Cisco ISO leak
p2pnet.net News:- Johannes Ullrich, the Internet Storm Center’s chief technology officer, doesn’t think the now confirmed leak of Cisco IOS source code is too worrisome.
In fact, Cisco is in better shape than Microsoft which in February had source code for parts of its Windows 2000 and Windows NT stolen, he says, quoted in a ZDNet story here.
"If you have the Windows source code, you can build it on your PC at home, where the Cisco code needs specialized hardware, so most people aren’t going to be able to compile the files," states Ullrich.
ZDNet also has spokeswoman Mojgan Khalili saying, "It appears that this occurrence was not the result of any exploitation or a vulnerability in any product or service offered by Cisco to its customers, nor do we have any reason to believe that it was the result of any malicious action by any Cisco employee or contractor."






May 18th, 2004 at 3:42 pm
You don’t need hardware to look at the source code for potential attack points either.
May 18th, 2004 at 4:57 pm
its called damage control and soothing the masses, very similar to the recent vuln in the TCP/IP protocol and how it was handled. Can’t have us panicking now can they
May 19th, 2004 at 7:59 am
I think he means IOS leak surely?!
It’s about time Cisco got hit, they ARE the Microsoft of the networking business.
May 19th, 2004 at 11:59 am
Not quite “the” Microsoft, more “the” IBM.
They have their share of urbis, but unlike M$, Cisco can (sometimes) pick a good idea, buy the company and make it a very good thing (TM) instead of just killing it. It was like this with VOIP IP Phones, they bought a company (can’t remember the name) and in 6/12 mounths Cisco had VOIP in almost all platforms and the IP Phones were selling like crazy. We all know what M$ uses to do…
Oh! And Cisco have a hell of a support. They really try to help you, and if you move enough $$$ they even make customized IOS versions for you (aka “fix THAT bug in THAT version with THIS set of features).
It’s easy to think that CISCO and Microsoft are alike just because both are trying for world domination in their fields.
Without the compilers, linkers and all the libs I don’t belive that the code helps THAT much in finding vulnerabilities. If “they” got everything and “they” can build and run IOS versions at will than yes, but if all “they” can do is look at the source code than I don’t think we’ll be seeing an outburst of Cisco vuln soon.