Slashdot Mirror


Cisco Warns of Stolen Web Site Passwords

An anonymous reader writes "Cisco warned customers today that someone had broken in and stolen an untold number of passwords and usernames that its customers and employees use to login at Cisco.com, according stories at News.com and Washingtonpost.com. Cisco says the problem is unrelated to flaws in its hardware, but both stories note that Cisco's latest troubles are likely fallout from their legal battles with researcher Mike Lynn, who last week revealed major flaws in Cisco routers. There is also a growing thread at Nanog where network admins are complaining of not being able to get new passwords."

31 of 165 comments (clear)

  1. Thanks, Cisco.... by SamMichaels · · Score: 4, Insightful

    ...especially since you require everyone to register in order to get ANY info or ANY software or ANY drivers.

    1. Re:Thanks, Cisco.... by TommyBlack · · Score: 3, Interesting

      Well the question there is whether they keep any personally identifiable information with that registration, which can now be accessed by whoever stole the logins.

      Even for people who use the same username and password everywhere, this shouldn't be a problem since the passwords should be stored in a manner that is encrypted and can't be reverse-engineered. They wouldn't be stupid enough to store the passwords, right?

      --
      Why do my serious comments get modded "funny"?
    2. Re:Thanks, Cisco.... by Lanboy · · Score: 2, Informative

      I wouldn't be shocked if they stored the passwords.

      This CCO login is a REALLY old system. It was the first html based login I ever used, and I havent changed my password since 1994, becaue I let all my co-workers use it to download IOS for patches, read bug reports, etc.

      It didn't use to matter as it used to only be cisco's weak attempt to lock down new versions of IOS to customers with a service contract. To thier credit, Cisco never went nuts trying to shut out users who didn't change them.

    3. Re:Thanks, Cisco.... by thogard · · Score: 2, Informative

      So you don't store the md5 of the password but an md5 of a a salt, an extra key and your password...
      So you md5("$password") but more of md5("ciscoCCO$UID$password")
      To make it even more fun, drop the last 4 or 8 bytes off the md5 since your hash should never have more bits than your unique secret data

    4. Re:Thanks, Cisco.... by BWindle · · Score: 2, Informative

      Actually, when they find major bugs (usually security related) they give away fixed versions of IOS for free (Without registering.)

  2. Solution and comments by daveschroeder · · Score: 5, Informative

    From: Kim Christensen (kichrist) [mailto:kichrist@cisco.com%5D
    Sent: Wednesday, August 03, 2005 11:58 AM
    Subject: CISCO - CCO Passwords

    Dear Cisco Partner,

    I'd like to bring your attention to an issue thatmay cause minor inconvenience for customers and partners.

    You may experience issues with yourlogin to www.cisco.com

    You will be required to reset your password, please send an email to cco-locksmith@cisco.com from the same email address that is associated with your CCO userid. Within a few minutes you should receive a new working password back to that same email address.

    Please note that when you send an email to cco-locksmith@cisco.com - the only requirement is that the email is sent from the same email address associated with your userid to receive the return email with the new password. Once this is received you should be able to reset your password to one of your own choosing.

    It ispossible that you are not impacted by this issue but I wanted to ensure you are aware of this in the event you have a problem logging into CCO today.

    Your Cisco Channel Team


    And Mike Lynn already settled with Cisco, but I suppose it's par for the course to get in one more jab.

    Also, the "major flaws" could only be referring to two things:

    - flaws that have already been long fixed (six months before Black Hat), that Lynn, in his opinion, didn't believe Cisco identified as "critical enough" to its customers, but nonetheless, as I already said, are fixed; or

    - general IOS flaws that will only materialize for architectural reasons in the next major iteration of Cisco's routers that Lynn felt it was important enough to have a frank discussion about, but are not yet shipping.

    In other words, Cisco's technical response was such that the vulnerabilities in shipping products are already fixed, and the vulnerability Lynn claims is a real killer allegedly exists in products that aren't even shipping yet and won't be for some time; it flies in the face of logic to believe that Cisco would ignore such vulnerabilities in yet-to-ship products, once identified. Yes, Cisco didn't believe it at first, but it sent engineering staff, and were proven wrong. One can only assume the engineer Cisco sent for the very purpose of confirming this general issue in turn confirmed to Cisco that the problem was indeed real.

    Furthermore, it's likely that Lynn broke no law (save possible civil violations of contract and/or trade secret provisions), so any FBI investigation, if not over already, is moot. Ironically, several members of the government, including possibly Air Force OSI and/or NSA congratulated Lynn after his talk at Black Hat, even giving him a challenge coin for his work. Don't worry: Lynn's work isn't lost on those who value security, but don't presume that there is a huge conspiracy just because someone was willing to quit his job to reveal the secrets of a sometime-competitor. A little more of the Cisco/ISS background in this issue - including what I would consider fairly questionably motivated references by ISS about this flaw being Cisco's "Witty" - is provided in the earlier Wired interview.

    1. Re:Solution and comments by Cramer · · Score: 2, Interesting

      I think the trust level you are assuming is a bit overstated. While a great many networks are dependant on Cisco technology, I know of none that "trust" Cisco to any measure. IOS is very closed source; customers have zero control over what it does. And today, they have even less control over what capabilities it has -- Cisco reduced the number of builds from several dozen to about 7 to "reduce confusion".

      (I call bullshit on this one as that alphabet-soup version string has been readily and correctly documented for a decade. I defy you to find an experience cisco monkey that doesn't know what most of the codes mean -- or cannot find the docs with google in under 10s. Again, this is cisco being greedy... it takes time and resources to build 56 images; and it takes a great deal more resources to "QA" each of those images.)

  3. This? This isn't a big deal by ReformedExCon · · Score: 3, Informative

    These things can be fixed pretty easily. All current members with valid logins will just get new passwords assigned to them and the world will keep spinning like it always does.

    But it points to a completely different, much more significant problem. That is of using the same password for every login. I admit that I do it too because it is much easier to remember one or two basic passwords than trying to remember a different password for each site that I log in to. But as this latest breach of security shows us, doing that jeopardizes all other logins on other sites.

    One can only hope that they don't keep the passwords in a plaintext file and that a strong one-way encryption scheme is used to scramble the passwords in the database.

    Also, I wonder who thinks it is useful to hack these sites in retaliation for some perceived wrong against a stranger? The hackers at fault here prove no point, present no agenda, and generally smear the image of computer enthusiasts in the public eye. I'd rather they find a better way to protest than to attack private property.

    --
    Jesus saved me from my past. He can save you as well.
    1. Re:This? This isn't a big deal by patio11 · · Score: 2, Interesting
      I wonder if someone could leverage a major breakin at one general or specialist Internet site with low protection due to perceived lack of value of accounts (I don't know, a large message board community or something) and then parlay that to account disclosures on a site with significant value -- say, Amazon or Paypal or somewhere you can actually monetize the data. When you're talking about sites which have some measurable percentage of the entire population of the Internet as users, it seems like you could do a non-trivial amount of damage just by trying every username/password combination you have and just skim the .5% that worked. With a botnet to do the scanning you could spread your millions of invalid logins over 50,000 IPs and a month to not look suspicious on logs, then gradually siphon from the compromised accounts and get lost in the fradulent transactions background noise...

      Scary scenario.

  4. Looks like they should have used..... by rolfwind · · Score: 4, Funny

    Looks like they should have used self defending networks......

    http://www.cisco.com/en/US/netsol/ns478/networking _solutions_white_paper0900aecd801dfec7.shtml

  5. Raises the debate of usefulness of registering by Anonymous Coward · · Score: 2, Interesting

    I've never liked these register for access websites, they generally seem to me to be for the purpose of 1 or 2 things..

    Bragging rights (sysadmins and their userbase stats - give me a break)

    Spammation of the nation!

    Either way I treat such accounts with contempt and I generally register with the awe inspiring uncrackable password of 123123. Simply because as long as I do not divulge any "classified" information, a hacker impersonating me to download updates from a site is not really going to ruin my life.

    123123 FTW!

    1. Re:Raises the debate of usefulness of registering by ginotech · · Score: 2, Informative

      www.bugmenot.com grab the firefox extension, too.

    2. Re:Raises the debate of usefulness of registering by Anonymous Coward · · Score: 3, Funny
      I generally register with the awe inspiring uncrackable password of 123123
      Holy crap that is the combination to my luggage.
    3. Re:Raises the debate of usefulness of registering by scottv67 · · Score: 2, Insightful

      "Interesting"? Wow! The mods are generous today.

      What about the case where you have to register for a website to VERIFY THAT YOU ARE A CUSTOMER WITH AN ACTIVE SUPPORT CONTRACT?

      I use my CCO login to download software that I should not have access to *unless* I have a valid support contract in place. I don't expect Cisco to give away new versions of software and firmware for free. Those "products" should go only to the people who are paying for them.

  6. Re:Plain Text Passwords by skeeball · · Score: 4, Informative

    Cisco doesn't use plain text passwords for CCO. They use RADIUS authentication, more than likely back to their CNS product. The question is, if those passwords were stored in a database on a *nix server behind the firewall what exactly got comprimised here?

  7. Cisco Trouble for the Past Week by pyite · · Score: 4, Insightful

    I've had nothing but CCO trouble for the past week. That combined with random problems have been frustrating. The lovely order of events:

    1) A SUP (well, MSFC) dies in one of our 6000s. I try to open a TAC case.
    2) I try to login to CCO. It doesn't really work. I login, but it tells me I'm not logged in. After a bunch of clicking and such, I can open a TAC case.
    3) Since Cisco can't get its Smartnet act together, I need to jump through hoops to get the right contract on my account, again.
    4) Finally open a case. Tech diagnoses immediately as an MSFC bug. Sends me a new SUP.
    5) After a day of messing with the new SUP and wondering if I'm crazy, I decide they've sent me a DOA SUP.
    6) Tech agrees, sends me a new SUP.
    7) Try to use the RMA POWR tool to print mailing labels for the pair of bad SUPs fails. The tool has been down for three days now. Completely down.
    8) Try to login to CCO for something else today and run into the password problem. Combine that with their password reset tool not working and I'm *very* *very* annoyed.

    *Sigh* Guess all companies have bad weeks, but this is particularly sucky for Cisco.

    --

    "Nature doesn't care how smart you are. You can still be wrong." - Richard Feynman

  8. how to by-pass password by blew_fantom · · Score: 3, Funny

    >o/r 0x2142

    oh. wrong password... oops...

  9. Bumper Stickers? by pyite · · Score: 2, Funny

    So, who's up for an order of bumper (router) stickers? If you only have some crappy routers, you can throw a nice sticker on it that says "My other router is your CRS-1."

    --

    "Nature doesn't care how smart you are. You can still be wrong." - Richard Feynman

  10. Cisco: "Thugs". by Futurepower(R) · · Score: 2, Interesting


    From the Slashdot story: "both stories note that Cisco's latest troubles are likely fallout from their legal battles with researcher Mike Lynn".
    I'm amazed at Cisco's lack of social sophistication. From previous dealings with Cisco, I knew they were boorish, but this is much worse than I imagined.

    I'm amazed at the sure sense some executives have for creating millions of dollars worth of bad publicity. It's as though they studied how to sink companies, and that is their most professional and creative skill.

    It's awesome. In only one afternoon of work, Cisco corporate officers arranged to have Bruce Schneier call them "thugs": "I can't imagine the discussions inside Cisco that led them to act like thugs."

    What's even more awesome is that Cisco managed to make the FBI look like it is willing to get involved in political attempts to suppress free speech, making it look like thugs, too.

    Is there some competition among executives that I didn't hear about? Are they having a contest to see who can do the most damage to their companies? Is Cisco having a competition with Adobe? Is Cisco trying to outdo the Skylarov incident and the Killustrator incident?

    I suppose it doesn't matter to top executives. They can just take their million-dollar golden parachutes and go to another company, leaving the wreckage behind.

    I agree exactly and entirely with Mr. Schneier's assessment:

    "... this has been a public-relations disaster for Cisco. Now it doesn't matter what they say - we won't believe them. We know that the public-relations department handles their security vulnerabilities [my emphasis], and not the engineering department. We know that they think squelching information and muzzling researchers is more important than informing the public. They could have shown that they put their customers first, but instead they demonstrated that short-sighted corporate interests are more important than being a responsible corporate citizen."

    If I were on the Board of Directors, I would: 1) Fire the President and Vice-President of Cisco immediately, in a highly public way. 2) Do immediate damage control by exhibiting some sophistication about Cisco's relationships with the outside world. I'm guessing that, sadly, the Board of Directors doesn't have anyone who has the necessary social skills.

    1. Re:Cisco: "Thugs". by demachina · · Score: 2, Insightful

      "Cisco corporate officers arranged to have Bruce Schneier call them "thugs"

      This one is pretty easy to explain. though its kind of a long proof, follow along.

      You may recall John Chambers, Cisco CEO, a while ago said:

      "What we're trying to do is outline an entire strategy of becoming a Chinese company"

      The people running China are now in fact no longer Communist. There is a prerequisite that there be state ownership of Capital to be Communist/Socialist. When China started transferring control of capital to private individuals, mostly highly place members of the party and their relatives, it did in fact transform from being Communist China to Fascist China.

      Under Fascism you have a repressive one party state but you can have private ownership of capital. The party just usually makes sure most of it wealth is in the hands of favored party members and the party liberally intervenes in the economy to pick the winners and losers. This is exactly the political and economic model you have in China today.

      So if you've followed this far:

      - The Chinese are now Fascists
      - Fascists are Thugs
      - Cisco is a "Chinese company"

      Cisco = thugs

      Bruce was stating the obvious.

      --
      @de_machina
  11. Re:untold and proactive robbery by jo_ham · · Score: 2, Interesting

    The poster is referring to the adjective used: proactive.

    Cisco are reacting to events, they are not being proactive.

  12. Get your stories straight... by homerskid · · Score: 3, Insightful
    If you are reporting news, try to get the story correct: No passwords were compromised, Cisco took a proactive stance to remedy something that had the possibility of occuring.
    "It has been brought to our attention that there is an issue in a Cisco.com search tool that could expose passwords for registered users,"

    This also had nothing to do with Lynn, even though the media would like to tie them together. It was brought to Cisco's attention by a completely separate company.
  13. I posted this first with a little different twist by geekp0wer · · Score: 3, Informative

    Cisco Web Site Hacked 3:18 PM

    According to an article at ZDNet, Cisco's web site has been hacked and they are advising users to change their passwords. As someone who was at Ciscogate (Michael Lynn's Blackhat presentation) I can not go without wondering if this event is related. Lynn stated in his presentation last week that the older IOS archives were removed from the download site due to his research. That begs the question, did someone hack Cisco's site in an attempt to get at those versions of IOS? BTW, if you are still looking for the orginal presentation this previous slashdot story mentions an article at Wired, which has a link to lynn-cisco.pdf

  14. No site should ever store passwords by vicaya · · Score: 3, Insightful

    It's appalling that a major company (a major tech company with security product offerings in this case!) website would store passwords in cleartext. Passwords (even usernames) should always be stored in strong one-way hashes like sha-1, so that even if they're stolen, they're close to useless.

  15. oh this is rich... from the eWeek article by ashpool7 · · Score: 2, Insightful
    However, experts say that while the security holes are unpatched and undisclosed, they put companies and individuals at risk. "We're making reverse engineering code illegal, but criminals don't follow the law. They reverse engineer code and find the holes," said Paller.


    So, in that case, how in the hell is making reverse engineering illegal helping anyone?

  16. Don't worry by That's+Unpossible! · · Score: 3, Funny

    Word is the thieves have just as much trouble logging in with these stolen passwords as those who originally created them, and Cisco predicts the thieves will give up on them shortly.

    And honestly, even if the thieves could get access to the needed areas of Cisco's TOP SECRET website, what are the chances they could decipher the grid of which firmware goes with which device?

    Last time I looked at Cisco's firmware listings (back when they had that exploit affecting all their routers), a co-worker had to pry the gun out of my hands.

    What moron developed their firmware version scheme? Please kill this person immediately.

    --
    Ironically, the word ironically is often used incorrectly.
  17. You can have THIS info sans registering! by Anonymous Coward · · Score: 2, Informative

    If you really want information from them why don't you be one of many to read the Lynn presentation? Here, I've even transcribed Lynn's presentation to text instead of that huge, ugly PDF. As a bonus, the assembly readings are now readable. For all I know, they consider this criminal even though I consider this not only a fair use but a public service. The bad guys already know this stuff; we need to let the legitimate security professionals in on this! Insofar as I can give permission, copy and paste this anywhere you please. It's still probably copyrighted to the ISS, though, but it's Cisco suing over it, even though anyone with a router can get those assembly listings, they're probably fair use since they're such small portions of the router software, and I have no dealings or contracts with Cisco binding me not to release such things (I don't own any Cisco gear), so if anything, only ISS should have grounds to sue me, and they don't seem to care to.

    [ Page 1 - The Holy Grail ]
    Cisco IOS Shellcode And Exploitation Techniques by Michael Lynn of Internet Security Systems
    [ Page 2 - Another Unbreakable System ]
    [Editor's note: This page shows a picture of what I presume to be the Titanic.]
    [ Page 3 - Why You Should Care ]
    * Wide Deployment
    - Switches
    - Routers
    - Access Points
    * Keys To The Kingdom (MITM)
    - Control the network traffic
    - Packet sniff in far off lands
    - Modify traffic
    - Break weakly authenticated encryption (passwords, etc.)
    [ Page 4 - Some Review: Basic Techniques ]
    * Stack Overflows
    - Overwrite return address on the stack
    * Heap Overflows (Pointer Exchange)
    - Tranditionally we use heap chunk linkage
    - Any linked list will do
    Typical linked list delink looks like:
    foo->prev->next = foo->next; foo->next->prev = foo->prev;
    [ Page 5 - Misconceptions ]
    * Routers And Switches Are Just Hardware
    * It Is Not Possible To Overthrow Buffers On IOS
    * There Is Now Way To Exploit Buffer Overflows On IOS
    * Every Router Is So Different That An Exploit Might Work On One Router But Never Another
    [ Page 6 - Wrong! ]
    * Routers And Switches Run Software On General Purpose CPUs
    * Buffers Do Exist And It Is Not So Rare That They Overrun
    * Exploitation Is Possible
    * Exploitation Can Be Made Reliable And Cross Platform (more on this later)
    [ Page 7 - IOS Basics ]
    * Monolithic
    - No loadable modules (yet)
    - All addresses are static
    - All addresses are different per build
    * Real Time OS
    - If you are running you own the CPU (mostly)
    - We have to exit or yeild properly or we will crash
    - Once our code is running we have won any race
    * Stability
    - IOS tends to favor rebooting over correcting errors
    [ Page 8 - A Word On Code Quality ]
    * Much Better Than Most Platforms
    - They check heap linkage
    - They are very aware of integer issues
    - They almost never use the stack
    - They have a process to check all heaps
    - Very old, very well tested code
    * Bugs Exist Anyways
    - Green pastures
    - We can get around some checks
    - Will will use some of these checks against them
    [ Page 9 - The Dreaded Check Heaps Process ]
    * Walks All Heaps Looking For Bad Linkage
    - Even if our chunk is not freed check heaps will detect bad linkage
    - Is run every 30 to 60 seconds depending on load
    * This Is the Main Reason Heap Overflows Can Be Hard
    [ Page 10 - Rules of Engagement ]
    * Stack Overflows
    - Rare, but if we find one, its fair game
    * Heap Overflows
    - They check next and previous pointers
    - We either have to beat check heaps or not offend it
    - We must either know the values for the previous pointer or we must get around this somehow
    * Monolithic Architecture
    - For heap overf

  18. Re:Plain Text Passwords by pnatural · · Score: 2, Insightful

    When will programmers learn that there is NO good reason to keep passwords in plain text?

    In my 20+ years programming experience, I've never seen a programmer that wanted to store a plain-text password. Rather, each time I've seen it done, it was a business-type making it a requirement.

  19. Re:SecureID by scottv67 · · Score: 2, Informative

    $50? It's more like $100 a head to use SecurID (not counting server hardware) becuase each $60 token also needs a corresponding $40 license on the ACE/Server.

    Every remote user who gets an RSA hardware (or software) token at the company I work for costs the company $100. This doesn't count the cost of administering the remote access accounts. We like to keep this figure handy for managers who request an RSA token (hard or soft) for everyone in their entire department. After they hear the cost, the number of people who really need the tokens often goes down substantially.

  20. Re:SecureID by Professor_UNIX · · Score: 2, Informative
    My SecurID hardware authenticators from RSA display a different tokencode every sixty seconds. Or are you talking about something else?

    Actually, for the record, that's an adjustable value when the token is created. Just tell your salesperson the value you want it to be. You can also request them with more than 6 digits.

  21. and then what? by Zen · · Score: 2, Interesting

    I'm not exactly sure why we care that our CCO account names and passwords were stolen. Does it really matter to me if someone downloads IOS while masquerading as me? Or maybe I should care if somebody opens up a TAC case as me, or submits a bug report as me? I really don't see the problem with someone else having access to my account on CCO. The only thing I use it for is to download code (we call TAC directly, or called our dedicated Advanced Services guy for everything else). I'm sure 90% of the people who have CCO accounts also use it solely for the purpose of downloading code/drivers/etc. So am I missing something that is highly private on the site?