nanog mailing list archives

Re: Cisco IOS Vulnerability


From: Andy Dills <andy () xecu net>
Date: Thu, 17 Jul 2003 15:59:32 -0400 (EDT)


On Thu, 17 Jul 2003, Jack Bates wrote:


Sean Donelan wrote:
Cisco stated if they receive any reports of the exploit in the wild,
they will re-issue the advisory with the updated information.


Sendmail root exploit took less than 24 hours to craft. I suspect that
this exploit will be found within 48 hours. Enough information was
provided to quickly guess where the problem lies with IPv4 processing.

Sendmail is open source, IOS is not.

Knowing where the problem is and knowing how to exploit it are two
entirely different situations.

Andy

---
Andy Dills
Xecunet, Inc.
www.xecu.net
301-682-9972
---


Current thread: