Go Back   Wireless and Wifi Forums > News > Newsgroups > comp.security.misc
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 07-28-2005, 05:35 AM
Imhotep
Guest
 
Posts: n/a
Default A MUST READ!!!

http://www.securityfocus.com/news/11259

-Im

Reply With Quote
  #2 (permalink)  
Old 07-28-2005, 01:55 PM
Todd H.
Guest
 
Posts: n/a
Default Re: A MUST READ!!!

Imhotep <Imhotep@nospam.com> writes:
> http://www.securityfocus.com/news/11259


Wild.

But if the guy learned or invented these attack techniques while bound
under a non-disclosure agreement, he should and likely will go down in
flames in the legal action.

--
Todd H.
http://www.toddh.net/

Reply With Quote
  #3 (permalink)  
Old 07-29-2005, 02:50 PM
Imhotep
Guest
 
Posts: n/a
Default Re: A MUST READ!!!

Todd H. wrote:

>
>
> Re: A MUST READ!!!
> From:
> Todd H. <comphelp@toddh.net>
> Date:
> Thursday 28 July 2005 09:55:48 am
> Groups:
> comp.security.misc
> References: 1
>
> Imhotep <Imhotep@nospam.com> writes:
>> http://www.securityfocus.com/n



....the kicker is they are saying that software flaws fall under IP. That is
crewed up as software flaws are unintentional....

-Imhotep

Reply With Quote
  #4 (permalink)  
Old 07-29-2005, 03:11 PM
Walter Roberson
Guest
 
Posts: n/a
Default Re: A MUST READ!!!

In article <bnrGe.54191$mC.13260@tornado.tampabay.rr.com>,
Imhotep <Imhotep@nospam.com> wrote:
:Todd H. wrote:

:>> http://www.securityfocus.com/n

:...the kicker is they are saying that software flaws fall under IP. That is
:crewed up as software flaws are unintentional....

No, Cisco is saying that information about the internal layout of
IOS is Trade Secret. The researcher's talk would have had to
describe essential features about the internal layout of IOS
in order to indicate how, given -any- buffer overflow, one could
consistantly take meaningful control of the device.

The internal layout of an operating system is valid IP.

Cisco wasn't objecting to the researcher publicising that
a single buffer overflow attack had been found: Cisco was objecting
that the researcher (who had access to NDA information) broke
NDA in revealing the internal organization of IOS to show how
classes of attacks would work against IOS.
--
The rule of thumb for speed is:

1. If it doesn't work then speed doesn't matter. -- Christian Bau

Reply With Quote
  #5 (permalink)  
Old 07-30-2005, 02:20 AM
Imhotep
Guest
 
Posts: n/a
Default Re: A MUST READ!!!

Alright, let's be 100% honest. Cisco WAS telling not to release info because
they were scared that their marketshare would suffer...They are acting like
Microsoft...what a shame I used to really like Cisco....

Walter Roberson wrote:

> In article <bnrGe.54191$mC.13260@tornado.tampabay.rr.com>,
> Imhotep <Imhotep@nospam.com> wrote:
> :Todd H. wrote:
>
> :>> http://www.securityfocus.com/n
>
> :...the kicker is they are saying that software flaws fall under IP. That
> :is crewed up as software flaws are unintentional....
>
> No, Cisco is saying that information about the internal layout of
> IOS is Trade Secret. The researcher's talk would have had to
> describe essential features about the internal layout of IOS
> in order to indicate how, given -any- buffer overflow, one could
> consistantly take meaningful control of the device.
>
> The internal layout of an operating system is valid IP.
>
> Cisco wasn't objecting to the researcher publicising that
> a single buffer overflow attack had been found: Cisco was objecting
> that the researcher (who had access to NDA information) broke
> NDA in revealing the internal organization of IOS to show how
> classes of attacks would work against IOS.



Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
HPSBMA02175 SSRT061174 rev.1 - HP OpenView Network Node Manager (OV NNM) Remote Unauthorized Read Access to Files Security Alert comp.security.misc 0 01-11-2007 07:06 PM
How best to install 2 DVD burners on one PC Pete alt.comp.hardware 12 10-15-2006 07:02 PM
[SSL-Talk List FAQ] Secure Sockets Layer Discussion List FAQ v1.1.1 Shannon Appel comp.security.misc 0 10-19-2005 04:37 AM
[SSL-Talk List FAQ] Secure Sockets Layer Discussion List FAQ v1.1.1 Shannon Appel comp.security.misc 0 08-30-2005 04:26 AM
[SSL-Talk List FAQ] Secure Sockets Layer Discussion List FAQ v1.1.1 Shannon Appel comp.security.misc 0 07-31-2005 04:25 AM


All times are GMT. The time now is 11:28 AM.


Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45