[scg-sec] Cisco Issue?

Smith, Donald Donald.Smith at qwest.com
Wed Jul 27 14:01:07 EDT 2005


Joshua Wright (a fellow sans handler) states in a comment on that
article.
Note that Mike Lynn was going to present on exploiting IOS to use
vulnerabilities in code to run arbitrary code of the attacker's
choosing. This is a huge deal, since a problem with IOS that was
formerly limited to a DoS could be leveraged to add configuration
commands to the IOS configuration, or other nasty things 



Donald.Smith at qwest.com giac 
-----Original Message-----
From: scg-sec-bounces at puck.nether.net
[mailto:scg-sec-bounces at puck.nether.net] On Behalf Of Bicknell, Leo
Sent: Wednesday, July 27, 2005 11:37 AM
To: scg-sec at puck.nether.net
Subject: [scg-sec] Cisco Issue?


http://blogs.washingtonpost.com/securityfix/2005/07/mending_a_hole_.html
 
Interesting news, and I doubt Cisco is ready to clue us in yet if it is
true. J
 



More information about the scg-sec mailing list