sans.edu
Nov 23rd 2022
6 months ago
isc.sans.edu
Dec 3rd 2022
6 months ago
isc.sans.edu
Dec 3rd 2022
6 months ago
<a hreaf="https://technolytical.com/">the social network</a> is described as follows because they respect your privacy and keep your data secure. The social networks are not interested in collecting data about you. They don't care about what you're doing, or what you like. They don't want to know who you talk to, or where you go.
<a hreaf="https://technolytical.com/">the social network</a> is not interested in collecting data about you. They don't care about what you're doing, or what you like. They don't want to know who you talk to, or where you go. The social networks only collect the minimum amount of information required for the service that they provide. Your personal information is kept private, and is never shared with other companies without your permission
isc.sans.edu
Dec 26th 2022
5 months ago
isc.sans.edu
Dec 26th 2022
5 months ago