Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Cisco, ISS file suit against rogue researcher
Robert Lemos, SecurityFocus 2005-07-27

LAS VEGAS -- Networking giant Cisco and security company Internet Security Systems filed for a temporary restraining order on Wednesday against the management of the Black Hat Conference and a security expert who told conference attendees that attackers can broadly compromise Cisco routers.

Comments Mode:
Cisco, ISS file suit against rogue researcher 2005-07-28
Anonymous
No good deed goes unpunished. ...

[ more ]  [ reply ]
Cisco, ISS file suit against rogue researcher 2005-07-28
Alexey Vesnin (2 replies)
Whatever that politicans will buy to be said about that person - I respect him. The action he've done is a rare illustration of the fact, that the work he doing is not for money, not for something else but for a deed....

[ more ]  [ reply ]
Re: Cisco, ISS file suit against rogue researcher 2005-07-28
Mike
I agree- he appears to be a man of honor and one who has priciples that he won't compromise. Bravo to him!

Mike

www.QuickTrivia.com...

[ more ]  [ reply ]
Re: Cisco, ISS file suit against rogue researcher 2005-07-28
Anonymous (1 replies)
It's probably naive to think that it was for the single good of the infrastructure. All of this publicity will play into his favor greatly. However, I don't know him and what type of person he is to make a legitimate decision on that....

[ more ]  [ reply ]
Re: Re: Cisco, ISS file suit against rogue researcher 2005-07-31
Alexey Vesnin (1 replies)
I don't know him in person too, but his act notes significantly, that he is honest and brave enough to do make his deceidion even going against all this dollar-kicking machine. The main difference between a kid and a grown-up person is that the kid is only makes it's wishes and deceidions, adn the g...

[ more ]  [ reply ]
Re: Re: Re: Cisco, ISS file suit against rogue researcher 2005-11-07
Anonymous
You sound like a 12 year old

...

[ more ]  [ reply ]
Cisco, ISS file suit against rogue researcher 2005-07-28
Anonymous (1 replies)
Im supprised Cisco would rather sue than fix their code. Its not the conduct I would expect

ljl...

[ more ]  [ reply ]
Re: Cisco, ISS file suit against rogue researcher 2005-07-31
Alexey Vesnin
Why don't Cisco fix it instead of playing PR-game? Because it's another way to charge you for sure for a new software, that will be invulnerable to this attack. Cisco doesn't works for deed - it works ONLY for money. To my great sorrow....

[ more ]  [ reply ]
no good deed? 2005-07-28
Anonymous (3 replies)
"No good deed goes unpunished" ... ?

You idiot. Lets see:

- you found a SERIOUS flaw in Cisco, while working for ISS

- you used ISS's findings to gain some ego-satisfying, yet irresponsible disclosure 'win'

- you screwed your employer and Cisco

... and you comment that it was a good deed.
...

[ more ]  [ reply ]
Re: no good deed? 2005-07-31
Alexey Vesnin (2 replies)
You've missed one stage :

- You alarmed ISS and Cisco about that SERIOUS flaw, and they're doing nothing.

.... But time is ticking - and not their, but ALL OTHER PEOPLES' businesses are under the great threat NOW....

[ more ]  [ reply ]
Re: Re: no good deed? 2005-08-01
Anonymous
As always... money prevales

...

[ more ]  [ reply ]
Re: Re: no good deed? 2005-08-01
Anonymous
As always... money prevales..also for CISCO...this will damage the value of their shares....it's like in the ancient days.. kill the messenger instead of handling the message

...

[ more ]  [ reply ]
Re: no good deed? 2005-08-03
Anonymous
I agree with you, what has happened to being honest with the one that is paying your salary....

[ more ]  [ reply ]
Re: no good deed? 2006-01-29
Anonymous
RE: >> You used ISS's findings for your own stage..

I don't think it matters who's company you work for or what 'stage' you set, if you find companies or the government playing games with critical information that threatens national security then you should bring it to the attention of the public...

[ more ]  [ reply ]
Cisco, ISS file suit against rogue researcher 2005-07-28
Anonymous (1 replies)
Why is Cisco so paranoid about the flaw. IF it is real, fix it. If Lyn lies, that will be figured out fairly fast and he will be discredited....

[ more ]  [ reply ]
Re: Cisco, ISS file suit against rogue researcher 2005-07-31
Alexey Vesnin
But time is ticking - and where is the dicreditation? I've digged the internet and found the description of that flaw. I've updated a non-production Cisco router and tried the exploit. IT WORKS. Cisco just waits to make some little additional stuff to join it all together to another expensive patch ...

[ more ]  [ reply ]
Cisco, ISS file suit against rogue researcher 2005-07-28
Anonymous (1 replies)
Its kind of funny listening to this stuff. Kind of. Its sad that the company can push so hard to hide their problems from the public - or their share holders rather - but you know stock got to sell. On the other hand the "researchers" keep giving us this story that their looking out for everyone -...

[ more ]  [ reply ]
Re: Cisco, ISS file suit against rogue researcher 2005-07-31
Alexey Vesnin
when you're trying to tell that such a big vendor have a bug and it's uneager to fix it - you can't be just anonymous. If you'll be anonymous - too many peoples won't even take a look on it....

[ more ]  [ reply ]
Cisco, ISS file suit against rogue researcher 2005-07-28
Don Parker (1 replies)
I give him credit for putting his money where his mouth is as it were. He gets my respect for risking an awful lot, for no gain. Hopefully he is not crucified by corporate America ie: Cisco. ...

[ more ]  [ reply ]
Re: Cisco, ISS file suit against rogue researcher 2005-07-31
Alexey Vesnin
I agree. He's not against just Cisco, he's against all that bored money-making machine now. Remember the story when Windows 2000 sources were published after being stolen from Microsoft? How many PR actions were taken before they considered that it can't be denied and at least major vulnerabilities ...

[ more ]  [ reply ]
Cisco, ISS file suit against rogue researcher 2005-07-28
Disenfranchised with Cisco
Economic Boycott

As an information security engineer who supports the gutsy stance that Mike has taken, I will be embarking on an economic boycott of both Cisco and ISS solutions. My economic boycott will exist as long as Cisco and ISS continue to postulate that what Mike presented was wrong and ...

[ more ]  [ reply ]
Cisco, ISS file suit against rogue researcher 2005-07-29
Anonymous (1 replies)
The actions of ISS and Cisco seem very unethical, using their lawfirms to try and keep their customers in the dark about vulnerabilities that could compromise their customers information infrastructure....

[ more ]  [ reply ]
Re: Cisco, ISS file suit against rogue researcher 2005-07-31
Alexey Vesnin
If your customer will see that you have a serious problem and you don't care about it - your customer will leave you. They're just protecting their business....

[ more ]  [ reply ]
Cisco, ISS file suit against rogue researcher 2005-07-29
Arhont Team (1 replies)
Exellent work and exellent presentation, which we managed to dig out online. If Michael is reading it, please contact us, since we want to describe the content of the presentation and more, including our own work in "Hacking Exposed: Cisco Networks".

Keep it coming!...

[ more ]  [ reply ]
Re: Cisco, ISS file suit against rogue researcher 2005-07-31
Alexey Vesnin
Let's do it! Maybe together we at least punch 'em to make some changes. Some hardware( like SLOW CPU ) in Cisco routers is bogus!!...

[ more ]  [ reply ]
Cisco, ISS file suit against rogue researcher 2005-08-02
Warguppy
Abaddon absolutely did the right thing. Cisco's position that this is fixed is absolutely incorrect. What they have done is made sure that new systems are not vulnerable from the XML vector for any new equipment. They have severely underplayed the potential for disaster here and made no active effor...

[ more ]  [ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus