Security experts view Black Hat as the premier event to discuss and explore Internet vulnerabilities. At this year’s event, Michael Lynn, a member of ISS’ X-Force R&D team, gave a talk Wednesday on vulnerabilities in Cisco’s IOS, but he did so only after resigning from ISS, according to a company spokesperson.
Lynn is MemeStreams user abaddon. Cisco’s statement added that Lynn’s presentation was not a disclosure of a new vulnerability or a flaw with Cisco IOS software, but an exploration of “ways to expand exploitations of existing security vulnerabilities impacting routers.”
Cisco PR is spinning at top speed right now. Lynn did infact demonstrate the remote injection of shellcode to a Cisco router. Lynn is able to make a Cisco router connect back to his attack host with an enable shell. For those unfamilar with Cisco routers, that basically means its possible to hack the router and get full control of it. This is not a DoS attack. This is a full on compromise. This is basically the bug that could be used to take down the Internet. No bullshit. Abaddon Drops The Bomb on Cisco |