funsec mailing list archives

Fwd: PoC Exploit Now Available for Cisco NHRP Vulnerability


From: "Paul Ferguson" <fergdawg () netzero net>
Date: Thu, 9 Aug 2007 17:42:30 GMT

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

FYI.

- - ferg

[forwarded message]

From: "Paul Ferguson" <fergdawg () netzero net>
Date: Thu, 9 Aug 2007 17:35:54 GMT
To: nanog () nanog org


If you're using NHRP and haven't patched, it might be a good
idea to do so real soon now.

A proof of concept exploit is now avialable which can crash a router
configured with NHRP authentication enabled:

http://www.milw0rm.com/exploits/4272

Cisco security advisory from yesterday:

http://www.cisco.com/en/US/products/products_security_advisory09186a0080899
63b.shtml

FYI,

- - ferg

-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.6.2 (Build 2014)

wj8DBQFGu1HXq1pz9mNUZTMRAhD1AKC/wH/SahO7CQRT0Eit9jTK2tqt3QCghx8i
vP5LZ4TleJkRSO7RdKF5nIY=
=dw8p
-----END PGP SIGNATURE-----


--
"Fergie", a.k.a. Paul Ferguson
 Engineering Architecture for the Internet
 fergdawg(at)netzero.net
 ferg's tech blog: http://fergdawg.blogspot.com/


_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: