nanog mailing list archives
Re: Cisco IOS Exploit Cover Up
From: Florian Weimer <fw () deneb enyo de>
Date: Thu, 28 Jul 2005 17:52:59 +0200
Lynn's statement would tend to make one believe that this is yet another example of a vulnerability that is awaiting an exploit, not one that has yet to be discovered -- a sort of Sword of Damocles, if you will...
I think he's just pointing out that the risk assessments of many network operators are way off. Some postings to this list certainly suggest that. Too many people seem to have forgotten the work done by Phenoelit. Maybe their exploits leave something to be desired, but, as the saying goes, attacks only get better. In other words, it's not about a single vulnerability. It's about a widespread belief in the invincibility of IOS. And, to be honest, I'm scared how many people subscribe to that religion. Such irrationality puts networks at risk, far more than any single vulnerability could.
Current thread:
- RE: Cisco IOS Exploit Cover Up, (continued)
- RE: Cisco IOS Exploit Cover Up Fergie (Paul Ferguson) (Jul 27)
- Re: Cisco IOS Exploit Cover Up Jeff Kell (Jul 27)
- Re: Cisco IOS Exploit Cover Up Daniel Golding (Jul 27)
- Re: Cisco IOS Exploit Cover Up Network Fortius (Jul 27)
- Re: Cisco IOS Exploit Cover Up Jason Frisvold (Jul 28)
- Re: Cisco IOS Exploit Cover Up Dan Hollis (Jul 28)
- Re: Cisco IOS Exploit Cover Up Jeff Kell (Jul 27)
- RE: Cisco IOS Exploit Cover Up Fergie (Paul Ferguson) (Jul 27)
- Re: Cisco IOS Exploit Cover Up Florian Weimer (Jul 28)
- RE: Cisco IOS Exploit Cover Up Geo. (Jul 28)
- RE: Cisco IOS Exploit Cover Up Randy Bush (Jul 28)
- RE: Cisco IOS Exploit Cover Up John A. Kilpatrick (Jul 28)
- Re: Cisco IOS Exploit Cover Up James Baldwin (Jul 28)
- Re: Cisco IOS Exploit Cover Up Randy Bush (Jul 28)
- Re: Cisco IOS Exploit Cover Up James Baldwin (Jul 28)
