Rootkit threatens Cisco routers

By Robert Vamosi and Liam Tung, ZDNet Australia
Wednesday, May 28, 2008 11:20 AM

Cisco and the security community are debating the reality of rootkits attacking the Cisco's Internetwork Operating System (IOS) after a researcher presented a proof of concept attack, which threatens Cisco routers and voice over IP phones.

At the EUSecWest conference in London, Core Security researcher Sebastian Muniz presented a proof of concept attack which he called the "Da IOS Rootkit", a binary modification to the IOS image.

"The main feature of Da IOS Rootkit is the universal password," Muniz said in an interview on the EUSecWest Web site. "Every call to the different password validation routines grant access to the user if the unique rootkit password is specified."

In anticipation of Muniz's talk, Cisco published three critical patches last week.

In response to the presentation, the company has published a set of best practices. Cisco noted that "no new vulnerability on the Cisco IOS software was disclosed during the presentation. To the best of our knowledge, no exploit code has been made publicly available, and Cisco has not received any customer reports of exploitation".

If the exploit code is made public, it could pose a further security risk to Cisco's customers, according to Chris Gatford, senior security consultant for penetration testing firm, Pure Hacking.

"If the code reaches the wild, it could be dangerous because of the lack of security attention given to Cisco's switches and routers," he told ZDNet Australia.

At the AusCERT 2008 conference on the Gold Coast last week, Cisco's chief security officer John Stewart complained that many of Cisco's customers fail to upgrade IOS, with some still operating on version 10.3, which was released on 1995, Apr. 13. The current release is version 12.4.

"I can give them the list of known vulnerabilities, but customers still don't want to touch it because it's working... I think there's a certain level of 'well it's working, don't touch it, because it's fragile, it might break'. I understand that, however I don't find it acceptable," he said.

Australian customers often avoid securing switches and routers, despite these devices offering a gateway to all network traffic.

"If I was to do a comparison of the number of assessments on operating systems versus networking hardware, I would say the OS and apps would be 90 per cent of what a customer is asking for and very few have us look at switches and routers. And once again, if you compromise a switch and router you own all those OSes, because you have access to all that sensitive traffic going in and out," Pure Hacking's Gatford said.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.

Related Whitepapers


Tech Jobs Now!

Search for your ideal tech job:

Prevent duplicates when entering data into Excel

Microsoft Office Suite

Duplicate values, when not valid entries, return erroneous summaries and totals. Here's what to do to prevent duplicates in a specific range using Excel's Validation feature.


Read more »



  • Enterprise 2.0

    Vince Casarez, vice president of product management at Oracle, explains how Web 2.0 technologies, such as tags, wikis, and mash-ups, can be applied within an organization.
    Play video


  • Nehalem Architecture

    What makes next-generation Intel® Microarchitecture (Nehalem) such a superior successor?
    Play video

 
Free the untapped potential of your IT infrastructure
Reduce bottlenecks to drive the efficiency and productivity of Business IT.
» Ultimate virtualization blade
» Scalable SAN solution
» Accelerate service delivery
On demand CRM goes strategic
CRM technology has come of age, and is now able to align with your customer strategy and grow in step with your business.

» Learn more about Oracle’s CRM Solutions




Securing a laptop, but no silver bullet

Blog thumbnail

I first met Ong Hock Sun a while back to discuss his interest in contributing to the Tech Podium blog. He had just returned from an oversea work stint, and..... by Eileen Yu

Read more »

Tags

  1. attack
  2. bank
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. u.s.
  19. viruses and worms
  20. web