Cisco says FTP feature in IOS is a hacker backdoor
- 14 May, 2007 08:32
- Comments
Cisco says a flaw in the FTP server utility in its IOS router/switch software could be used as a backdoor by attackers.
IOS FTP, which comes disabled by default in IOS, is used to upload IOS software images and other software to routers and switches remotely. However, Cisco says attackers could exploit a vulnerability in the FTP server to gain access to the file system of an IOS-based router or switch and affect configuration settings.
"Unauthorized users could retrieve the device's startup-config file from the filesystem," Cisco says. "This file may contain information that could allow the attacker to gain escalated privileges."
Cisco is offering customers software fixes with the FTP server removed from IOS.
In the meantime, Cisco says users should shut down IOS FTP if they are running the server on an affected system. (The command to do this is "no ftp-server enable".) The company says users can upload software to IOS devices through other methods, such as the "Secure Copy" feature in the software. Users can also set up access control lists to restrict FTP access to a router or switch, Cisco adds.
The affected IOS versions are: 11.3, 12.0, 12.1, 12.2, 12.3 and 12.4. Cisco's IOS XR is not vulnerable, and non-IOS Cisco devices are also safe. Cisco says it will remove the FTP feature in IOS because of this, and other past issues with the code. The company says it may add a secure FTP server to IOS in the future.
- Bookmark this page
- Share this article
- Got more on this story? Email Computerworld
- Follow Computerworld on twitter
- Blurring boundaries: The disappearing gap between work and home life
- IBM zEnterprise System Brings Hybrid Computing Capabilities to Midsize Organisations
- Demonstrating Return on Investment with Enterprise-Class Identity and Access Management Technology
- Eight things senior managers need to know about data encryption
- Reducing Costs Through Better Server Utilisation
- iPhone 5 rumour rollup for the week ending February 10
- 3D mapping revives underwater city
- Academic challenges Turnbull over NBN satellite criticism
- What are you saying: Telstra’s customer service slowly improving, SA minister urging Facebook to overturn its photo ban
- In pictures: Capgemini opens new Canberra office
-
After Megaupload shuts, BTJunkie follows
-
Windows Event Viewer phishing scam remains active
-
NeuroSky MindWave: Fun with Brainwaves
-
20 popular Ubuntu Linux apps you may want to try
-
Nokia N9: Why you shouldn't buy this device
-
Embedded System Design
-
Objects, Data Structures and Abstraction Using C++ WileyPlus Standalone Registration Card
-
Java 2 Exam Notes
-
Discovering Requirements - How to Specify Products and Services
-
Mastering AutoCAD 2002 (Includes CD-ROM)
-
Professional Apache Geronimo
-
Software Evolution and Feedback - Theory and Practice
-
Hacking the Psp
-
DOS for Dummies Quick Reference, 3rd Edition












Comments
Post new comment