jim_duffy
Managing Editor

IOS vulnerability in detail

Analysis
Jun 29, 20072 mins

Technocrat is alerting Cisco users to a paper available at milw0rm.com that goes into detail about the IOS vulnerability that made Michael Lynn a controversial figure at Black Hat in 2005.

Lynn caused a stir when he disclosed information about security weaknesses in Cisco routers at the security conference. He was forced to quit his job as a researcher at Internet Security Systems in order to give the presentation and was subsequently sued by both ISS and Cisco, though the lawsuit was dropped when he agreed not to discuss contents of the presentation. He was later hired by Juniper.

According to Technocrat, the paper at milw0rm:

… is a result of research carried out by IRM to analyze and under the check_heaps() attack and its impact on similar embedded devices. Furthermore, it also helps developers understand security-specific issues in embedded environments and developing mitigation strategies for similar vulnerabilities. The paper primarily focuses on the techniques developed for bypassing the check_heaps() process, which has traditionally prevented reliable exploitation of memory-based overflows on the IOS platform. Using inbuilt IOS commands, memory dumps and open source tools IRM was able to recreate the vulnerability in a lab environment.

Go to Cisco Subnet for more Cisco news, discussion forums, security alerts, and book giveaways.