Forums: Oh Oh Cisco... - Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • This topic is locked

Oh Oh Cisco... Customer passwords compromised

#1 User is offline   usch 

  • Staff Sergeant
  • Icon
  • Group: Specialist
  • Posts: 269
  • Joined: 19-January 04

Posted 03 August 2005 - 03:30 AM

After all the trouble at the BlackHat and the discovered heap overflow in IPV6 processing, Cisco is facing even more problems.

A news-article by a German online magazine says that every customer who wants to log on to the Cisco Support-Management got the following message:

Quote

IMPORTANT NOTICE:

* Cisco has determined that Cisco.com password protection has been compromised.

For caution, Cisco has reset all passwords.

Original Article(in German) :http://www.heise.de/newsticker/meldung/62404

Translation (by me) :
For Ciscos image regarding Security it is getting even harder. After the network specialist's unfortunate role at the recitation about Cisco-flaws a week ago and a heap overflow in the procession of IPv6-packets being published shortly after that, customer data has apparently been compromised. Everybody who tries to log on to Cisco's webserver for support-management and orderings, gets the message:

IMPORTANT NOTICE:

* Cisco has determined that Cisco.com password protection has been compromised. 

As a precaution, Cisco has reset the passwords, as an empoyee at the Cisco-Hotline confirmed on request by Heise Security. The situation is specially sensitive, because not just everyone can download patches for Cisco-products. Who for example wants to secure his router against the last Friday published flaw in the procession of IPv6 Packets, usually needs access to Cisco's Software Distribution Center.

The employee couldn't tell when the regular service would be restored and an official response to the affairs by Cisco is still outstanding. Due to the flood of requests to Cisco, the clarification of the issue will take time.




usch
0

#2 User is offline   Spookie 

  • Staff Sergeant
  • Icon
  • Group: Specialist
  • Posts: 293
  • Joined: 21-December 03

Posted 03 August 2005 - 07:34 AM

I think all the attention given to Cisco since the BH /DefCon gatherings can be best summed up by what Raven said

Quote

"Hiding your head in the sand is not going to help; suing researchers is not going to help - Cisco, you are really screwing up here,"

The comment can be found in this article at Security Focus

Theres several other issues with Cisco, that I have. But I won't jump on my soap box for now. Time will show the true ugly head of greed. But thats JMO

This post has been edited by Spookie: 03 August 2005 - 07:54 AM

Beauty is only a light switch away
0

#3 User is offline   b4nqu0 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 51
  • Joined: 07-July 05

Posted 03 August 2005 - 07:55 AM

Quote

"Hiding your head in the sand is not going to help; suing researchers is not going to help - Cisco, you are really screwing up here,"


oh yah, i was there. Everyone started applauding at that point. She did a really nice presentation. If anyone wants her notes/slides pm me.
0

#4 User is offline   dotslasher 

  • Private
  • Icon
  • Group: Members
  • Posts: 8
  • Joined: 27-June 05

Posted 03 August 2005 - 07:59 AM

lol they screwed up once again
0

Page 1 of 1
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting