01 Aug 2005
Ex-Internet Security Systems (ISS) researcher Michael Lynn’s presentation outlined how a known security flaw in Cisco’s Internetwork Operating System (IOS) could be exploited to run attack code.
Lynn gave the presentation shortly after resigning from ISS, and argued that the information is in the public interest. Cisco and ISS have been granted an injunction preventing Lynn from further discussing the issue.
Other researchers also used the event to highlight current risks. Staff from eEye Digital Security demonstrated a Windows kernel buffer overflow and a trojan that could load itself onto a computer before the operating system start-up process.
Marc Maiffret, co-founder of eEye, said the event gave firms a good opportunity to learn how to protect themselves. “Black Hat is a way for businesses and security experts to share information in the same way that hackers do. We find a lot of flaws, discovery and exploitation techniques, and warn people about them,” Maiffret said.
Elsewhere, security vendor TippingPoint tried to drum up support for its scheme that offers payments to people who provide details of new vulnerabilities. Phil Zimmerman, the creator of PGP encryption, also unveiled Zfone, an application for encrypting VoIP calls.
‹ Rewards for flaws, p5 ‹ Network security, p23
‹ Fighting e-crime, p28 ‹ www.tinyurl.com/bmjdr
Have your say on this article
Newsletters
Latest stories from Operating Systems
Latest videos
You may also like
Operating Systems jobs
Technology Patent Wars
Case studies from large organisations across all sectors
... And rich media, and flexible working, and peaks in traffic ...
Upcoming Events
Join us for this Computing web seminar, in which the Head of BI at the Co-operative Group Nick Colebourn will be explaining just how he reigned in the Group’s sprawling database estate and how significant savings were realised and data quality improved as a result.
Date: 31 May 2012
Time: 11:00 AM
Live June 13th 11:00am: Register now. During this web seminar we will be looking at the sorts of incidents that can bring data centres grinding to a halt and what can be done about them.
Date: 13 Jun 2012
Time: 11:00 am
Receive the latest jobs direct to your inbox
Are you being paid what you are worth?