Entries for January, 2009

The PPDIOO network lifecycle

One of the first topic presented in the “Designing for Cisco Internetwork Solutions (DESGN)” book is about the network design methodology. This methodology is composed by six phases closely related: prepare, plan, design, implement, operate, optimize.
As show in this figure, the PPDIOO lifecycle phases are separate, yet closely related.

 

Cisco IOS: Attack & Defense

Surfing the web, I have found a nice talk on Cisco IOS Forensics and Exploits, explained during the 25C3: “Cisco IOS Attack & Defense – The State of the Art“.
What is 25C3?
The 25th Chaos Communication Congress (25C3) is the annual four-day conference organized by the Chaos Computer Club (CCC). It takes place at the bcc [...]

2 new Cisco critical vulnerabilities

On 21 January 2009, Cisco has published two new security advisories, which can be exploited by malicious people to conduct a DOS attack or a Remote control attack.
The two vulnerabilities are: Cisco Security Manager Vulnerability and Cisco Unified Communications Manager CAPF Denial of Service Vulnerability.
1) Cisco Security Manager Vulnerability
Cisco Security Manager contains a vulnerability when [...]

How to test Cisco IOS FTP Server Multiple Vulnerabilities

On 09 May 2007, Cisco published a Security advisory about multiple IOS FTP Server vulnetabilities.
Cisco IOS FTP Server is prone to multiple vulnerabilities including a denial-of-service issue and an authentication-bypass issue. Attackers can exploit these issues to deny service to legitimate users, gain unauthorized access to an affected device, or execute arbitrary code. Only IOS devices [...]

Preventing STP forwarding loops

The Spanning Tree Protocol is an OSI layer-2 protocol that ensures a loop-free topology for any bridged LAN. Spanning tree allows a network design to include spare (redundant) links to provide automatic backup paths if an active link fails, without the danger of bridge loops, or the need for manual enabling/disabling of these backup links. [...]

3 new Cisco critical vulnerabilities

Yesterday Cisco has published 3 different vulnerabilities, which can be exploited by malicious people to conduct a DOS attack or a Remote control attack.
1) Cisco ONS Platform Crafted Packet Vulnerability
The Cisco ONS 15300 series Edge Optical Transport Platform, the Cisco ONS 15454 Optical Transport Platform, the Cisco ONS 15454 SDH Multiservice Platform, and the Cisco ONS 15600 [...]

DOCSIS 3.0: Modems Over 300 Mbps

Cisco Systems is developing a cable modem that will use Broadcom’s recently announced DOCSIS 3.0 silicon to bond together eight downstream channels – letting cable providers, theoretically, pump Internet content down to subscribers at more than 300 Mbps.
According to Bekele, the idea with the eight-downstream-channel devices is to let cable operators future-proof their installed base [...]

Wireless Home Audio system

During the CES show, Cisco did just that with its new Linksys by Cisco Wireless Home Audio system, a multi-room audio solution that will be positioned as a direct – and less expensive – competitor to the Sonos multi-room wireless system.
The Wireless Home Audio system utilizes Wireless-N technology to deliver a rich audio experience to [...]

Cisco Global Site Selector Appliances DNS Vulnerability

The Cisco Application Control Engine Global Site Selector (GSS) contains a vulnerability when processing specific Domain Name System (DNS) requests that may lead to a crash of the DNS service on the GSS.
Cisco has released free software updates that address this vulnerability.
A workaround that mitigates this vulnerability is available.
Vulnerable Products
The following GSS products are affected [...]

Cisco Press Conference at CES 2009

Cisco will unveil new consumer products and initiatives during a press conference at the 2009 International Consumer Electronics Show (CES) in Las Vegas on Jan. 7, 2009. Cisco Chairman and CEO John Chambers will be joined by key Cisco executives responsible for the company’s consumer strategy to discuss how Cisco is enabling the connected life [...]