Friday, December 15, 2006

Cisco issues security warning

Cisco has issued a security warning about code published on the internet that targets weaknesses in its Internetwork Operating System (IOS).

The code was written by a group of teenagers in Italy calling themselves the Black Angels, and it exploits nine vulnerabilities in IOS, which runs on the Cisco Catalyst Ethernet switch, IP routers and other products.

The new program, called Cisco Global Exploiter, provides simple code streams to make it easier to exploit the weaknesses, most of which have been identified by Cisco over the past four years, and get round the vendor's workarounds.

"Customers should take steps to ensure that they have addressed each of these either via a software upgrade or workarounds in place as appropriate in order to mitigate any risk from this new exploit code," the company said on its web site.

Most of the vulnerabilities make Cisco routers and switches more susceptible to distributed denial of service attacks. These attacks occur when hackers take control of servers and flood the network with millions of packets, which eventually cripple devices like switches and routers that try to process all the packets.