Cisco Systems's products will again come under scrutiny again at this year's Black Hat USA 2006 conference, which kicks off later this month in Las Vegas.
Conference organizers say that 15 new exploits will be discussed at this year's event and that two of them target NAC (Network Admission Control) and VOIP vulnerabilities that affect products from a number of vendors, including Cisco.
Security researchers, no longer as focused on digging up bugs in core Windows components, are looking for green fields, said Black Hat Director Jeff Moss.
Last year Cisco sued Black Hat conference organizers after security researcher Michael Lynn demonstrated a method for running unauthorized code on a Cisco router. It was a difficult technical achievement that had been considered impossible by some, but Cisco saw it to be a dangerous disclosure of information that could be used to harm the Internet's infrastructure.
Black Hat and Cisco settled the lawsuit after conference organizers promised not to disseminate information on Lynn's research. Lynn is not listed among this year's presenters.
However, it is unlikely that Cisco will be suing the conference this year, given that neither of the exploits target Cisco specifically. Instead they relate to underlying technologies that are used by a large number of products including Cisco's NAC and VOIP (Voice Over Internet Protocol) products.
One researcher, Ofir Arkin, the chief technology officer of Insightix Inc. will be speaking about NAC technologies "and ways to bypass them," he said in an e-mail interview. Information on Arkin's presentation can be found here.
A second presentation, given by researchers at 3Com Corp. and SecureLogix Corp. will examine the SIP (Session Initiation Protocol) used by VOIP systems. "In it, we describe and demonstrate many real-world VOIP exploitation scenarios against SIP-based systems (Cisco, Avaya, Asterisk, etc.)," the presenters wrote in a description of their talk. This description can be found here.
Researchers will disclose three exploits that take advantage of bugs in the Linux-based Asterisk PBX (private branch exchange) telephony software, conference organizers said. And as previously reported, wireless security researchers David Maynor and Jon Ellch plan to show a way of running unauthorized software on a laptop computer by manipulating buggy code in the system's wireless device driver.
Products from perennial favorites Microsoft and Oracle will also be discussed, with three Oracle exploits and four Microsoft exploits being disclosed, Black Hat said. There will also be discussion of two Linux exploits and one relating to Xerox's products.
Researchers will also demonstrate 25 new hacking tools at the show, which will also be noteworthy for its degree of friendly cooperation with technology vendors. Cisco itself is a platinum sponsor at the show, and Microsoft employees will be speaking at a track devoted entirely to the company's upcoming Windows Vista operating system.
Black Hat's Moss credits Lynn with inspiring new research work in the area of embedded devices, which be one of the hottest areas of research at this year's conference. By showing how Cisco's routers could be hacked and made to run unauthorized code just like a PC, Lynn helped change the way researchers think about many of these devices. "Once he did that, it really opened people's eyes," Moss said. "The amount of people who are now beating up on embedded devices has changed. Now the floodgates are opened."
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Email Archiving Implementation: Five Costly Mistakes to Avoid
CRM your salespeople will love
Making the Business Case for IT Consolidation
Controlling storage costs with Oracle database 11g
Data grids and service-oriented architecture
Discover the advantages of an open architecture multi-vendor network solution
Best Practice in Building an Integrated Information Management Strategy
Mimosa™ NearPoint™ for Microsoft® Exchange Server: Email Archiving 101
Zones provide focussed content from Computerworld and leading technology partners.Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
FrontRange Solutions launches HEAT Plus Mobile to reduce help desk costs and improve service management productivity 2008-12-02 15:15:00+11
AARNet Helps to Advance Indigenous Health 2008-12-02 12:44:00+11
Orbis selects Telstra International as its data centre partner for the UK, Europe and Middle East Region 2008-12-02 11:23:00+11
ComOps Deploys Corporate Performance Reporting Solution For Healthcare Test Manufacturer 2008-12-02 10:09:00+11
Mornington Peninsula Shire implements Objective to manage knowledge and deliver service excellence 2008-12-02 09:56:00+11
Delivering the Power of Choice with Microsoft Dynamics CRM
Join Ed Thompson, Research VP, featured analyst firm, Gartner, Inc., and Brad Wilson, General Manager CRM Microsoft Dynamics, for a new webcast, Delivering the Power of Choice with Microsoft Dynamics CRM, available now. Our panel will break down the best practices for getting the most out of CRM and you'll learn key recommendations you can implement in your organization. Additionally, you'll also hear Microsoft's vision for CRM.












