- http://isc.sans.org/diary.php?date=2005-07-29
Updated July 30th 2005 01:08 UTC
>>> http://www.cisco.com/en/US/products/produc…0804d82c9.shtml
Last Updated 2005 July 29 1630 UTC
"Cisco has released the above advisory stating that all un-upgraded IPv6 configured routers are vulnerable to DOS and possible shellcode execution.
According to Cisco: all Cisco devices running any unfixed version of Cisco IOS code that supports, and is configured for, IPv6. A system which supports IPv6, if not specifically configured for IPv6, is not affected…"
EDIT/ADD: Hackers race to expose Cisco Internet flaw
- http://today.reuters.com/news/newsArticle….ET-CISCO-DC.XML
Sun Jul 31, 2005
"Computer hackers worked through the weekend to expose a flaw that could allow an attacker to take control of the Cisco Systems Inc. routers that direct traffic across much of the Internet. Angered and inspired by Cisco's attempts to suppress news of the flaw earlier in the week, several computer security experts at the Defcon computer-security conference worked past midnight Saturday to discover and map out the vulnerability. "The reason we're doing this is because someone said you can't," said one hacker… The hackers said they had no intention of hijacking e-commerce payments, reading private e-mail, or launching any of the other malicious attacks that could be possible by exploiting the flaw. Rather, they said they wanted to illustrate the need for Cisco customers to update their software to defend against such possibilities. Many Cisco customers have postponed the difficult process because it could require them to unplug entirely from the Internet…"
Cisco CCO Password Issue
- http://isc.sans.org/diary.php?date=2005-08-03
"Ever have one of those days? Looks like Cisco is having one of those months… It appears that something has happened to compromise the passwords for their Cisco Connection Online service. What exactly happened? Cisco isn't saying. Attempting to log into CCO brings up the following terse message:
'IMPORTANT NOTICE:
* Cisco has determined that Cisco.com password protection has been compromised.
* As a precautionary measure, Cisco has reset your password. To receive your new password, send a blank e-mail, from the account which you entered upon registration, to [removed]. Account details with a new random password will be e-mailed to you.
* If you do not receive your new password within five minutes, please contact the Technical Support Center.
* This incident does not appear to be due to a weakness in Cisco products or technologies…'"
… and yes, they updated their Advisory again. Now at Rev 1.6…