• On TV.com: THE GIRLS NEXT DOOR photos

July 16, 2003 3:52 PM PDT

ISPs rush to fix Cisco flaw

  • Print
Related Stories

Taking aim at denial-of-service attacks

May 13, 2003

Bush unveils final cybersecurity plan

February 14, 2003

Damage control

February 6, 2003

Flaws in common software threaten Net

February 12, 2002
Internet service providers are vulnerable to a flaw in Cisco routers that could cause some Web sites and servers to become inaccessible, according to a major telecommunications company and network administrators familiar with the issue.

While details of the flaw are unclear, it is apparently widespread and affects much of the network infrastructure used by the major Internet service providers, CNET News.com learned Wednesday. Cisco is a major provider of network switches and routers used to direct data across the Internet.

Cisco could not immediately comment, but telecommunications provider Sprint confirmed that there is a problem.

"Sprint is aware of the issue regarding Cisco," said spokesman Charles Fleckenstein, reading from a statement. "Modifications are being performed on the Sprint Internet backbone, and customers should have no concerns regarding an interruption of service in regards to Sprint."

The flaw could be used by an attacker to crash a router, clogging the Internet's communications channels, sources said. Due to the vulnerability's nature, the router won't appear to be down, said one network expert familiar with the flaw. The router would have to be restarted or reset to make it operational.

While Fleckenstein couldn't confirm the details of the flaw, he stressed that network outages elsewhere on the Internet could affect its customers' connections and their ability to reach Web sites.

"While the appropriate measures are being taken to protect the Sprint Internet backbone, issues may arise with traffic that is handed off to other carriers, if those carriers have not taken the measures that Sprint has, to protect their networks," Fleckenstein said.

Sprint expected to have its network hardware updated by Thursday morning.

Other ISPs, including Level 3 and AT&T, did not immediately comment on the issue. However, messages posted on a network administrators' mailing list indicated that those companies were also upgrading their networks.

Bruce Schneier, a noted security expert and chief technology officer for network monitoring service provider Counterpane Internet Security, wasn't ready to ring the alarm bell, however.

"Could it be a problem? Of course, it could be a problem, but so could the other 30 vulnerabilities that have been announced this week," he said.

While it's difficult to gauge how critical the glitch is, he added, any issue with the Internet backbone--the large communications channels that connect different areas of the Net--should be taken seriously.

advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Cisco Systems (2.41%) 0.36 15.32
Level 3 Communications (-4.76%) -0.04 0.80
AT&T (4.01%) 1.08 28.04
Dow Jones Industrials (3.31%) 270.00 8,419.09
S&P 500 (3.99%) 32.60 848.81
NASDAQ (3.70%) 51.73 1,449.80
CNET TECH (3.64%) 36.93 1,051.13
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right
  • Business Tech

    IPOs a thing of the past?

    At AlwaysOn Venture Summit West conference, investment bankers, venture capitalists, and private equity players weigh in on the prognosis for the IPO market.

  • Gallery

    Photos: Space station marks a decade aloft

    The first pieces of the International Space Station went into orbit 10 years ago. Now a full-fledged lab facility, it continues to grow.

  • Security

    Apple deletes Mac antivirus suggestion

    Apple removes statement to customers urging them to use antivirus software, saying that Macs are safe "out of the box."

  • Beyond Binary

    Microsoft expands Vista SP2 testing

    Starting on Thursday, the software maker will make public a test version of the service pack update to Vista.

  • Video

    A toast to online wine A toast to online wine
  • Digital Media

    EFF, Bush administration spar over telecom immunity

    Feds tell district judge government must be allowed to protect the heartland. EFF says that is fine, but don't strip away constitutional rights.

  • Video

    Wi-Fi while you fly Wi-Fi while you fly
  • Gaming and Culture

    From Cy Young to video game fame

    Tim Lincecum, one of the best pitchers in baseball, was chosen to be the cover athlete for 2K Sports' next baseball game. On Tuesday, he did a motion-capture session for the game.

  • Green Tech

    Ta ta, Tesla

    Are the Valley-based VCs and big-wigs who back Tesla Motors really serious about asking the federal government for low-interest loans?

  • Gallery

    Photos: Top-rated reviews of the week

    Here are a few of CNET Reviews' favorite items from the past week, including Adobe suites, laptop bags, and a Panasonic flat panel TV.

  • The Download Blog

    Music and browsing take flight in Songbird

    Music and browsing mashup Songbird has kicked the remnants of its shell to the curb, and the program's main emphasis as a music browser couldn't be more clear.

  • Green Tech

    Ford accelerates electric-vehicle plans

    In its turnaround plan presented to Congress, Ford says it will invest billions in fuel efficiency and introduce a family of hybrid-electric and all-electric cars.