Cisco reaches deal with flaw researcher

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

The dispute over a presentation on hacking Cisco Systems' router software at the Black Hat security conference culminated in a legal settlement on Thursday.

Michael Lynn, a former ISS researcher, and the Black Hat organisers agreed to a permanent injunction barring them from further discussing the presentation Lynn gave on Wednesday. The presentation showed how attackers could take over Cisco routers, a problem that Lynn said could bring the Internet to its knees.

The injunction also requires Lynn to return any materials and disassembled code related to Cisco, according to a copy of the injunction, which was filed in US District Court for the District of Northern California. The injunction was agreed on by attorneys for Lynn, Black Hat, ISS and Cisco.

Lynn is also forbidden to make any further presentations at the Black Hat event, which ended on Thursday, or the following Defcon event. Additionally, Lynn and Black Hat have agreed never to disseminate a video made of Lynn's presentation and to deliver to Cisco any video recording made of Lynn.

In his first news conference, Lynn on Thursday said that despite all the legal wrangling he faced during the past day and a half, demonstrating an attack on Cisco's router software was the right thing to do.

"I think I did the right thing. It was pretty scary, but the real important thing was there was the potential of serious problem," Lynn said. "I did not think the nation's interest was served by waiting another year when a router worm would be a serious threat."

In his presentation on Wednesday, Lynn outlined how to attack Cisco's Internetwork Operating System to gain control over the router running IOS. Cisco routers make up much of the infrastructure of the Internet. A widespread attack could badly hurt the Internet, according to experts attending Black Hat.

It is possible to actually destroy a router, which could cripple or shut down parts of the Internet or a corporate network. "It is one of those cases where software can destroy hardware, Lynn said.

IOS had been perceived to be impervious to such attacks, which is why a wake-up call was needed, Lynn said.

"Nobody really considered until Wednesday that this was possible," he said. The theft of Cisco's IOS source code also increases the chances that criminal hackers are working on exploits, he said.

Lynn acknowledged that his talk may actually help criminals in finding ways to attack Cisco routers.

"I gave maybe 5 percent of the information required to actually do what I did," he said. "The first guy who did it is sort of in some way responsible for all the other people who do it."

Several Black Hat attendees suggested that with the information provided by Lynn, skilled security researchers would have little trouble reproducing his attack.

What's important now is that Cisco fixes the underlying problem in IOS and prevents the problem in future versions of the software, Lynn said.

Lynn quit his job as a researcher at ISS to deliver the presentation after ISS had decided to pull the session. Notes on the vulnerability and the talk, "The Holy Grail: Cisco IOS Shellcode and Remote Execution," were removed from the conference proceedings by Cisco, leaving a gap in the thick book.

ISS wanted to cancel the session because the research was premature and would be presented at a later security conference, an ISS representative said Wednesday.

After the talk, Lynn retained attorney Jennifer Granick in the face of legal action by his former employer ISS and Cisco. Granick is the executive director of the Stanford Law School Centre for Internet and Society.

"Without her help I would be in some really serious trouble," Lynn said on Thursday.

Cisco said in a statement on Thursday that it is "gratified" by the agreed injunction. It prevents further discloser of information that could help create an attack on critical network infrastructure, the networking giant said in a statement.

"It is Cisco's opinion that the method Mr. Lynn and Black Hat chose to disseminate this information was not in the best interest of protecting the Internet," Cisco said.

Cisco plans to release a security advisory on the issue within the next day, it said.

The actual flaw Lynn exploited for his attack was fixed by Cisco in recent releases of IOS. Users of the latest versions are not vulnerable, Lynn and Cisco said. However, Lynn cautioned in his talk on Wednesday that new IOS flaws could be exploited for similar wide-ranging attack.

Talkback

I ask readers accross the Internet to write to John T. Chambers, President of Cisco Systems regarding Black Hat confrence and Michael Lynn Saga. since then Things at Cisco systems moved in the negative direction. Among the negative happenings at Cisco the following stand out. 1. Cisco used its legal Muscle for Lynn to voluntarily agree to a permanent Injunction, 2. agree to refrain from participation at Black Hat Confrence, 3. Chambers issued a statement that Lynn was silenced because he had obtained the vital information illegally and had to be silenced, 4. Cisco issued a baa humbug patch to cure the flaw disclosed by Lynn.

This is not the way a CEO of a major Multinational should act. He can't silence a researcher after his result uncovers negative information. People can't trust Cisco. Nobody knows how good the patch, issued by Cisco is if people can't talk about if the Patch is useless. Microsoft issues daily patches to windows operating systems. I know because I'v Windows XP.

The least that Chambers should have done is to 1. vacate the temporary Injunction, 2. Hired the researcher Michael Lynn back and 3. assured the world that he is as concerned about the matter as Michael Lynn is.

John T Chambers can't be trusted. He has to go, not Michael Lynn the researcher.

I ask every reader to write to John T Chambers asking him to resign as Cisco CEO and telling him you are writing to every Director to fire him if he does not resign.

I'm listing below the names of every Director of Cisco Systems and his Assress. Please write asking him to fire Jon T. Chambers if he does not resign.

Address of John T Chambers, CEO Cisco Systems, 170 West Tasman Drive, San Jose, CA 95134-1706

His Telephone number 408-526-4000

Names and Addresses of Director of the Board of Cisco Systems

1. Jerry YANG, Yahoo Co-founder 701 1st ave, Sunnyvale, CA 94089

2. Donald T Valentine, Partner and Co-founder of Sequoia Capital, 3000 Sandhill Rd Building 4, Suite 180, Menlo Park CA 94025

3. Steven M. West, Partner and Founder of Emerging Company Partners LLC 551 Lantern Court, Incline Village, NV 89451

4.Richard M. Kovalevich, Director, C/O Barclays Global Systems, 45 Freemont St, 17th Floor, San Francisco, CA 94106

5. John P. Morgridge, C/O Cogent Communications Group
1015 31 St, Washington DC20007

6. Roderick C. McGeary, 1676 International Dr, McLean, VA22102

7. James T. Gibbons, 10001 Louisiana St, Houston, TX 77002, second Address Professor, Research, Electrical Engineering Dept., Stanford University, Stanford, CA 94305

8. Michele M Burns, Exec VP, Mirant Corp., 1155 Perimeter Center West Atlanta, GA 30308

9. Carol Bartz, C/O Auto Desk, INC., 111 Mc Innis Parkway, San Rafael, CA 94903

10. John L. Hennessy, President, Stanford University, Stanford, CA 94305

11. James C. Morgan, Chairman, Applied Materials, 3050 Bowers Ave, Santa Clara, CA 95054

Please also write to the following parties that have voting agreemebts with Cisco for election of Directors:

1. H. Perry Barth, Chief Accounting Officer, NetSolve,
2.Jeffery Guillot, Vice President Development, NetSolve
3. Russel Sellers, Product Development, NetSolve
4. Jerry J. Quade, VP Human Resource, NetSolve
6. Richard Hamilton, VP, Service and Delivery, NetSolve
7. David P. Hood, CEO, NetSolve
8. Gregory K. Jones, VP Sales, Net Solve
9. Michael Guillard, Cornerstone Mgmt Profit Sharing Plan, P.O. box 1203, Menlo Park, CA 94026
10. John McCarthy, Gateway Venture Partnership 8000 Maryland Ave #1190, St. Louis, MO 63105
111.Guillard Family Trust, P.O. Box 1203, Menlo Park, CA 94026
12. George N Gregoise, Rancher, Editor, Columnist, CIO Magazine
13.Spectra Enterprise Resource LP, 1119 St. Paul St., Baltimore, MD 21202
14.Howard D.Wolfe Jr., General Partner of Venture Partners I LP; New Venture Partners LP, New VEnture Partners II and III LP, 1119 St. Paul, Baltimore, MD 21202
15. James J. Zucco, Corzente, Inc., 444 Madison Ave,

via Facebook 30 July, 2005 21:54
Reply

I ask readers accross the Internet to write to John T. Chambers, President of Cisco Systems regarding Black Hat confrence and Michael Lynn Saga. since then Things at Cisco systems moved in the negative direction. Among the negative happenings at Cisco the following stand out. 1. Cisco used its legal Muscle for Lynn to voluntarily agree to a permanent Injunction, 2. agree to refrain from participation at Black Hat Confrence, 3. Chambers issued a statement that Lynn was silenced because he had obtained the vital information illegally and had to be silenced, 4. Cisco issued a baa humbug patch to cure the flaw disclosed by Lynn.

This is not the way a CEO of a major Multinational should act. He can't silence a researcher after his result uncovers negative information. People can't trust Cisco. Nobody knows how good the patch, issued by Cisco is if people can't talk about if the Patch is useless. Microsoft issues daily patches to windows operating systems. I know because I'v Windows XP.

The least that Chambers should have done is to 1. vacate the temporary Injunction, 2. Hired the researcher Michael Lynn back and 3. assured the world that he is as concerned about the matter as Michael Lynn is.

John T Chambers can't be trusted. He has to go, not Michael Lynn the researcher.

I ask every reader to write to John T Chambers asking him to resign as Cisco CEO and telling him you are writing to every Director to fire him if he does not resign.

I'm listing below the names of every Director of Cisco Systems and his Assress. Please write asking him to fire Jon T. Chambers if he does not resign.

Address of John T Chambers, CEO Cisco Systems, 170 West Tasman Drive, San Jose, CA 95134-1706

His Telephone number 408-526-4000

Names and Addresses of Director of the Board of Cisco Systems

1. Jerry YANG, Yahoo Co-founder 701 1st ave, Sunnyvale, CA 94089

2. Donald T Valentine, Partner and Co-founder of Sequoia Capital, 3000 Sandhill Rd Building 4, Suite 180, Menlo Park CA 94025

3. Steven M. West, Partner and Founder of Emerging Company Partners LLC 551 Lantern Court, Incline Village, NV 89451

4.Richard M. Kovalevich, Director, C/O Barclays Global Systems, 45 Freemont St, 17th Floor, San Francisco, CA 94106

5. John P. Morgridge, C/O Cogent Communications Group
1015 31 St, Washington DC20007

6. Roderick C. McGeary, 1676 International Dr, McLean, VA22102

7. James T. Gibbons, 10001 Louisiana St, Houston, TX 77002, second Address Professor, Research, Electrical Engineering Dept., Stanford University, Stanford, CA 94305

8. Michele M Burns, Exec VP, Mirant Corp., 1155 Perimeter Center West Atlanta, GA 30308

9. Carol Bartz, C/O Auto Desk, INC., 111 Mc Innis Parkway, San Rafael, CA 94903

10. John L. Hennessy, President, Stanford University, Stanford, CA 94305

11. James C. Morgan, Chairman, Applied Materials, 3050 Bowers Ave, Santa Clara, CA 95054

Please also write to the following parties that have voting agreemebts with Cisco for election of Directors:

1. H. Perry Barth, Chief Accounting Officer, NetSolve,
2.Jeffery Guillot, Vice President Development, NetSolve
3. Russel Sellers, Product Development, NetSolve
4. Jerry J. Quade, VP Human Resource, NetSolve
6. Richard Hamilton, VP, Service and Delivery, NetSolve
7. David P. Hood, CEO, NetSolve
8. Gregory K. Jones, VP Sales, Net Solve
9. Michael Guillard, Cornerstone Mgmt Profit Sharing Plan, P.O. box 1203, Menlo Park, CA 94026
10. John McCarthy, Gateway Venture Partnership 8000 Maryland Ave #1190, St. Louis, MO 63105
111.Guillard Family Trust, P.O. Box 1203, Menlo Park, CA 94026
12. George N Gregoise, Rancher, Editor, Columnist, CIO Magazine
13.Spectra Enterprise Resource LP, 1119 St. Paul St., Baltimore, MD 21202
14.Howard D.Wolfe Jr., General Partner of Venture Partners I LP; New Venture Partners LP, New VEnture Partners II and III LP, 1119 St. Paul, Baltimore, MD 21202
15. James J. Zucco, Corzente, Inc., 444 Madison Ave,

via Facebook 30 July, 2005 21:54
Reply

I ask readers accross the Internet to write to John T. Chambers, President of Cisco Systems regarding Black Hat confrence and Michael Lynn Saga. since then Things at Cisco systems moved in the negative direction. Among the negative happenings at Cisco the following stand out. 1. Cisco used its legal Muscle for Lynn to voluntarily agree to a permanent Injunction, 2. agree to refrain from participation at Black Hat Confrence, 3. Chambers issued a statement that Lynn was silenced because he had obtained the vital information illegally and had to be silenced, 4. Cisco issued a baa humbug patch to cure the flaw disclosed by Lynn.

This is not the way a CEO of a major Multinational should act. He can't silence a researcher after his result uncovers negative information. People can't trust Cisco. Nobody knows how good the patch, issued by Cisco is if people can't talk about if the Patch is useless. Microsoft issues daily patches to windows operating systems. I know because I'v Windows XP.

The least that Chambers should have done is to 1. vacate the temporary Injunction, 2. Hired the researcher Michael Lynn back and 3. assured the world that he is as concerned about the matter as Michael Lynn is.

John T Chambers can't be trusted. He has to go, not Michael Lynn the researcher.

I ask every reader to write to John T Chambers asking him to resign as Cisco CEO and telling him you are writing to every Director to fire him if he does not resign.

I'm listing below the names of every Director of Cisco Systems and his Assress. Please write asking him to fire Jon T. Chambers if he does not resign.

Address of John T Chambers, CEO Cisco Systems, 170 West Tasman Drive, San Jose, CA 95134-1706

His Telephone number 408-526-4000

Names and Addresses of Director of the Board of Cisco Systems

1. Jerry YANG, Yahoo Co-founder 701 1st ave, Sunnyvale, CA 94089

2. Donald T Valentine, Partner and Co-founder of Sequoia Capital, 3000 Sandhill Rd Building 4, Suite 180, Menlo Park CA 94025

3. Steven M. West, Partner and Founder of Emerging Company Partners LLC 551 Lantern Court, Incline Village, NV 89451

4.Richard M. Kovalevich, Director, C/O Barclays Global Systems, 45 Freemont St, 17th Floor, San Francisco, CA 94106

5. John P. Morgridge, C/O Cogent Communications Group
1015 31 St, Washington DC20007

6. Roderick C. McGeary, 1676 International Dr, McLean, VA22102

7. James T. Gibbons, 10001 Louisiana St, Houston, TX 77002, second Address Professor, Research, Electrical Engineering Dept., Stanford University, Stanford, CA 94305

8. Michele M Burns, Exec VP, Mirant Corp., 1155 Perimeter Center West Atlanta, GA 30308

9. Carol Bartz, C/O Auto Desk, INC., 111 Mc Innis Parkway, San Rafael, CA 94903

10. John L. Hennessy, President, Stanford University, Stanford, CA 94305

11. James C. Morgan, Chairman, Applied Materials, 3050 Bowers Ave, Santa Clara, CA 95054

Please also write to the following parties that have voting agreemebts with Cisco for election of Directors:

1. H. Perry Barth, Chief Accounting Officer, NetSolve,
2.Jeffery Guillot, Vice President Development, NetSolve
3. Russel Sellers, Product Development, NetSolve
4. Jerry J. Quade, VP Human Resource, NetSolve
6. Richard Hamilton, VP, Service and Delivery, NetSolve
7. David P. Hood, CEO, NetSolve
8. Gregory K. Jones, VP Sales, Net Solve
9. Michael Guillard, Cornerstone Mgmt Profit Sharing Plan, P.O. box 1203, Menlo Park, CA 94026
10. John McCarthy, Gateway Venture Partnership 8000 Maryland Ave #1190, St. Louis, MO 63105
111.Guillard Family Trust, P.O. Box 1203, Menlo Park, CA 94026
12. George N Gregoise, Rancher, Editor, Columnist, CIO Magazine
13.Spectra Enterprise Resource LP, 1119 St. Paul St., Baltimore, MD 21202
14.Howard D.Wolfe Jr., General Partner of Venture Partners I LP; New Venture Partners LP, New VEnture Partners II and III LP, 1119 St. Paul, Baltimore, MD 21202
15. James J. Zucco, Corzente, Inc., 444 Madison Ave,

via Facebook 30 July, 2005 21:55
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

1 hour ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

9 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

11 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

12 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

14 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

15 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

16 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

17 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

17 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

18 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

20 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

1 day ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

1 day ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

1 day ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

1 day ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

1 day ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

1 day ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint