Black Hat: Cisco to Face Scrutiny Again


Wed, July 19, 2006

CIO

Cisco Systems’ (CSCO); products will again come under scrutiny again at this year’s Black Hat USA 2006 conference, which kicks off later this month in Las Vegas.

Conference organizers say that 15 new exploits will be discussed at this year’s event and that two of them target network admission control (NAC) and voice-over-IP vulnerabilities that affect products from a number of vendors, including Cisco.

Security researchers, no longer as focused on digging up bugs in core Windows components, are looking for green fields, said Black Hat Director Jeff Moss.

Last year, Cisco sued Black Hat conference organizers after security researcher Michael Lynn demonstrated a method for running unauthorized code on a Cisco router. It was a difficult technical achievement that had been considered impossible by some, but Cisco saw it to be a dangerous disclosure of information that could be used to harm the Internet’s infrastructure.

Black Hat and Cisco settled the lawsuit after conference organizers promised not to disseminate information on Lynn’s research. Lynn is not listed among this year’s presenters.

However, it is unlikely that Cisco will be suing the conference this year, given that neither of the exploits targets Cisco specifically. Instead they relate to underlying technologies that are used by a large number of products including Cisco’s NAC and VoIP products.

One researcher, Ofir Arkin, the chief technology officer of Insightix, will be speaking about NAC technologies "and ways to bypass them," he said in an e-mail interview. Information on Arkin’s presentation can be found here.

A second presentation, given by researchers at 3Com and SecureLogix, will examine the Session Initiation Protocol (SIP) used by VoIP systems. "In it, we describe and demonstrate many real-world VoIP exploitation scenarios against SIP-based systems (Cisco, Avaya, Asterisk, etc.)," the presenters wrote in a description of their talk. This description can be found here.

Researchers will disclose three exploits that take advantage of bugs in the Linux-based Asterisk private branch exchange telephony software, conference organizers said. And as previously reported, wireless security researchers David Maynor and Jon Ellch plan to show a way of running unauthorized software on a laptop computer by manipulating buggy code in the system’s wireless device driver.

Products from perennial favorites Microsoft (MSFT) and Oracle (ORCL) will also be discussed, with three Oracle exploits and four Microsoft exploits being disclosed, Black Hat said. There will also be discussion of two Linux exploits and one relating to Xerox’s (XRX) products.

Researchers will also demonstrate 25 new hacking tools at the show, which will also be noteworthy for its degree of friendly cooperation with technology vendors. Cisco itself is a platinum sponsor at the show, and Microsoft employees will be speaking at a track devoted entirely to the company’s upcoming Windows Vista operating system.

Continue Reading

As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.
This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make to help achieve project success.
Learn how Gartner's criteria for next generation IPS helps organizations achieve effective threat prevention despite changes in network communications, new applications, and changes in the threat landscape.
3 minute Flash video - overview of the need for and value of Configuration Control.
Cloud deployments are playing a critical role in propelling innovation for many companies. At the same time security has become the #1 one of the top concerns for IT and business leaders as they migrate into the cloud. In this webinar, learn from Accenture discusses how to recast the cloud as a "fresh chance to rethink your approach to security."
As greater numbers of datacenter servers transition from the physical to the virtual world, the components of virtualization success come to the fore. What scores of organizations have discovered is that success is derived from an optimal pairing of the right software platform with the right hardware platform.
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn about VMware customer, Navicure, and their experiences testing and evaluating the recovery manager, their progress in implementing it in their environment and their advice other customers considering using vCenter.
Many enterprises have discovered that the use of virtualization to support desktop workloads creates a range of significant benefits. These benefits include price efficiencies, improved IT management and greater agility and choice for end users.

This VMware sponsored webcast with IDC will provide both quantitative measurement of the business value -- defined as the expected ROI -- and qualitative analysis associated with the use of VMware View™. IDC will also provide an analysis of the View Composer and ThinApp™ features of VMware View, including the business value of these solutions and an overview of how they work.

Attend this webcast to learn about:
- Challenges and barriers that might impede the adoption of desktop virtualization
- Navigating roadblocks to facilitate a strategic implementation
- Optimizing qualitative and quantitative benefits to IT and your business
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all Newsletters | Privacy Policy
Resource Center