![]() |


|
|||||||
| The Sandbox This forum is for current events, satire and humorous discussions. |
![]() |
|
|
Thread Tools |
|
|
#1 (permalink) |
![]() ![]() ![]() ![]() Join Date: Oct 2001
Location: Rhode Island, USA
Age: 36
Posts: 8,917
|
"Cisco Gate" at DEFCON and Black Hat
For those of you out there interested in network/Internet security related topics:
Michael Lynn was a former employee of ISS. While employed at ISS he discovered a critical vulnerability in Cisco's IOS that is largely responsible for the backbone operation of the Internet. This vulnerability allowed an attacker to get full administrative/root (in Cisco land, called "enable") rights to network devices. Lynn was scheduled to present this information this past week at Black Hat and was warned by his employer, ISS, not to present his findings. Lynn summarily quit his job at ISS in order to be able to present these findings. Cisco and ISS responded by suing Lynn and the Black Hat organizers hours after his presentation on Wednesday and forced Black Hat to remove sections of conference book that included notes on the vulnerability as well as a copy of his talk. On Saturday, I watched Raven Alder's presentation on "Hacking the Backbone" and she had some very harsh comments towards Cisco: "Cisco, you are really screwing up. Suing researchers is not going to make you secure. Alienating the security community is not going to encourage people to come to you and report problems and work with you."How do you feel about these actions taken by Cisco? In this day and age, many companies are only as concerned about security as they are forced to be. Security vulnerabilities exist in all sorts of software products and hardware appliances that are never touched until the public becomes aware of them and force the manufacturers to fix the flaws. As long as a security hole remains hidden, most companies don't bother to fix them. Some Articles: Cisco hits back at flaw researcher Hackers rally behind Cisco flaw finder Black Hat Day 1: Update on Cisco-Gate A video clip of Cisco/ISS and Black Hat reps tearing out Lynn's section of the Black Hat Briefings book: Book Destruction Video
__________________
Diplomacy is the art of saying "good doggie" while looking for a bigger stick.
|
|
|
|
|
|
#2 (permalink) |
![]() Join Date: Sep 2003
Age: 39
Posts: 7,669
|
Re: "Cisco Gate" at DEFCON and Black Hat
I'm just saying that the guy is clearly willing to throw his job away for something he thinks is "right", in this case exposing a backbone vulnerability. What if he's working for me and finds some hole in our processes (not that we have any....HA!)? Will he feel compelled to announce it to the world over our objections? Seems so.
Last edited by leejo; 08-02-2005 at 03:36 PM. |
|
|
|
| Sponsored links | |
|
|
|
|
|
#3 (permalink) |
|
Join Date: Jul 2005
Location: USA
Age: 23
Posts: 127
|
Re: "Cisco Gate" at DEFCON and Black Hat
This wasn't just a "hackers" conference, law enforcement was there also...
Edit: And not in the way your probably thinking.
__________________
I'm not the Killer Man... I'm the Killer Man's son... But I'll do the killing... Until the Killer Man comes...
|
|
|
|
|
|
#4 (permalink) | |
![]() ![]() ![]() ![]() Join Date: Oct 2001
Location: Rhode Island, USA
Age: 36
Posts: 8,917
|
Re: "Cisco Gate" at DEFCON and Black Hat
Quote:
Nothing was disclosed telling people exactly how to exploit this vulnerability. The only reason anyone should be concerned about hiring Michael Lynn is if they wish to practice security by obscurity and not to take the appropriate steps as soon as possible to remedy issues such as this.
__________________
Diplomacy is the art of saying "good doggie" while looking for a bigger stick.
|
|
|
|
|
|
|
#5 (permalink) | |
![]() ![]() ![]() ![]() Join Date: Oct 2001
Location: Rhode Island, USA
Age: 36
Posts: 8,917
|
Re: "Cisco Gate" at DEFCON and Black Hat
Quote:
Although I don't think it was any LEO or DOD employee that poured the Kool-Aid in Pool #3 on Friday night. ![]()
__________________
Diplomacy is the art of saying "good doggie" while looking for a bigger stick.
|
|
|
|
|
|
|
#6 (permalink) |
|
Join Date: Feb 2005
Location: Littleton, CO
Posts: 602
|
Re: "Cisco Gate" at DEFCON and Black Hat
To me, this is akin to shooting the messenger. My company utilizes (2) very expensive (More than $100k) Cisco routers and we cannot afford any downtime as our routers are used to provide closed captioning to live TV broadcasts and we will be fined, no matter the reason. Just as I don't trust Cisco anymore to identify vulnerabilites, I cannot trust them to provide a reliable fix or work around as quickly as I might need it. As is usually the case, providing this information to world at large is more likely to produce a quick fix than waiting on the manufacturer. I think the whistleblower laws should protect people like this also.
|
|
|
|
| Sponsored links | |
|
|
|
|
|
#7 (permalink) | |
|
Join Date: Feb 2005
Location: Littleton, CO
Posts: 602
|
Re: "Cisco Gate" at DEFCON and Black Hat
Quote:
|
|
|
|
|
|
|
#8 (permalink) |
![]() ![]() Join Date: Jan 2004
Location: Houston, TX
Age: 26
Posts: 4,473
|
Re: "Cisco Gate" at DEFCON and Black Hat
It's Cisco.... I mean... are you really surprised they pulled this? I would be shocked if they didn't.
Cisco is the only company I know that sells a 100 Mb hub for $300 US. Last year it was $600. They'd probably squeeze school-children to death if they thought silicon would come out of them. Plus the food at their confrences sucks.
__________________
|
|
|
|
|
|
#9 (permalink) | |
|
Join Date: Oct 2004
Posts: 499
|
Re: "Cisco Gate" at DEFCON and Black Hat
According to the article:
Quote:
This has nothing to do with security by obscurity. Cisco patched it, and tried to protect their customers by stopping Lynn. From what I see, I don't think there's anything wrong with that. |
|
|
|
|
|
|
#10 (permalink) | |
|
Join Date: Oct 2004
Posts: 499
|
Re: "Cisco Gate" at DEFCON and Black Hat
Actually, from one of the articles
Quote:
But it's important to note that, despite how the flaw was discovered, Cisco did patch it. Lynn quit his job at ISS because they didn't want to present their research yet, and he presented their research anyway. Any company that has an NDA should be concerned about hiring Lynn, because it's pretty obvious that doesn't mean anything to him. The bottom line is, everyone involved in this whole mess was doing something wrong. |
|
|
|
|
| Sponsored links | |
|
|
|
|
|
#11 (permalink) | |
|
Join Date: Feb 2005
Location: Littleton, CO
Posts: 602
|
Re: "Cisco Gate" at DEFCON and Black Hat
Quote:
|
|
|
|
|
|
|
#13 (permalink) | |
|
Join Date: Oct 2004
Posts: 499
|
Re: "Cisco Gate" at DEFCON and Black Hat
Quote:
It's like if I send you the source code for a class I wrote at work last week. Is there a reason why I shouldn't be able to talk about what I wrote? Yes. It's called an NDA, a legally binding contract I signed when I was hired stating that I would not do that. |
|
|
|
|
|
|
#14 (permalink) | |
![]() ![]() ![]() ![]() Join Date: Oct 2001
Location: Rhode Island, USA
Age: 36
Posts: 8,917
|
Re: "Cisco Gate" at DEFCON and Black Hat
Quote:
__________________
Diplomacy is the art of saying "good doggie" while looking for a bigger stick.
|
|
|
|
|
|
|
#15 (permalink) | |
![]() ![]() ![]() ![]() Join Date: Oct 2001
Location: Rhode Island, USA
Age: 36
Posts: 8,917
|
Re: "Cisco Gate" at DEFCON and Black Hat
Quote:
__________________
Diplomacy is the art of saying "good doggie" while looking for a bigger stick.
|
|
|
|
|
| Sponsored links | |
|
|
|
![]() |
| Bookmarks |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Black Hat 2006 - DEFCON 14 | Apophis | General Discussion | 16 | 08-04-2006 11:22 PM |

