Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Finance
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
Computerworld 2007Subscribe to Computerworld
40 years of the most authoritative source of news and information for IT leaders.

Theft of Cisco source code stirs fears of security threat

The vendor's reticence to discuss the theft leaves users uneasy
Jaikumar Vijayan   Today’s Top Stories    or  Other Security Stories  
 

Sign up to receive Security Resource Alerts

May 21, 2004 (Computerworld) -- The theft of proprietary operating system source code from Cisco Systems Inc. poses a potentially serious security threat to corporate networks that use the company's technology, users and analysts said.
And the paucity of information released by the networking giant this week in the wake of the theft is raising troubling questions about what exactly happened and the real extent of the compromise, they said.
"We are all waiting to hear what Cisco has to say," said Stephen Smith, network manager at Keystone Mercy Health Plan in Philadelphia.
Cisco has been "unnaturally and unproductively quiet," said John Pescatore, an analyst at Gartner Inc. "That gives the impression that they are still unsure about the scope of the breach. Or they are sure, and it's much worse than has come out so far."
Unidentified attackers stole an unspecified amount of source code for Cisco's Internetworking Operating System 12.3 and 12.3T software, which is widely used in switches and other networking equipment (see story). A Russian Web site posted about 13MB of what it claimed was the stolen code last Saturday, saying that as much as 800MB of code appeared to have been stolen.
Alexander Antipov, a security expert at Moscow-based Positive Technologies, which owns the Web site that posted the stolen code, claimed that the company downloaded it via a link provided over an Internet Relay Chat channel by someone using the online name Franz.
The supposed Cisco code samples, a copy of which was sent to Computerworld, was removed from the Web site at Cisco's request on May 18, Antipov said.
In a statement posted on its Web site, Cisco confirmed that a "portion" of IOS code had been illegally copied and publicly posted for several days. It appeared that the occurrence wasn't the result of flaw in any Cisco product or service, the note said. It also was unlikely that the action was taken by a Cisco employee or contractor.
The company refused to provide further details, citing an ongoing investigation into the matter, but said it believed that "the improper publication of this information does not create increased risk to customers' Cisco equipment."
"We will continue to closely monitor this matter and provide updates as appropriate to customers," a company spokesman said.
The theft raises security concerns, especially since Cisco's technology is widely used on corporate networks, users said.
"Now that the code is available to scrutinize, it will be easier to find holes to exploit," said Jon Duren, chief technology officer at IdleAire Technologies Corp., a Knoxville, Tenn.-based provider of electrification services. "This issue has caused [us] to re-evaluate our access control lists on the routers, and on devices surrounding our routers, to ensure that they are solid."
A similar incident involving the theft of Microsoft Corp. source code for Windows NT and Windows 2000 in February led to the discovery of a remotely executable flaw in the company's Internet Explorer browser software (see story).
The stolen Cisco code could be investigated for similar flaws or somehow exploited to create back doors or to fool users into downloading malicious patches or Trojan horse programs, security experts said.
In the Microsoft incident, the stolen code was freely available for download. In contrast, the Cisco source code hasn't resurfaced following its brief public airing on the Russian Web site.
Another difference between the two incidents is that the Cisco source code could be a lot more difficult to exploit than the Microsoft code, which was "complete and reasonably easy to work with," said Johannes Ullrich, chief technology officer at the SANS Internet Storm Center in Quincy, Mass.
"Just the same, we still have to be aware of the possibility of a security issue arising as a result of the theft," said Edward York, CTO at 724 Inc., an application service provider in Lompoc, Calif.
This is especially true given the lack of information coming from Cisco, users and analysts said. Gartner's Pescatore noted that the question that always gets raised when incidents such as this occur is, "If this got out, what else was going on?"




Print this Story Send Us Feedback E-mail this Story Digg! Digg this Story Slashdot this Story
"A video is making the rounds showing how Vista SP1 has significantly improved Vista's immensely annoying User Account Control (UAC)...." Read more...
"So are you getting excited about a nice, long weekend for Memorial Day? Well, before you start cooking hot dogs..." Read more...
Read more Security posts or See all Blogs
Mozilla launches Firefox 3.0 RC1 early
Microsoft: Don't misunderstand UAC, other Vista features
HP confirms XP SP3 endless reboot snafu, promises patch
More top stories...
Microsoft pulls Windows Home Server backup feature
Yahoo tells Icahn that its own board knows best
Tools circulate that crack Debian, Ubuntu keys
Specialists have retrieved about 99% of the data on a disk drive on board the crashed space shuttle Columbia. Don't miss the photographs of the recovered drive.
These big ideas were supposed to revolutionize technology, but they never actually appeared. In a few cases, you'll be glad they didn't.
Nearly 20 years after the first Internet worm, Steven J. Vaughan-Nichols takes stock of the malware/anti-malware landscape and spotlights how the two sides are approaching the battle.
Though some thought it was released too soon, Mac OS X 10.5 has matured into a solid operating system, says reviewer Michael DeAgonia.
Reviews, analyses, how-tos, visual tours, hot issues and predictions about Microsoft's new OS.
Four years from now, the IT field will be a vastly different place. Will you be ready?
All Zones
Application Performance Zone
Enterprise-Class Security Zone
Enterprise Solutions Zone
The File Data Management Zone
Grid Computing on Windows Zone
Security Management Zone
ITIL Best Practices Zone
The SAS Zone
Storage Virtualization Zone
The Data Center Management Zone

Ads by TechWords

See your link here
Why SaaS is Vital to Email and Web Security
Why SaaS is Vital to Email and Web Security
Download this webcast, free, compilments of Webroot Software
Go to the webcast 
Computerworld Executive Bulletin: Building a Robust Antivirus Defense
Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs.
(Source: MessageLabs) Antivirus software alone isn't enough to prevent today's speedy, sophisticated virus attacks. Security managers should consider multitiered approaches that include behavior scanning, appliances that check e-mail for worms, and restricting user access to dangerous Web sites. Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs, to learn more.
Download this executive briefing download
Eliminate SPAM, Gain Productivity
Get this white paper now!
(Source: MessageLabs) Learn all about the dangers and the costs of spam in all its forms - from stock-touting to spreadsheet. Also, understand the drawbacks of traditional hardware- and software-based defenses - and the unique benefits of MessageLabs multi-layered, managed Anti-Spam solution; as illustrated by a real-world case study where MessageLabs stopped spam cold.
Download this white paper go
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
Securing Financial Services Beyond the Perimeter
Intercept Spam & Viruses With MessageLabs
Meeting PCI Compliance with SonicWALL Global Management System
View more whitepapers 
Layered Security Solutions
Although basic network security issues have changed very little over the past decade, the network security landscape has changed dramatically. Today's IT professionals still have the primary responsibility of protecting the confidentiality of corporate information, preventing unauthorized access, and defending the network against attacks. Security experts and analysts agree that a security solution comprised of multiple layers is the best defense against today's increasingly sophisticated attacks.

Download this white paper 
Universal Threat Management - Because Conventional UTM is Not Enough!
This white paper, written by Mark Bouchard of Missing Link Security Services, examines the challenges confronting today's enterprises with respect to managing threats on a network. It also discusses the need for "Universal Threat Management", which is a security solution approach for all physical locations within an enterprise that require threat protection.

Download this white paper 
Selecting the Right Threat Management Solution
This short demo will guide you through key considerations for selecting a solution to manage threats on a network. Learn about the popularity of Unified Threat Management (UTM), and how it fits into an overall security solution. Explore critical elements of a network-wide solution for multisite and large network-size deployments and identify the four key features of a threat management solution.

View this demo