On TV.com: Why Is Everyone in TV High School SO OLD
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Jul 27, 2005 11:55:00 PM

LAS VEGAS--Cisco Systems has taken legal action to keep a researcher from further discussing a hack into its router software.

The networking giant and Internet Security Systems jointly filed a request Wednesday for a temporary restraining order against Michael Lynn and the organizers of the Black Hat security conference. The motion came after Lynn showed in a presentation how attackers could take over Cisco routers--a problem that he said could bring the Internet to its knees.

The filing in U.S. District Court for the Northern District of California asks the court to prevent Lynn and Black Hat from "further disclosing proprietary information belonging to Cisco and ISS," said John Noh, a Cisco spokesman.

"It is our belief that the information that Lynn presented at Black Hat this morning is information that was illegally obtained and violated our intellectual property rights," Noh added.

Lynn decompiled Cisco's software for his research and by doing so violated the company's rights, Noh said.

The legal moves came Wednesday afternoon, only hours after Lynn gave the talk at the Black Hat security conference here. Lynn told the audience that he had quit his job as a researcher at ISS to deliver the presentation, after ISS had decided to pull the session. Notes on the vulnerability and the talk, "The Holy Grail: Cisco IOS Shellcode and Remote Execution," were removed from the conference proceedings, leaving a gap in the thick book.

Lynn outlined how to run attack code on Cisco's Internetwork Operating System by exploiting a known security flaw in IOS. The software runs on Cisco routers, which make up the infrastructure of the Internet. A widespread attack could badly hurt the Internet, he said.

The actual flaw he exploited for his attack was reported to Cisco and has been fixed in recent releases of IOS, experts attending Black Hat said.

The ISS research team, including Lynn, on Monday decided to cancel the presentation, Chris Rouland, chief technology officer at ISS, said in an interview. "It wasn't ready yet," he said. Lynn resigned from ISS on Wednesday morning and delivered the presentation anyway, Rouland added.

Lynn presented ISS research while he was no longer an employee, Rouland said.

Adding to the controversy, a source close to the Black Hat organization said that it wasn't ISS and Lynn who wanted to cancel the presentation, but Cisco. Lynn was asked to give a different talk, one on Voice over Internet Protocol security, the source said.

But ISS' Rouland said there "was never a VoIP presentation" and that Wednesday's session was supposed to be cancelled altogether.

"The research is very important, and the underlying work is important, but we need to work with Cisco to determine the full impact," Rouland said.

Cisco was involved in pulling the presentation, a source close to the company said. The networking giant had discussions with ISS and they mutually agreed that the research was not yet fully baked, the source said.

The demonstration on Wednesday showed an attack on a directly connected router, not a remote attack over the Internet. "You could bring down your own router, but not a remote one," Rouland said.

One Black Hat attendee said he was impressed with Lynn's presentation. "He got a shell really easy and showed a basic outline how to do it. A lot of folks have said this could not be done, and he sat up there and did it," said Darryl Taylor, a security researcher. "Shell" is a command prompt that gives control over the operating system.

Noh said that Lynn's presentation did not disclose information about a new security vulnerability or new security flaws. "His research explored possible ways to expand the exploitation of existing vulnerabilities affecting routers," the Cisco spokesman said.

Cisco has patched several flaws in IOS over the past year. Last year, the San Jose, Calif., networking giant said that part of the IOS source code had been stolen, raising fears of more security bugs being found.

On Wednesday, Noh reiterated the company's usual advice that customers upgrade their software to the latest versions to mitigate vulnerabilities.

Following his presentation, Lynn displayed his resume to the audience and announced he was looking for a job. Lynn was not available for comment. Representatives of the Black Hat organization said the researcher was meeting with lawyers.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 68 Talkback(s)
Both Cisco and BHS are right from there point of view
From BHS point of view they did the right thing by disclosing the security issues although not completely at the conference.
On the other hand, the intellectual property rights of cisco cannot be d... (Read the rest)
Posted by: alfresco_0101@... Posted on: 08/04/05 You are currently: a Guest | | Terms of Use
"not yet fully baked"  Roving_Reporter | 07/28/05
"Baked"  htotten | 07/28/05
Please...  ArtMac | 07/28/05
Please...give me a break  TN-Limey | 07/28/05
Lynn a criminal???  tonkica | 07/28/05
Yup  TN-Limey | 07/28/05
Just food for thought for a second  Xbeing | 07/28/05
Ummm...  ArtMac | 07/28/05
half-baked  linuxoverwindows | 07/28/05
java_p-your're stupid  phi_alpha_nu@... | 07/28/05
The issue  brichter | 07/28/05
Whistle Blower  wolf_z | 07/28/05
What if Microsoft did this?  jbburks | 07/28/05
No yawning here  John L. Ries | 07/28/05
have you hacked a cisco today?  linuxoverwindows | 07/28/05
IP violation  Carrion | 07/28/05
Are you quite certain?  dalecosp | 07/28/05
I'm sure a real hacker...  el1jones | 07/28/05
Flaws  Carrion | 07/28/05
Read the facts.  jnoble@... | 07/28/05
YOU read the facts  brichter | 07/28/05
Analogy issue here  Xbeing | 07/28/05
what is a r00ted box?  linuxoverwindows | 07/28/05
15 minutes.  jpfitz@... | 07/28/05
re:15 minutes  deepee912 | 07/28/05
If he is a hero  Xbeing | 07/28/05
If it's no big deal...  el1jones | 07/28/05
Get a clue  jnoble@... | 07/28/05
Whistle-blower, my a$$  brichter | 07/28/05
Why a 1 vendor solution is stupid  ITGuy04 | 07/28/05
Cisco certification  itpro_z | 07/28/05
Cisco certification  Loverock Davidson | 07/28/05
i need an employer that will pay for those happy  linuxoverwindows | 07/28/05
hear! hear!  linuxoverwindows | 07/28/05
Well...  ArtMac | 07/28/05
Well ...  dalecosp | 07/28/05
Yep, right here...  Grimm Reaper | 07/28/05
lol  linuxoverwindows | 07/28/05
MS Bashers  Too Old For IT | 07/28/05
Maybe they are too smart  ebrke | 07/28/05
IOS  jnoble@... | 07/28/05
Cisco hits back  Mugsy_z | 07/28/05
Let's keep such things underground, shall we?  Sxooter_z | 07/28/05
wink  dalecosp | 07/28/05
sure, cause then...  linuxoverwindows | 07/28/05
This is why all software should be Open Source  kokuryu | 07/28/05
Open Source Presumption  Too Old For IT | 07/28/05
Right ...  gary.douglas@... | 07/28/05
Easy picking.  papatator | 07/28/05
Bad News Supression  John L. Ries | 07/28/05
Hmm, that's an interesting thought....  dalecosp | 07/28/05
Security by Obscurity  Dr_Zinj | 07/28/05
Did I miss something?  Xbeing | 07/28/05
Thanks  TN-Limey | 07/29/05
when you use the law to cover your sorry butt  toxicfreak | 07/28/05
what??  sirsully | 07/28/05
Re: when you use the law to cover your sorry butt  webster_z | 08/01/05
Cisco and the jerk  TN-Limey | 07/28/05
He didn't reveal anything new  george_ou | 07/28/05
Why  TN-Limey | 07/28/05
Right on, Limey - Re: Cisco and the jerk  webster_z | 08/01/05
If one can figure it out anybody can  xkmail | 07/28/05
Black Hat to be commended for efforts to expose cisco and all other flaws  samm_z | 07/28/05
Are they 'bugs' or 'humans'?  mtn.brk@... | 07/28/05
non-disclosure  sandbagger | 07/28/05
Learn that which you speak about  jnoble@... | 07/28/05
cisco, injunction  jef124c41 | 07/29/05
Both Cisco and BHS are right from there point of view  alfresco_0101@... | 08/04/05

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline