- 12 myths about how the Internet works
- Smartphone smackdown: Storm vs. iPhone
- IETF: Should we ignore the Kaminsky bug?
- Top 10 wicked cool algorithms
- How to recession-proof yourself
Michael Lynn, the former Internet Security Systems researcher who disclosed information about how unpatched Cisco routers could be hacked, said he is seeking to settle with Cisco and ISS over the controversy.
More: Cisco nixes conference session on hacking IOS router code
Furor over Cisco IOS router exploit erupts at Black Hat
Cisco, ISS, Michael Lynn and Black Hat sign legal accord
Forum: Who's right?
Separately, Cisco said this Friday it plans to issue a security advisory of its own related to the issue of remote exploits of Cisco routers, which will be posted here.
Lynn, an expert in uncovering security flaws, stepped in to the limelight - and a storm of controversy - after he spoke out earlier this week about a buffer-overflow exploit that can potentially undermine routers.
In doing so, he violated the wishes of former employer ISS as well as Cisco, which had abruptly canceled the presentation, saying it was premature to present the security findings.
Facing a lawsuit from Cisco and ISS, Lynn said he entered into a legal agreement with both vendors - with much help from high-tech defense attorney Jennifer Grannick - which he hopes will let him move on with his life and find another job.
But in a room full of reporters at the Black Hat conference, Lynn offered his own impression of the events that had led to the furor, which also included legal action by Cisco and ISS against the Black Hat conference.
Lynn told reporters at Black Hat that despite the complications it caused him and the fact it “was pretty scary,” he still feels he “did the right thing” in revealing what he had discovered in researching exploits associated with unpatched Cisco routers.
“I didn’t think the nation’s interest was served in waiting another year when a router worm would mean a serious threat,” he said of his decision to quit his job at ISS and reveal what he knew.
He said Cisco knew about the underlying vulnerability before he did, sometime in February, and fixed it with a patch in April. Lynn’s research examined how buffer-overflow exploits could undermine routers that aren’t patched.
Lynn admitted that he did engage in a “bit of deception” when he told Jeff Moss, CEO of Black Hat, that he would talk about voice over IP as a substitute presentation when ISS and Cisco canceled the original topic on the Cisco ISO shellcode and exploits.
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comment