Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    Lessons to Learn from Cisco vs. Lynn

    Written by

    Larry Loeb
    Published August 12, 2005
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Cisco, those folks that make professional-style routers so beloved by Internet types, beat up a fellow trying to share some research (done while he was employed by Internet Security Systems) at the recent Black Hat security conference in Las Vegas.

      Cisco filed a request on July 27 for a temporary restraining order in the U.S. District Court for the Northern District of California against Michael Lynn and the Black Hat organizers to prevent Lynn and Black Hat from “further disclosing proprietary information belonging to Cisco and ISS,” as John Noh, a Cisco spokesman, put it.

      Noh also said, according to reports, that “It is our belief that the information that Lynn presented at Black Hat is information that was illegally obtained and violated our intellectual property rights.”

      It appears that Lynn was involved in decompiling Ciscos software for research while he was employed at ISS, and Cisco thinks that kind of activity violated their rights. Lynn delivered a talk July 27 on IOS (the Cisco OS) shellcode that showed how using a known vulnerability attack code could be run on a router if one was directly (not remotely) connected to it.

      ISS had decided two days earlier to pull the talk (at Ciscos urging), but Lynn resigned from ISS and went ahead with it anyway. The exploit involves a way using IPv6 to fool the router into thinking that it is crashing, so that it does not initiate the shutdown sequence.

      Jennifer Granick, who was the attorney for Lynn, noted on her blog that “The lawyers scrambled, and we were able to settle the case cheaply and expeditiously within 24 hours. … Mikes responsibilities under the settlement agreement are almost complete, and I expect the civil case to be dismissed very soon.” There were also reports of FBI agents on the Black Hat conference floor asking questions about Lynn.

      The flaw has been fixed in recent (since April) IOS releases, according to Cisco.

      /zimages/2/28571.gifClick here to read more reaction to the Cisco/Lynn case.

      Further compounding the situation is the tactic that ISS is using against sites that have posted a PDF file describing the exploit. They have sent a cease-and-desist letter to Richard Forno and his InfoWarrior.org site, accusing Forno of publishing stolen proprietary information. Further legal action is threatened by the letter. Forno has pulled the slides from the site.

      The big question surrounding this entire affair is: What constitutes “responsible disclosure”? Lynn thinks he should be allowed to talk about a security flaw that has been patched for months, even though it involves breaking an NDA, because of its critical nature.

      Cisco customers are concerned about having to find out the true consequences of the flaw from a third party, rather than from Cisco. Cisco comes out of this affair looking like a major bully trying to hide a problem rather than confront it. And all the attention caused by the legal fluffing around can only draw attention to what otherwise might have been a quiet tech session.

      It simply shows once again that security through obscurity will never work for anyone, not even Cisco.

      /zimages/2/28571.gifCheck out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

      Larry Loeb
      Larry Loeb

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.