Follow Us

Cisco puts question mark over claimed hack

Can't reproduce "really easy" firewall problem.

Cisco has called into question the existence of a "really easy" hack of its firewall software by announcing it has been unable to reproduce the claimed hack.

The alleged flaw was discovered by Hendrik Scholz, a developer with Freenet Cityline, who discussed it in a presentation at the Black Hat USA conference earlier this month.

Scholz claimed that if someone sent the PIX device a specially-crafted SIP message, the firewall would then allow attackers to send traffic to any device on the network.

"We've had engineers both within the business unit and within our PSIRT (product security incident response team) organisation looking into this," said John Noh, a Cisco spokesman. "We have not been able to replicate what he claims he has discovered."

Cisco had not ruled out the possibility that a flaw exists and is still testing its security appliances for a possible vulnerability, Noh said. But the company wanted to update customers on what it had found so far, he explained.

"This is just a response for the benefit of our customers who might have seen the press coverage."

Scholz could not be reached immediately for comment. During his presentation, the security researcher said exploiting the flaw was "really easy to do." But in an e-mail interview conducted a week later, Scholtz said that a hacker would first need to know "intimate details" about the network being attacked and have control of a device on the inside in order to pull off the attack.






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

State of software security report volume 4

If your business has anything worth protecting, be it money, intellectual property or a trusted...

Download Whitepaper

New threats demand innovative responses

Financial institutions in the UK remain susceptible to further systemic problems, as challenging...

Download Whitepaper

Delivering a competitive advantage through IT

IT organisations share a common mission; to optimise investments and streamline operations to...

Download Whitepaper

6 tips to mobilise your existing ERP

Enterprise mobile users throughout the global business community will number 1.19 billion by...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Awards

Techworld Awards Winners 2011


Learn who the winners of this year's Techworld Awards are. Video footage coming soon...

Find out more
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

Site Map

* *