Re: CISCO and nestea.

From: Jim Duncan (jnduncanat_private)
Date: Sat Sep 11 1999 - 23:20:34 PDT

  • Next message: Dr. Joel M. Hoffman: "fixing all buffer overflows --- random magin numbers"

    Vit Andrusevich <vandruseat_private> writes:
    > Hello.
    >
    > Sorry if it was known before..
    >
    > My CISCO 2600 with NAT IOS 12.0 crashes when I try to run nestea DoS attack
    > against one of my servers.
    >
    > The victim of nestea attack was one of my NT servers which was "under NAT".
    
    Basil V. Dolmatov <dolat_private> writes:
    > 12.0(what?)
    >
    > It was a bug in IOS several months ago, which was fixed already.
    >
    > Upgrade your IOS.
    
    Basil is correct.  Thanks.
    
    Vit, just to make sure that is the correct answer, could you please send
    us the output from a "show tech" command?  Thanks.  There's always a
    chance you may have uncovered a new problem.
    
    As always, the best place to send questions and reports about possible
    vulnerabilities in any Cisco product is to the Cisco Product Security
    Incident Response Team, <psirtat_private>.  You can read about us at
    <http://www.cisco.com/warp/public/707/sec_incident_response.shtml>.
    
    Check with us first to avoid wasting bandwidth by posting unnecessary or
    inaccurate messages to critical mailing lists like BUGTRAQ.  We provide
    24x7 response to reports of vulnerabilities in Cisco products and to
    requests to assist customers with security incidents.
    
    It's also faster to send us e-mail directly -- BUGTRAQ is an incredibly
    useful list, but as an e-mail gateway it's not as efficient as e-mail
    addressed directly to us at <psirtat_private>.  :-)
    
    The Cisco Product Security Incident Response Team is affiliated with the
    Forum of Incident Response and Security Teams, <http://www.first.org/>.
    
    Thanks.
    
    	Jim
    
    
    --
    Jim Duncan, Product Security Incident Manager, Cisco Systems, Inc.
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:03:00 PDT