Cisco code leak
p2pnet.net News:- Cisco has been "unnaturally and unproductively quiet", says Gartner analyst John Pescatore.
"That gives the impression that they are still unsure about the scope of the breach. Or they are sure, and it’s much worse than has come out so far," he says, quoted in a ComputerWeekly.com story here.
Rumours that Cisco’s 12.3, 12.3t IOS had been hacked and source code stolen started cirulcating in the middle of the month, and a leak was later confirmed.
Cisco systems route a significant portion of Net traffic and loose IOS source code could therefore lead to serious trouble not only for Cisco, but for the Net at large.
Johannes Ullrich, the Internet Storm Center’s chief technology officer, didn’t think the situation was too worrisome.
"If you have the Windows source code, you can build it on your PC at home, where the Cisco code needs specialized hardware, so most people aren’t going to be able to compile the files," he stated.
"In a press release, Cisco said it took information security very seriously and continues to take active measures to protect its proprietary information as well as employee, customer and partner information." says UK’s The Inquirer here, going on:
"In other words Cisco has shut the door after the horse has bolted and published the combination of the stable safe on the net.
"Cisco added that since the pilfered code has been removed from the foreign Web site where it had been available for several days all was well. However, the code was spotted by several in Her Majesty’s loyal press and if hackers had not copied it themselves, they certainly would known a spotty Herbert mate who would have done it for them."






May 24th, 2004 at 6:25 pm
>>”If you have the Windows source code, you can build it on your PC at home, where the Cisco code needs specialized hardware, so most people aren’t going to be able to compile the files,” he stated.
Why compile it? If I know what the underlying program is doing, then I can write exploits to take advantage of it. Cisco is fooling themselves if they honestly believe that this is of no or limited consequence.