[NEWS] Cisco IOS Exploitation Techniques (Black Hat, Michael Lynn)

SecuriTeam <[email protected]> 1 Aug 2005 18:42:08 +0200
Newsgroups gmane.comp.security.securiteam
Message-ID <[email protected]>
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html 

- - - - - - - - -



  Cisco IOS Exploitation Techniques (Black Hat, Michael Lynn)
------------------------------------------------------------------------


SUMMARY

Cisco IOS (originally Internetwork Operating System) is the operating 
system used on Cisco Systems routers and some network switches. It is a 
multitasking operating system and provides kernel services such as process 
scheduling as well as the command line interface and routing software.

Mike Lynn, former researcher for Internet Security Systems (ISS), spoke at 
the Black Hat security conference in Las Vegas about a serious 
vulnerability that he found while reverse-engineering the operating system 
in Cisco routers.

DETAILS

Cisco Systems and ISS prevented Lynn and the Black Hat conference 
organizers to publish this presentation and forced to remove it from 
conference material. The material however, can be found at the following 
link:  <http://www.security.nnov.ru/files/lynn-cisco.pdf> 
http://www.security.nnov.ru/files/lynn-cisco.pdf.


ADDITIONAL INFORMATION

The original article can be found at:  
<http://www.security.nnov.ru/Fnews57.html> 
http://www.security.nnov.ru/Fnews57.html



======================================== 


This bulletin is sent to members of the SecuriTeam mailing list. 
To unsubscribe from the list, send mail with an empty subject line and body to: [email protected] 
In order to subscribe to the mailing list, simply forward this email to: [email protected] 


==================== 
==================== 

DISCLAIMER: 
The information in this bulletin is provided "AS IS" without warranty of any kind. 
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.