A security researcher who gave a presentation on vulnerabilities in Cisco Systems routers at this week's Black Hat USA conference has agreed not to further discuss the issue under the terms of a permanent injunction issued by a U.S. federal court.
Cisco plans to issue a security advisory "within the next day," according to a statement the company released on Thursday after the injunction was issued.
Cisco and Internet Security Systems (ISS) sought the injunction on Wednesday against Michael Lynn, who gave the Wednesday morning presentation, and Black Hat, which organized the Las Vegas computer security conference. It was granted on Thursday by Judge Jeffrey White of the U.S. District Court for the Northern District of California, in San Francisco.
All parties involved in the case have agreed to the injunction, effectively putting an end to a dispute that dominated the final two days of Black Hat and diminished the reputation of Cisco and ISS in the eyes of many attendees.
ISS had originally replaced the presentation, entitled "The Holy Grail: Cisco IOS Shellcode and Remote Execution," with a different one and had ensured the presentation materials were torn out of a book that was part of the materials given out at the Black Hat show.
But Lynn, a research analyst at ISS, quit his job at ISS and gave the presentation anyway.
"The information that Mr. Lynn disclosed at the conference, we believe was illegally obtained, and included Cisco intellectual property," said Cisco spokesman John Noh.
Lynn described a now-patched flaw in the Internetwork Operating System (IOS) software used to power Cisco's routers, and demonstrated a buffer-overflow attack in which he took control of a router. Although Cisco was informed of the flaw by ISS, and patched its firmware in April, users running older versions of the company's software are at risk, he said.
Among other things, the injunction issued Thursday blocks Lynn from disclosing or disseminating any part of the presentation, disseminating any video recording of the presentation, or disassembling or reverse engineering Cisco code in the future.
Cisco had sought the injunction "to stop continued irresponsible public disclosure of illegally obtained proprietary information," it said in a statement.
At a news conference Thursday afternoon, Lynn admitted that he had converted some of Cisco's binary code into a human-readable form, a process called reverse-engineering. But he disputed the idea that this was an illegal practice. "It's generally speaking not illegal to reverse engineer for security reasons," he said.
Many end-user license agreements, including Cisco's, prohibit reverse-engineering.
Lynn said the attention that the case drew will push Cisco to improve the security of its routers. "I think I did the right thing. It was pretty scary, but the real important message was [that] there was a potential or serious problem coming in the future. It wasn't too late to fix it, but you had to take it seriously," Lynn said.
"I didn't think the nation's interests were served by waiting until another year, until a router worm would be a serious threat," he said.
Cisco welcomed the injunction.
This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.
Download now »Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.
Download now »
The emergence of WLANs has created a new breed of security threats to enterprise networks.
Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation
Effectively address data protection challenges, implementing solutions that help store and protect businesscritical data while cutting costs and improving efficiency and reliability.
Download now »
Sign up to receive Security Resource Alerts
This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.
Download now! »Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.
Download now! »Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.
Download now! »