International
At Black Hat Europe 2007 Dror-John Roecher and Michael Thumann showed how they were able to hack the Cisco NAC solution by exploiting a fundamental design flaw. In this video they illustrate how they worked towards this discovery and give us some exploit details. It is not their intention to simply release a tool, they want the audience to understand how Cisco NAC works and why it is not as secure as Cisco wants us to believe.
For more security-related material visit http://www.net-security.org
Cisco support has gone down the tubes. I remember calling sales and getting someone who actually could help. Now They are refusing to support Vista with my Pix firewall VPN, I need remote logon for my domain. (SBL) They did everything (including blaming Micrsoft) not to fix my problem. I would expect more out of Cisco then to make a client that only Half works for vista. No plans to make it right, very lame....
By phillyfunnyguy [Affiliate User] 1199339853 Reply Spam [+0] Moderate Up Moderate Down RemoveCisco mainly positions its NAC appliance solution which is widely deployed and is a very reliable solution and not the NAC framework mentioned. If the hacking was truly done, how come they did not demo it? and how come they did not talk about other vendors?
Seeing is believing: anybody can talk and claim that they hacked any system and if there is no concrete proof and clear explanation of how testing was done and proper analysis and explanation of results, this information is simply worthless
Thanks for posting this video. I got to meet these guys at BH America and I have to say their work is amazing. The research and reverse engineering work alone seemed overwhelming and the hack was brilliant. Thanks for the vid.
By tsudohn1mh [Affiliate User] 1187530773 Reply Spam [+0] Moderate Up Moderate Down RemoveAn in all honesty, most (if not all) NAC technologies out there suffer from a similar type of flaw. As rightly said at the begining, you are asking an end-device for posture information, which quite frankly can be spoofed - in some cases easily, in other cases not so easily.
By splintcer [Affiliate User] 1182994944 Reply Spam [+0] Moderate Up Moderate Down Removeif this would be the only flaw on the cisco devices I would be the gladest man in the world.
By Madowstone [Affiliate User] 1181640292 Reply Spam [+0] Moderate Up Moderate Down RemoveYer solid effort indeed. Smartasses :)
By masterdanoz [Affiliate User] 1180560230 Reply Spam [+0] Moderate Up Moderate Down RemoveGreat video guys!
By Webmast84 [Affiliate User] 1179914642 Reply Spam [+0] Moderate Up Moderate Down RemoveI never saw anything but two guys talk, demo anyone?
By eneasquintero [Affiliate User] 1179734640 Reply Spam [+0] Moderate Up Moderate Down RemoveVery intresting, I do a little bit of reverse engineering myself and it is a lenghty process.
So grats to these guys.
DUDE you rock....
i need your help :)
Rated 2.57 | 248 Views
By Ciscovid
Rated 1.93 | 194 Views
By Ciscovid
Rated 3.94 | 209 Views
By Ciscovid
Cisco ASA 5500 Series IPS Edition Video Da...ta Sheet
Rated 3.23 | 485 Views
By Ciscovid
Cisco ACE Web Application Firewall Video D...ata Sheet
Rated 3.92 | 186 Views
By Ciscovid
Cisco IOS Firewall Video Data Sheet
Rated 4.70 | 75 Views
By Ciscovid
NAC Sport - Como El Deporte Se Fusiona Con...La Tecnología
Rated 1.52 | 105 Views
By NACsport
Nizam-ı Alem-i Cedid Klan Vidyosu
Rated 0.00 | 118 Views
By hokkabaz1
NAC Sport - Software De Video Análisis Par...a Todos Los Deportes
Rated 1.92 | 288 Views
By NACsport
Rated 4.43 | 7 Views
By BlackBox_NS
Rated 1.00 | 2 Views
By OSEO
Cisco CCENT 640-822 Network Basics for the...CCENT Course
Rated 3.51 | 188 Views
Affiliate Submitter: LiveTrain
Cisco $10K Edge Quest Tournament of Aces:...Can You Handle It?
Rated 2.67 | 32 Views
By CiscoSP360
Tata Communications First to Launch Cisco...TelePresence Pay-Per-U
Rated 4.30 | 119 Views
By MultiVu
$100,000 Cisco Developer Contest - Think I...nside the Box
Rated 3.02 | 163 Views
By Ethan-B
Cisco Crossover Cable for Router Connections
Rated 3.99 | 349 Views
Affiliate Submitter: diablocable