Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
Security

Possible Cisco Source Code Theft 189

OmegaBlac writes "According to Ars Technica, a Russian security site is claiming that Cisco's corporate network was comprimised and about 800MB of Cisco's source code for IOS Operating System version 12.3 was stolen. I guess Cisco forgot to implement their own Self Defending Network solutions."
This discussion has been archived. No new comments can be posted.

Possible Cisco Source Code Theft

Comments Filter:
  • by cide1 ( 126814 ) on Sunday May 16, 2004 @10:15AM (#9166683) Homepage
    Yeah, I'd like to believe you, but I've seen people get away with murder in source code before. Open source coders worry a lot more about things like indentation, and filenames that make sense. In closed source shops, a lot of times what is quickly coded as a prototype becomes the shipping product, and things like indent cant be used because it breaks diffs. As much as I'd like to look with my own eyes, this sounds like one of the things it would be best if I just ignored it.
  • by versus ( 59674 ) on Sunday May 16, 2004 @10:20AM (#9166709) Homepage
    I don't know who moderated parent as Informative (hint: use +1 Funny)

    Here is word-to-word translation (english is not my mother tongue):

    • As SecurityLabz was informed, in May 13, 2004 all source code of Cisco IOS 12.3, 12.3t was stolen. Cisco IOS is used in most Cisco network products. Full size of the stolen information is about 800 MBytes archived.
    • Source code leak was made possible because of Cisco's corporate network compromise. Cisco gave no official comments yet.

      Someone known as franz at IRC channel #darknet@EFnet showed a small part of stolen code as the proof.

      First 100 lines of source file ipv6_tcp.c and ipv6_discovery_test.c is listed below.

  • Re:Heh... (Score:2, Informative)

    by billygr ( 751676 ) * on Sunday May 16, 2004 @10:28AM (#9166743)
    "SO, if you don't like it, you go out and make an OS for the Cisco routers and put it out for free - go ahead, no one is stopping you"

    Who said that there isn't somethink like this ?

    http://www.uclinux.org/ports/
    From uClinux page: uClinux has successfully been ported to the Cisco 2500, 3000, 4000 routers. The patch allowing uClinux to run on the Cisco 2500/3000/4000 routers was completed by Koen De Vleeschauwer"
  • by corrosive_nf ( 744601 ) on Sunday May 16, 2004 @11:31AM (#9167141)
    Cisco had already announced a few weeks ago that version 13 of IOS was coming out and in June they were going to dump IOS fully for a totally new os for their routers that was going to be pluggable and more secure

    http://news.com.com/2100-1033_3-5210745.html
  • by Anonymous Coward on Sunday May 16, 2004 @11:44AM (#9167191)
    the company has long practiced a policy of "security through obscurity

    Not really... every version of Cisco IOS since 6 has been leaked. The first time I've seen IOS source was probably 6-7 years ago. I'm not even sure why this is news.
  • by TheGratefulNet ( 143330 ) on Monday May 17, 2004 @12:07AM (#9170661)
    quite wrong.

    its freebsd. I used to work there so I know.
  • by thinlineofsanity ( 705239 ) on Monday May 17, 2004 @06:03AM (#9171730)
    You'll be happy to know that MCI (UUNET/Worldcom) use a significant portion of Juniper equipment, nowadays.

"Ninety percent of baseball is half mental." -- Yogi Berra

Working...