Cisco can't reproduce Black Hat flaw
- 15 August, 2006 11:00
- Comments
Cisco Systems has been unable to reproduce a security flaw reported in its PIX firewall appliance earlier this month, the networking company said Tuesday.
The alleged flaw was discovered by Hendrik Scholz, a developer with Freenet Cityline, who discussed it during Aug. 2 presentation at the Black Hat USA conference in Las Vegas. Freenet is a German VOIP (voice over Internet Protocol) service provider.
Scholz claimed that if someone sent the PIX device a specially crafted SIP (Session Initiation Protocol) message, the firewall would then allow attackers to send traffic to any device on the network. SIP is a protocol used to set up telephone calls and other communication sessions over the Internet.
"We've had engineers both within the business unit and within our PSIRT [product security incident response team] organization looking into this," said John Noh, a Cisco spokesman. "We have not been able to replicate what he claims he has discovered."
Cisco had not ruled out the possibility that a flaw exists and is still testing its security appliances for a possible vulnerability, Noh said. But the company wanted to update customers on what it had found so far, he explained. "This is just a response for the benefit of our customers who might have seen the press coverage."
Scholz could not be reached immediately for comment.
During his Black Hat presentation, the security researcher said that exploiting the flaw was "really easy to do." But in an e-mail interview conducted two weeks ago, Scholtz said that a hacker would first need to know "intimate details" about the network being attacked and have control of a device on the inside in order to pull off the attack.
The problem, as Scholtz described it, had to do with the PIX SIP state engine and parser.
Cisco's comments on Scholtz's findings can be found athttp://www.cisco.com/warp/public/707/cisco-sr-20060815-sip.shtml.
- Bookmark this page
- Share this article
- Got more on this story? Email Computerworld
- Follow Computerworld on twitter
- 3D mapping revives underwater city
- Academic challenges Turnbull over NBN satellite criticism
- What are you saying: Telstra’s customer service slowly improving, SA minister urging Facebook to overturn its photo ban
- In pictures: Capgemini opens new Canberra office
- Power profiles to help electronics go Green
-
Windows Event Viewer phishing scam remains active
-
NeuroSky MindWave: Fun with Brainwaves
-
20 popular Ubuntu Linux apps you may want to try
-
Nokia N9: Why you shouldn't buy this device
-
Microsoft at a loss over Event Viewer scam
-
Office 2007 All-In-One Desk Reference for Dummies
-
Windows 7 for Seniors for Dummies®
-
Microsoft Office
-
Windows 7 for Dummies® Dvd+book Bundle
-
MYOB Software for Dummies 6E Australian Edition
-
Windows 7 for Dummies®
-
Computers for Seniors for Dummies, 2nd Edition
-
Office 2007 for Dummies
-
Teach Yourself Visually Windows 7












Comments
Post new comment