July 29, 2005 11:40 PM PDT

More legal threats over Cisco flaws

LAS VEGAS--In an apparent attempt to keep a presentation on Cisco Systems' router flaws off the Web, a lawsuit was threatened against a person who made details of the flaw available online.

Richard Forno, a security specialist and author, said in an e-mail that he received a cease-and-desist letter from lawyers representing Internet Security Systems. He subsequently pulled the presentation from his Infowarrior.org Web site and replaced it with a fax he said came from the law firm of Piper Rudnick Gray Cary, counsel for ISS.

An ISS representative could not immediately confirm late Friday that the company had asked its lawyers to take action against Web sites hosting the presentation. A Cisco representative said that although Cisco is working with ISS in the matter, he was told that ISS was sending out the takedown notices.

The presentation appears to be an early version of the slide-deck used by security researcher Michael Lynn on Wednesday morning at the Black Hat security confab in Las Vegas for his talk: "The Holy Grail: Cisco IOS Shellcode and Remote Execution."

Lynn caused a stir at Black Hat--in defiance of Cisco and ISS--by demonstrating how he could gain control of a Cisco router by exploiting a security flaw. Cisco and ISS had agreed to pull the presentation shortly before the event, but Lynn quit his job at ISS and gave the talk anyway.

Cisco and ISS subsequently went to court seeking a gag order against Lynn and the Black Hat organizers. The parties reached a deal on Thursday, in which Lynn agreed never to repeat the information he gave at Black Hat. He also has to hand over any Cisco source code in his possession.

The presentation was pulled out of the hard copy of the event proceedings. Hours before Black Hat was to start, temporary workers hired by Cisco cut the pages from the book, the Black Hat organizers said Thursday. CD-ROMs were destroyed and replaced. Some attendees, however, were able to obtain the original disks, they said at the event.

Lynn outlined how to run attack code on Cisco's Internetwork Operating System by exploiting a known security flaw in IOS. The software runs on Cisco routers, which make up the infrastructure of the Internet. A widespread attack could badly hurt the Internet and immediate action is needed to protect the critical infrastructure, he said.

The slides are still available for public download on other Web sites, including Cryptome.org. The presentation was also distributed on the popular Full Disclosure security mailing list on Friday.

Black Hat ended on Thursday. At DefCon--the more informal hacker gathering that followed--Michael Lynn was hailed as a hero for disclosing information that may help protect the Internet. DefCon attendees chided Cisco and ISS for thinking only about their pocket books and not about securing their customers.

Jennifer Granick, Lynn's attorney, on Friday said her client is the subject of a federal investigation. She declined to share more details, but did say that it likely will end soon because of the agreement reached between Lynn, ISS and Cisco.

Cisco on Friday released a security advisory detailing the flaw in IOS that was exposed by Lynn and admitting that it could be exploited to gain control over routers.

Cisco claims the potential damage caused by the flaw is limited because the hacker would need to be connected directly to the router, rather than remotely via the Net.

According to Cisco's advisory, older versions of IOS are flawed in the way they process IPv6 packets, Cisco said in its advisory. A specially crafted data packet could let a miscreant gain control over the router, but an attack is possible only from a local network segment and only on systems configured for IPv6, Cisco said.

See more CNET content tagged:
Black Hat, Cisco IOS, Cisco Systems Inc., router, Defcon

Add a Comment (Log in or register) 2 comments
Crytome.org
by Sugarat July 30, 2005 10:12 AM PDT
"The slides are still available for public download on other Web sites, including Crytome.org."

Crytome.org is nothing more than a redirect to a generic search engine. I don't understand why you would put that in without checking it out first. It's actually http://www.cryptome.org.
Reply to this comment View reply
Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Chrome's JavaScript challenge to Silverlight

    The advent of Google's Chrome browser, software pros say, should spur a big speedup for JavaScript, which would raise its standing against Microsoft's Silverlight technology.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • News - Apple

    Apple watchers spot 'iPod Nano' pix, iTunes hints

    The rumor mill has long been predicting a longer, leaner new version of the iPod Nano, and now it's conjuring up some pictures.

  • Coop's Corner

    Chris Shipley 1, Internet lynch mob 0

    Demo's impresario goes public with a tart and smartly written riposte to the shoot-from-the-lip crowd.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • News - Digital Media

    Google-focused satellite enters orbit

    The search titan has exclusive rights among online mapping sites to images from the new GeoEye-1 satellite, which launched Saturday.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Crossfade

    The Standard, 'A Different Skin': Free MP3 of the Day

    Eschewing the danceable beats favored by many of its post-punk brethren, while opting instead for more ominous and insistent rhythms, is what makes the Standard visceral and engaging. Download a free MP3 of "A Different Skin" courtesy of CNET Download Mus

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.