Vulnerability Development mailing list archives

Code red II crashes cisco 678


From: "Geo." <georger () nls net>
Date: Sun, 5 Aug 2001 22:43:01 -0400

All day I've had customers calling with cisco 678 routers running cbos 2.4.2
with the web interface disabled. Seems their routers have been crashing.

We traced this back to the code red worm. For some reason even with web
disabled on these routers port 80 remains open. Simply running a port scan
and cutting off the connection is enough to crash the router. Locks up
solid.

I also found a solution, by doing a

set web remote ipaddress

where ipaddress is one of their internal IP's you can prevent outside
addresses from being able to crash the router.

Just a heads up guys, if you are seeing 678's crashing, give it a try, it's
working here.

Geo.




Current thread: