Home > Security News > Researchers warn of new attack methods against Cisco IOS
Security News:
EMAIL THIS

Researchers warn of new attack methods against Cisco IOS

By Bill Brenner, Senior News Writer
10 Oct 2007 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Cisco Systems' Internetwork Operating System (IOS) is susceptible to attacks in which hackers could cause a denial of service or launch malicious code, according to an analysis conducted by researchers at London-based Information Risk Management (IRM).

IRM Chief Research Officer Andy Davis conducted the Cisco IOS security analysis over a two-month period along with senior consultants Gyan Chawdhary and Varun Uppal. The analysis includes videos demonstrating three different shellcode techniques the researchers used to gain remote level 15 (root) exec VTY (shell) access to IOS.

Each piece of shellcode was written in PowerPC assembly language and launched from within a development environment rather than the payload to an exploit, the researchers noted, adding that the development server is connected to the Cisco router 2600 Series via a serial cable and Ethernet for TCP/IP communications. "It takes a short while for the shellcode to start functioning as it has been hooked into the IOS image checksumming routine that runs every 30-60 seconds," the researchers said. "When each starts running, the arbitrary text '' is displayed on the console to indicate successful execution of the shellcode."

Cisco news:
Does security fit into Cisco's wireless agenda? Cisco Systems has unveiled new products in recent months to fill customer demand for more wireless networking capacity. But with more threats being directed at wireless users, is Cisco ready to address security issues?

Cisco users upbeat about security direction: Cisco customers say the vendor's security strategy is headed in the right direction, which is why they believe the networking giant's IronPort integration will be smooth sailing.

Cisco warns of critical IOS flaws: Attackers could exploit multiple flaws in Cisco's IOS to cause a denial of service or remotely execute arbitrary code.

The researchers say there are numerous other IOS security issues that will be released in the near future.

Cupertino, Calif.-based Symantec Corp. found the research noteworthy enough to flag it in an advisory to customers of its DeepSight threat management service.

"A successful attack may allow an attacker to execute arbitrary code and gain unauthorized access to the device," Symantec said. "Attackers can also leverage this issue to cause an affected device to reload, denying service to legitimate users. A sustained denial-of-service condition can arise due to repeated attacks."

Judging by the limited information in the security advisory, Symantec said, it is assumed that all Cisco IOS 12.x and IOS XR versions are affected. But Symantec said it can't verify that as yet.

Kevin Petschow, a spokesman for Cisco's Product Security Incident Response Team (PSIRT), said in an email exchange that IRM approached Cisco with its findings prior to issuing its news release, and that the networking giant doesn't see this as a flaw within IOS.

"We have confirmed the information provided does not represent a security vulnerability, but rather the proof that third-party code can be injected by users who already have physical access and full privileges software access to the Cisco IOS device," he said. "The third-party code is calling existing functions within Cisco IOS in the same manner as a legitimate Cisco IOS user would do upon issuing commands."

To mitigate the threat, Symantec recommended users block external access at the network boundary unless external parties require service, and deploy network intrusion detection systems to monitor network traffic for malicious activity.



Tags: Network Device ManagementNetwork Firewalls, Routers and SwitchesVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Network Device Management
Firewall rule management best practices
What are best practices for fiber optic cable security?
Enterprise UTM security: The best threat management solution?
Making the case for network security configuration management
Know when you need IDS, IPS or both
SIEM: Not for small business, nor the faint of heart
Evaluating MSSP security before taking the plunge
Ixia network security tool exposes problems
Product Review: Deepdive's DD300
Security services: Fiberlink's MaaS360 Mobility Platform

Network Firewalls, Routers and Switches
Firewall rule management best practices
Should enterprises be running multiple firewalls?
What are the disadvantages of proxy-based firewalls?
IT pros find corporate firewall rules tough to navigate
PCI compliance requirement 1: Firewalls
Comparing an application proxy firewall and a gateway server firewall
Microsoft Threat Management Gateway has some drawbacks
Rising Profile
Front-end/back-end firewalls vs. chassis-based firewalls
How to configure a firewall to communicate with an upstream router

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
OCSP  (SearchSecurity.com)
trusted computing base  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts