By Jay Lyman TechNewsWorld Part of the ECT News Network
07/18/03 8:26 AM PT
The Internet infrastructure will be generally affected by the flaw -- regardless of whether a particular router is targeted -- because of the broad distribution of affected Cisco routers.
eMarketer Whitepaper: Optimizing the E-Commerce Experience
From the Web to the Contact Center, are you prepared to proactively engage and keep your savvy customers? Read how e-commerce leaders are optimizing their sites with ratings, reviews, live help, Web analytics, mobile and more.
A software flaw in routers discovered by networking giant Cisco (Nasdaq: CSCO) has forced Internet carriers and others to apply fixes quickly before attackers cause network outages by exploiting the vulnerability.
Exploit code that takes advantage of the flaw was released early Friday morning, and networks using the Cisco routers and switches were being attacked once or twice per minute, ISS X-Force vice president Chris Rouland told TechNewsWorld.
Rouland, whose company's AlertCon warning meter was raised to level three –- the second highest alert level and a rare event for the company -- said corporate networks and countries that are known for slow security response, such as Korea, are most likely to experience network outages.
"This severity of flaw in this widespread a device is fairly rare," Rouland said. "We had one last year and one this year."
Weekend Slowdown
Aberdeen Group vice president of security and privacy Jim Hurley told TechNewsWorld that consumers might experience Internet slowdowns because of the large number of emergency maintenance outages occurring as Internet service providers and carriers patch the Cisco networking software.
"This is an emergency situation," Hurley said. "The folks that got a hold of the problem yesterday are probably applying patches today, or they were last night. You're likely to see a lot of IT folks working over the weekend and a lot of networks down."
All Routers at Risk
Cisco reported in an advisory on the problem that routers and switches running Cisco Internetworking Operating System (IOS) software and configured to process Internet Protocol version 4 (IPv4) packets are vulnerable to a denial-of-service (DoS) attack.
"My guess is that's 96 to 97 percent of the routers out there in the universe," Hurley said. "For all practical purposes, almost every single one of them [is affected]."
In its security advisory, Cisco reported that a rare sequence of crafted IPv4 packets with specific protocol fields sent directly to affected routers might cause the input interface to stop processing traffic once the input queue is full. No authentication is required to process the inbound packet, the company said.
No Alarms
Cisco also reported that no alarms will be triggered, nor will affected routers reload to correct themselves. The company said the vulnerability, which can affect all Cisco devices running IOS software, may be exercised repeatedly, resulting in loss of availability until a workaround has been applied or a software patch is installed.
Cisco warned that, while applying the software fix it has made available, customers should be certain the devices to be upgraded contain sufficient memory.
Rouland said that, despite the availability of the software fix, financial institutions and people using voice over IP (VoIP) are likely to experience network slowdowns or outages.
Hurley said Internet infrastructure will be generally affected by the flaw -- regardless of whether a particular router is targeted -- because of the broad distribution of affected Cisco routers.
"There's really no choice but to take the network down," Hurley said. "I suspect most everybody will be on it real quickly."
IBM and Cisco Sync, Widen SAN Coverage July 15, 2003
The cost of bandwidth is one of the largest limitations of storage networking, but the Fibre Channel over IP support in the new switch might make storage area networks' use and expansion more attractive.
Could Cisco and Sun Make Strange Bedfellows? July 08, 2003
With traditional computing disappearing into the storage network and the app server, it's time the greybeards got together.
Best Firewalls for Big Enterprises July 02, 2003
"We see the firewall space as changing dramatically in the next few years," Gartner research director Richard Stiennon told the E-Commerce Times. "There's an opportunity for startups to challenge existing vendors to change their technology."
Selling to Skeptics in a Tech Downturn July 01, 2003
Despite continued IT buying, today's CIOs seem less like adventurers and more like bargain-hunters.
Slow Ahead, It's Longhorn Crossing June 24, 2003
Microsoft's next PC OS isn't due out until 2005. What ever happened to the "fast follower"?
Related News Alerts
More by Jay Lyman
Open Source Developer Dumps Novell Over Microsoft Deal December 26, 2006
A key open source developer, Jeremy Allison, who cofounded the Samba project, has resigned from Novell in protest over the company's recent agreement to enter a collaborative arrangement with Microsoft. The deal has created an uproar in the open source community because it does not treat all recipients of the GPL equally and thus violates the spirit of the license, critics say.
Financial Firms Tap Microsoft for Linux December 22, 2006
Three major financial institutions are among the first companies to go to Microsoft for Linux services, provided through an agreement the software giant struck with Novell. Although a recent survey showed customer approval of the collaboration, many members of the open source community view Novell's move as sleeping with the devil.
Mozilla Beefs Up Security in Firefox 2.0 December 21, 2006
Mozilla's latest update to its open source Firefox browser includes security measures targeting phishers. Phishing scams that use social engineering techniques to dupe Web surfers into revealing personal financial information have become an effective way for cybercriminals to conduct their nefarious activities on the Internet.