Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Of hackers and ego
Don Parker, 2007-10-10

The world of computer security can often be a strange and compelling one. Many outsiders, or those with little knowledge of computers, just don’t understand the whole uproar over various issues, such as whether Microsoft Vista is more secure then Linux or Mac. It’s all moot as far as the general population is concerned. But, for those of us who work in the industry, it is just more grist for the mill.

Comments Mode:
Disagree 2007-10-10
Anonymous
Of hackers and ego 2007-10-11
furiusg
Of hackers and ego 2007-10-11
HAL
Of hackers and ego 2007-10-11
Anonymous
Of hackers and ego 2007-10-11
Anonymous
Of hackers and ego 2007-10-11
Jason Gunnoe
You misunderstand Lynn's work 2007-10-11
dragonfrog
Michael Lynn did not claim to have found an exploit in IOS. He was quite clear that he was giving his demo using an old, patched exploit, so there should be no reason for anyone to be endangered by his work.

What he was revealing was research (and very good research it was) into IOS shellcode - how to go from overflowing a buffer on a router, to actually getting your code run.

The reason Cisco didn't like this, is that they had always claimed that there was no way of running shellcode on IOS - that any buffer overflow was limited to DoS. Their vulnerability notifications reflected this. With Lynn's work in the open, they were going to have to admit that IOS was actually vulnerable to remote compromise through many of the vulnerabilities that come out.

At least, that's the idea - for an example of how Cisco continues to try to play us for fools, see Cisco's recent FUD postings to bugtraq on IRM PLC's demonstration of IOS shellcode techniques.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/454/34734#34734
Of hackers and ego 2007-10-12
Anonymous
Of hackers and ego 2007-10-12
secure_it_y
Of hackers and ego 2007-10-12
Anonymous
skillz. 2007-10-12
batz
Of hackers and ego 2007-10-13
Anonymous (1 replies)
Re: Of hackers and ego 2007-10-15
Anonymous
Of hackers and ego: Agree (mostly) 2007-10-15
Dr. Neal Krawetz
Of hackers and ego 2007-10-16
Anonymous (1 replies)
Re: Of hackers and ego 2007-10-17
Don Parker (1 replies)
Re: Re: Of hackers and ego 2007-10-18
Anonymous
Of hackers and ego 2007-10-16
IbeUID0
Of hackers and ego 2007-10-21
The Great Dongle
Of hackers and ego 2007-11-01
Anonymous
Of hackers and ego 2007-11-02
Gandalf







 

Privacy Statement
Copyright 2009, SecurityFocus