A Cisco engineer is warning of scams by hackers who hijack routers and blackmail companies to regain access.
Recounting incidents he heard at Black Hat 2008 in Washington D.C. last month, Brian Wilson, a.k.a Slimjim100 blogger, wrote: "I have heard of reports where this is happened to a large multi-site company and they where blackmailed for money to get access back to there routers ... In the case of this reported company, the cost of sending people out to password recover the routers was a lot more than the blackmailer's offer so the company paid them and then locked down the devices after they regained access." He says the incident could have been avoided using Access Control Lists and having an understanding of how the network is designed. Wilson also advises companies that have had their routers compromised in this way to reload IOS and review configs once they regain access as hackers could load non-Cisco patches to the network OS.
Read more about this story in the Brad Reese on Cisco blog.
More from Cisco Subnet: * Cisco Subnet's Top 20 Cisco Press books: How do you rate them? * Which vendors' certifications are the most popular for exam cheaters? * Cisco joins open source software body * Suspect Cisco cards being offered for sale * How to establish an architecture revision process * Ciena: A little known manufacturer that's showing the way * Security wireless networks: Using the wireless network to monitor itself * Scientific-Atlanta officially loses its name - sign of things to come for Linksys? * Salary survey says CCIE pay is slipping * Understanding MPLS label distribution * Why an economic recession could leave companies wide open to cyber attacks Go to Cisco Subnet for more Cisco news, blogs, discussion forums, security alerts, book giveaways, and more. 20 useful sites for Cisco networking professionals Network World's IT Buyer's Guide: Cisco products Subscribe to Network World's Cisco Alert, which includes a weekly digest of all Cisco Subnet items
The Cisco Subnet blog is the official blog of the Network World Cisco Subnet community, managed by Editor Linda Leung. Cisco Subnet is the independent voice of Cisco customers and is your gateway to daily Cisco news, blogs, opinion, books, prize giveaways and more. Visit the Cisco Subnet home page daily and while you are there, subscribe to the Cisco Alert e-mail newsletter, which includes news and views generated by the Cisco Subnet community as well as Cisco-related stories on Network World and elsewhere on the Web.
The opinions expressed in this Weblog are those of the writer and may not represent the opinions of Network World.
|
|
Post new comment