RE: Free Cisco security web seminar on IPV4 DoS today 7/18

From: Charles Church (cchurch@wamnet.com)
Date: Fri Jul 18 2003 - 12:37:10 GMT-3


A friend of mine who's an AT&T customer told me they went through and
upgraded all their routers last night and this morning. Hope they've got a
decent TFTP or FTP server...

Chuck Church
CCIE #8776, MCNE, MCSE
Wam!Net Government Services
13665 Dulles Technology Dr. Ste 250
Herndon, VA 20171
Office: 703-480-2569
Cell: 703-819-3495
cchurch@wamnet.com
PGP key: http://pgp.mit.edu:11371/pks/lookup?search=chuck+church&op=index

-----Original Message-----
From: nobody@groupstudy.com [mailto:nobody@groupstudy.com]On Behalf Of
Jay Hennigan
Sent: Friday, July 18, 2003 10:25 AM
To: Paul Borghese
Cc: ccielab@groupstudy.com
Subject: Re: Free Cisco security web seminar on IPV4 DoS today 7/18

On Fri, 18 Jul 2003, Paul Borghese wrote:

> Hi Everyone,
>
>
>
> Global Knowledge is offering a free seminar on the new IPv4 DoS
> vulnerability. I have been allowed to invite the GroupStudy members to
the
> seminar as I think some of you will find it interesting. Here is the
> complete invite:
>
>
>
> Foundstone Security Briefings:
>
> Cisco IPv4 Remote Denial of Service Vulnerability

snippage...

> This vulnerability should be considered extremely critical due to the
impact
> and ease-of-exploitation. Devices are vulnerable to a Denial of Service
> (DoS) attack and although no known exploit has been yet identified, a
> complex purposely malicious sequence of IPv4 packets targeted to a
> vulnerable Cisco switch or router can cause the processing interface to
stop
> processing traffic.

The above is no longer true, an exploit has been identified and publicly
posted. And the script kiddies are already rattling doorknobs, we're
seeing it hit random IPs. Time to hack out an IDS signature...

http://lists.netsys.com/pipermail/full-disclosure/2003-July/011420.html
http://lists.netsys.com/pipermail/full-disclosure/2003-July/011421.html

--
Jay Hennigan - CCIE #7880 - Network Administration - jay@west.net
WestNet:  Connecting you to the planet.  805 884-6323      WB6RDV
NetLojix Communications, Inc.  -  http://www.netlojix.com/


This archive was generated by hypermail 2.1.4 : Wed Aug 06 2003 - 06:52:44 GMT-3