Cisco Patches 'Black Hat' IOS Flaw
thursnick writes "eWeek is reporting that Cisco has finally issued a comprehensive fix for a critical IOS vulnerability that set off a firestorm of controversy at the Black Hat Briefings earlier this year. The patches come more than three months after former ISS researcher Michael Lynn quit his job to present the first-ever example of exploit shellcode in Cisco IOS (Internetwork Operating System), a presentation that landed him in legal hot water. Cisco's advisory effectively confirmed Lynn's summer warning that the flaw could be exploited by remote attackers to execute arbitrary commands or cause a denial-of-service on compromised routers."
So, what ever happened to Michael Lynn? He quit his job and made the presentation but, where is he today? Is he employed? Is he proud of what he did? Does he feel the price he paid was worth what he gave up for 15 minutes in the spot light? Would he recommend his "high road" choice to others in the future? Does he feel that he really made any difference in the end?
..... Is this safe enough to deploy or should it be dropped into a test environment of some sort before deploying into a production environment? That assumes of course that admins have the luxury of delaying the deployment of this.
This is my opinion. To make sure you don't steal it, it's covered by the DMCA.