4 ms·
IKEv1 Information Disclosure Vulnerability in Multiple Cisco Products
- jdright 10y agoReflection of a "responsible" disclosure culture...
- benevol 10y agoNo way could anyone else have discovered and used the same vulnerability during these 14 years. Thanks for making use safe./s
- wepple 10y agoI get the point of your comment, but at a minimum if this were indeed NSA work, at least they could monitor for exploitation of the same bug against targets they want to defend (which, given their network reach could be both public and private sector). Fixing it would've at least prevented exploitation, but there is value in knowledge of who else has this exploit and who they're trying to attack.
- eganist 10y agoDo we even know anything about their defensive operations? I'm almost glad we don't since defensive capabilities are the kind of thing you'd rather not disclose to your adversary until you truly need to leverage them, but at the same time, with all the leaks, it's as if the NSA just runs offensive operations and reactive analysis/reconnaissance.
- wbl 10y agoYes. IPsec is widely used, and TLS on top of that with formally verified specialized implementations of IPsec. They also use data diodes, restricting the syntax of data that flows into and out of networks.
- eganist 10y agoI appreciate this, but I should clarify that I'm speaking specifically to active defense (hence defensive operations) rather than developing, publishing, and using defensive best practices, which I'd personally consider more passive than anything else.
- nialo 10y agoI think this actually has the opposite implication from the one you seem to be trying to draw. If different teams finding the same bugs was common, then someone else probably would have found this one sometime in the last 14 years and reported it to Cisco such that it was actually closed. Therefore, finding overlapping bugs is rare -> NSA should stockpile bugs. (We probably should have a separate agency in charge of attempting to make things more secure, perhaps by finding and reporting bugs like this)
- vxxzy 10y agoHow best, or how would one expect the NSA to behave? Where is the balance between offense and defense? On one hand, I can see this exploit needing disclosed to the general public. On the other, I can see this being useful for offensive purposes.
- mozumder 10y agoWhere does it indicate the NSA had anything to do with this?
- sctb 10y agoWe updated updated the headline from “NSA had 14 year old zero day to take VPN keys”, which breaks the HN guidelines for editorializing.
- ynezz 10y agoRight there, No workaroundS Available.
- deleted 10y ago[deleted]
- crystalmeph 10y agoIn the "Exploitation and Public Announcments" part of the linked article, it says that this vulnerability was discovered in the documents leaked/hacked from the Equation Group, which appears to be a group either within or extremely close to the NSA, although neither their actual name nor their existence has been acknowledged by the NSA. I don't see any reference to this exploit being used 14 years ago though, although the code being exploited is that old.
- United857 10y agoWhere in the page is the NSA mentioned? Not saying it's not reasonable for the NSA to have exploited (they probably did), but unless we have proof, the headline is a bit clickbait-ish.
- edelans 10y agolooks like a slandering title : how do you know NSA had the knowledge of this vulnerability ? I know that NSA may be considered "allmighty" considering its researching power, but this sounds a bit like a fast and easy accusation, and misleading title... I expected a whole different story (disappointed to see that ctrl+F "NSA" had no result).
- SEJeff 10y agoAnd this is just one of the disclosed 0day tools. Supposedly, the Shadow Brokers have quite a bit more that has yet to be released. Should be interesting in the future as more comes out.
- dogma1138 10y ago"The vulnerability is due to insufficient condition checks in the part of the code that handles IKEv1 security negotiation requests. An attacker could exploit this vulnerability by sending a crafted IKEv1 packet to an affected device configured to accept IKEv1 security negotiation requests. A successful exploit could allow the attacker to retrieve memory contents, which could lead to the disclosure of confidential information." So basically heartbleed for Cisco VPN's.
- tptacek 10y agoThis is a pretty common vulnerability. We found the same bug in nginx not long before Heartbleed. Cisco in particular has a history with these kinds of bugs (IIRC FX sort of famously dumped a whole image of a Cisco router in the early 2000s with one).
- elchief 10y agoI guess that's why there's IKE 2... IKE 1 was seemingly purposely complicated.
- prdonahue 10y agoI reported incredibly strange IKE behavior on PIX 6.x to Cisco in ~2005. They escalated to TAC, confirmed it was a bug, and eventually "patched" it. Wonder if it was same codepath?
- aaronmdjones 10y ago> An attacker could exploit this vulnerability by sending a crafted IKEv1 packet to an affected device configured to accept IKEv1 security negotiation requests > There are no workarounds that address this vulnerability. Call me crazy, but could one not work around this by ... I don't know, disabling IKEv1?
- simbalion 10y agoIs anyone else bothered by the mis-use of the term "zero-day" in the media?