Showing posts with label NSA. Show all posts
Showing posts with label NSA. Show all posts

Wednesday, April 12, 2017

WikiLeaks reveals that NSA has been spying on Pakistan’s mobile networks

WikiLeaks reveals that NSA has been spying on Pakistan’s mobile networks
The US National Security Agency (NSA) has been spying on Pakistan’s mobile networks, whistleblowing organisation WikiLeaks has tweeted. “Hundreds of NSA cyber weapons variants publicly released including code showing hacking of Pakistan mobile system,” @wikileaks tweeted.
According to a report in Express Tribune on Monday, the hacker group “Shadow Brokers” released a new cache of information detailing how the NSA accessed private and public networks in other countries. A researcher on Twitter who identifies himself as ‘x0rz’ decrypted the files and uploaded them on Github, a web-based repository and internet hosting service.
“The researcher confirmed that the archives include evidence of NSA operators’ access inside the GSM network of Mobilink – one of the Pakistan’s most popular mobile services provider,” the report noted. The hacker group had previously released data suggesting the US agency may have been monitoring hundreds of IP addresses in Pakistan. The encrypted files were being decrypted by security researchers around the world.
“Shadow Brokers” had initially wanted to auction its data cache in exchange for Bitcoin but as no buyer turned up, they released the data online. This is not the first time that reports have surfaced claiming that the US NSA is snooping on other countries. According to a Daily Mail report in 2014, WikiLeaks disclosed documents that suggested the Bharatiya Janata Party (BJP) was among six political parties from around the world the NSA was authorised to conduct surveillance on for gathering foreign intelligence. The authorisation was given by a secret American court, it said.
The leak was planned months ahead of Prime Minister Narendra Modi’s visit to the US, the report claimed. Another report in the Washington Post that also came in 2014 said the US has long had broad no-spying arrangements with four countries – Britain, Canada, Australia and New Zealand – in a group known collectively as the “Five Eyes”.
“But a classified 2010 legal certification – approved by the Foreign Intelligence Surveillance Court and included among a set of documents leaked by former NSA contractor Edward Snowden – lists 193 countries [including India], that would be of valid interest for US intelligence,” the Post said.
Publish date: April 12, 2017 11:45 am| Modified date: April 12, 2017 11:41 am

Wednesday, March 1, 2017

NSA fears talent drain as low morale and worries about Trump’s leadership take toll

NSA fears talent drain as low morale and worries about Trump’s leadership take toll

The National Security Agency (NSA) risks a brain-drain of hackers and cyber spies due to a tumultuous reorganization and worries about the acrimonious relationship between the intelligence community and President Donald Trump, according to current and former NSA officials and cybersecurity industry sources. Half-a-dozen cybersecurity executives told Reuters they had witnessed a marked increase in the number of U.S. intelligence officers and government contractors seeking employment in the private sector since Trump took office on January 20.
One of the executives, who would speak only on condition of anonymity, said he was stunned by the caliber of the would-be recruits. They are coming from a variety of government intelligence and law enforcement agencies, multiple executives said, and their interest stems in part from concerns about the direction of U.S intelligence agencies under Trump.
Retaining and recruiting talented technical personnel has become a top national security priority in recent years as Russia, China, Iran and other nation states and criminal groups have sharpened their cyber offensive abilities. NSA and other intelligence agencies have long struggled to deter some of their best employees from leaving for higher-paying jobs in Silicon Valley and elsewhere. The problem is especially acute at NSA, current and former officials said, due to a reorganization known as NSA21 that began last year and aims to merge the agency’s electronic eavesdropping and domestic cyber-security operations.
The two-year overhaul includes expanding parts of NSA that deal with business management and human resources and putting them on par with research and engineering. The aim is to “ensure that we’re using all of our resources to maximum effect to accomplish our mission,” NSA Director Mike Rogers said. The changes include new management structures that have left some career employees uncertain about their missions and prospects. Former employees say the reorganization has failed to address widespread concerns that the agency is falling behind in exploiting private-sector technological breakthroughs.
A former top NSA official said he had been told by three current officials that budget problems meant there was too little money for promotions. That is especially important for younger employees, who sometimes need two jobs to make ends meet in the expensive Washington D.C. area, the official said. “Morale is as low as I’ve ever seen it,” said another former senior NSA official, who maintains close contact with current employees.
Asked about the risk of losing talent from NSA and other agencies, White House spokesman Michael Anton said Trump had sought to reassure the intelligence community by visiting the CIA headquarters on his first full day in office. Anton also pointed to the military spending increase in Trump’s budget proposal released on Monday.
It will likely take more than a visit to the CIA to patch up relations with the intelligence community, the current and former officials said. Trump has attacked findings from intelligence agencies that Russia hacked emails belonging to Democratic Party operatives during the 2016 presidential campaign to help him win, though he did eventually accept the findings. In January, Trump accused intelligence agencies of leaking false information and said it was reminiscent of tactics used in Nazi Germany.
How many?
The breadth of any exodus from the NSA and other intelligence agencies is difficult to quantify. The NSA has “seen a steady rise” in the attrition rate among its roughly 36,000 employees since 2009, and it now sits at a “little less than six percent,” according to an NSA spokesman. NSA director Michael Rogers said last year that the attrition rate was 3.3 percent in 2015, suggesting a sharp jump in departures since then.
Several senior NSA officials who have left or plan to leave, including deputy director Richard Ledgett and the head of cyber defence, Curtis Dukes, have said their departures were unrelated to Trump or the reorganization. Some turnover is normal with any new administration, government and industry officials noted, and a stronger economy has also improved pay and prospects in the private sector.
“During this time the economy has been recovering from the recession, unemployment rates have been falling and the demand for highly skilled technical talent has been increasing,” an NSA spokesman said, when asked to comment on the reports of employee departures. In a statement, Kathy Hutson, NSA’s chief of human resources, said the agency continues “to attract amazing talent necessary to conduct the security mission the nation needs.”
Controversial Boss
Some NSA veterans attribute the morale issues and staff departures to the leadership style of Rogers, who took over the spy agency in 2014 with the task of dousing an international furore caused by leaks from former contractor Edward Snowden. Concern about Rogers reached an apex last October, when former Defense Secretary Ash Carter and former Director of National Intelligence James Clapper recommended to then-President Barack Obama that Rogers be removed.
The NSA did not respond to a request for comment on the recommendation last fall that Rogers be replaced. Rogers is now expected to retain his job at NSA for at least another year, according to former officials. Rogers acknowledged concerns about potential morale problems last month, telling a congressional committee that Trump’s broadsides against the intelligence community could create “a situation where our workforce decides to walk.”
Trump’s criticism of the intelligence community has exacerbated the stress caused by the reorganization at the NSA, said Susan Hennessey, a former NSA lawyer now with Brookings Institution. The “tone coming from the White House makes an already difficult situation worse, by eroding the sense of common purpose and service,” she said. A wave of departures of career personnel, Hennessey added, “would represent an incalculable loss to national security.”
Reuters

Thursday, December 15, 2016

Hackers took control of a unclassified email system in Pentagon in 2015

Hackers took control of a unclassified email system in Pentagon in 2015

Representational Image
Russian hackers seized control last year of the unclassified email system used by the U.S. military’s Joint Chiefs of Staff, CBS News reported on Thursday, citing an interview with then-Joint Chiefs of Staff Chairman Martin Dempsey.
Dempsey, who did not appear on camera, said he was alerted to the August 2015 attack by an early morning phone call from the director of the National Security Agency, Admiral Mike Rogers, according to CBS. The email system is used by the Pentagon’s Joint Staff, an organization of some 3,500 military officers and civilians who work for the chairman.
The hackers seized the passwords and electronic signatures used by Dempsey, an Army general who retired in September 2015, and hundreds of other senior officers to sign on to the network, according to CBS. The only way to stop the attack was to take the network down, CBS said.
The attack, which U.S. officials now blame on Russia, was not spying, but a full-on assault whose only apparent purpose was to cause damage and force the Pentagon to replace both hardware and software, which took about two weeks to accomplish, according to CBS.
The motive for the attack was believed to be Russian anger at economic sanctions orchestrated by the Obama administration in response to Russian President Vladimir Putin’s annexation of Crimea and interference in Ukraine, CBS said.
The Pentagon declined to comment. U.S. officials have accused Putin of supervising his intelligence agencies’ hacking of the U.S. presidential election in an effort to help Republican Donald Trump. Russian officials have denied accusations of interference in the Nov. 8 election won by Trump.
Reuters

Saturday, December 10, 2016

US and UK spies tried accessing data from passengers’ mobile phones on commercial airline, says report

US and UK spies tried accessing data from passengers’ mobile phones on commercial airline, says report

American and British spy agencies have tried to intercept data from passengers’ mobile phones on commercial airlines including Air France, French media has reported, citing documents from US whistleblower Edward Snowden.
The French flag-carrier was an early target of the US National Security Agency and its British counterpart GCHQ as it was seen as a terrorist target and it carried out tests in 2007 on allowing the use of mobile phones on its aircraft.
“The use of mobile phones with Internet connections in the sky gave rise to the creation of specific programs at the NSA and GCHQ,” said Le Monde, which has access to Snowden’s archive in partnership with news website The Intercept.
While it is not normally possible to make phone calls on planes, some carriers allow passengers to connect to a cabin Wi-Fi, allowing them to use internet-based functions on their handsets.
In 2012, at least 27 airlines allowed passengers to use mobile phones on board, including British Airways, Aeroflot, Etihad, Cathay Pacific, Lufthansa and Singapore Airlines.
But Air France was “such a symbol of the surveillance of communications on board airlines that the British spy agency used a drawing of one of their planes to illustrate how the interception worked.”
Asked about the British and American surveillance claims, Air France told Le Monde, “We are visibly not the only ones to have been targeted and we know absolutely nothing about these practices.”
According to the report, internal documents from the two agencies describe the results of the “impressive” programs – codenamed “Thieving Magpie” and “Homing Pigeon” – which allowed data to be collected “almost in real time”.
In order to spy on a telephone, all that was needed was that the aircraft be cruising at an altitude above 10,000 feet, the report said.
Secret aerial stations on the ground could intercept the signal as it transited through a satellite.
“The simple fact that the telephone was switched on was enough to give away its position, the interception could then be cross-referenced with the list of known passengers on the flight, the flight number, and the airline code to determine the name of the smartphone user,” the report said.
The mobile phone’s function could also be disrupted, it said, forcing the user to input their access codes and thereby allowing the British spy agency to intercept the information.
Snowden, a former National Security Agency contractor, leaked thousands of classified documents to the press in 2013 which revealed the vast scope of US surveillance of private data that was put in place after the 9/11 attacks.
After fleeing his home in Hawaii, he now lives in exile in Russia where he has sought asylum.
Should he ever return to the United States, Snowden would be tried for espionage and other charges carrying up to 30 years in prison.
AFP

Tuesday, November 1, 2016

Shadow Brokers reveal more tools from NSA trove

Shadow Brokers reveal more tools from NSA trove

Image Credit: Venture Beat
A group calling itself “Shadow Brokers” says it has released another gem from its trove of high-level hacking tools stolen from the U.S.’s National Security Agency, potentially offering added insight into how America’s spies operate online. The leak discloses NSA-style codenames — including “Jackladder” and “Dewdrop”— and carries internet protocol information about scores of organizations, many based in Japan, China and South Korea, according to severalexperts who have examined the data.
Matthew Hickey, co-founder of U.K.-based cybersecurity consultancy Hacker House, said it was plausible that the servers would have seen use as staging posts to help obfuscate the origin of electronic eavesdropping operations. More worrying for the NSA, the leak backs Shadow Brokers’ claims to have stolen an as-yet undisclosed set of electronic lock picks from the agency.
“Those can be hard to generate,” Hickey said in a telephone interview, calling it “quite expensive to replicate all those tools.” Shadow Brokers has been closely followed by intelligence watchers and cybersecurity specialists since the group released an initial set of NSA hacking tools back in August. The seriousness of the leak was confirmed when security companies rushed to patch holes in their software revealed by the disclosure.
The Intercept, an investigative publication with access to NSA material leaked by former intelligence contractor Edward Snowden, later confirmed Shadow Brokers’ tools were really from the NSA by cross-referencing the leaked data with information held in a previously unpublished top secret manual. The authenticity of the latest batch of material could not immediately be established, although Hickey said any hoax would have to have been unusually elaborate.
Shadow Brokers did not return messages seeking comment Monday. The NSA declined to comment.
AP

Monday, October 31, 2016

Shadow Brokers reveals list of Servers Hacked by the NSA

nsa-shadow-brokers








The hacker group calling itself the Shadow Brokers, who previously claimed to have 
leaked a portion of the NSA’s hacking tools and exploits, is back with a Bang!


The Shadow Brokers published more files today, and this time the group dumped a list of foreign servers allegedly compromised by the NSA-linked hacking unit, Equation Group, in various countries to expand its espionage operations.

Top 3 Targeted Countries — China, Japan, and Korea


The data dump [Download / File Password: payus] that experts believe contains 306 domain names, and 352 IP addresses belong to at least 49 countries. As many as 32 domains of the total were run by educational institutes in China and Taiwan.

A few target domains were based in Russia, and at least nine domains include .gov websites.

The top 10 targeted countries include China, Japan, Korea, Spain, Germany, India, Taiwan, Mexico, Italy, and Russia.

The latest dump has been signed by the same key as the first Shadow Brokers’ dump of NSA exploits, though there is a lot to be done to validate the contents of the leaked data dump fully.

Targeted Systems — Solaris, Unix, Linux and FreeBSD


Most of the affected servers were running Solaris, Oracle-owned Unix-based operating system, while some were running FreeBSD or Linux.

Each compromised servers were reportedly targets of INTONATION and PITCHIMPAIR, code-names given for cyber-spy hacking programs.

The data dump also contains references to a list of previously undisclosed Equation Group tools, including Dewdrop, Incision, Orangutan, Jackladder, Reticulum, Patchicillin, Sidetrack and Stoicsurgeon.

The tools as mentioned above could be hacking implants, tools or exploits used by the NSA's notorious group.

Security researcher Mustafa Al-Bassam, an ex-member of Lulzsec and the Anonymous hacking collective, said the NSA likely compromised all the servers between 2000 and 2010.
"So even the NSA hacks machines from compromised servers in China and Russia. This is why attribution is hard," Al-Bassam added. 

Are Hackers trying to influence U.S. Presidential elections?


A message accompanying the leaked data dump calls for attempts to disrupt the forthcoming United States presidential election. The portion of message from the Shadow Brokers reads:
"TheShadowBrokers is having suggestion. On November 8th, instead of not voting, maybe be stopping the vote all together? Maybe being grinch who stopped the election from coming? Maybe hacking election is being the best idea? #hackelection2016."
Targeted victims can use the leaked files in an effort to determine if they were the potential target of the NSA-linked hacking unit.

Since the records are old, many servers should now be clean of infection. However, a brief Shodan scan of these domains indicates that some of the affected servers are still active and still running old, possibly-vulnerable systems.

The latest release comes after the FBI arrested Harold Thomas Martin, an NSA contractor, who was reportedly a prime suspect in The Shadow Brokers case.

Friday, October 28, 2016

Booz Allen Hamilton has hired former FBI chief to review security after NSA contractor gets arrested

Booz Allen Hamilton has hired former FBI chief to review security after NSA contractor gets arrested

Image Credit: REUTERS
Booz Allen Hamilton said on Thursday it had hired a former FBI chief to conduct an external review of its security practices, after the consulting firm learnt for the second time in three years that an employee working under contract with the National Security Agency had been charged with stealing classified information.
Booz Allen, which earns billions of dollars a year contracting with U.S. intelligence agencies, has come under renewed scrutiny in recent weeks after authorities took Harold Thomas Martin into custody. The firm also employed Edward Snowden, who leaked a trove of secret files to news organizations in 2013 that exposed vast domestic and international surveillance operations carried out by the NSA. Snowden, who was in Hong Kong when his disclosures surfaced, lives in Moscow under asylum.
Former Federal Bureau of Investigation Director Robert Mueller is leading the audit of security, personnel and management practices, Booz Allen said in a statement. The review began on Oct. 19. Martin, 51, was taken into custody in August, but his arrest was not announced publicly until earlier this month. Prosecutors have alleged he spent more than two decades pilfering secret documents and hoarding them at his home in Maryland, where investigators said they seized at least 50 terabytes of data.
Among the material allegedly stolen by Martin was a top secret document that contained “specific operational plans against a known enemy of the United States and its allies,” the prosecutors said. The FBI is investigating possible links between Martin and the leak online this summer of secret NSA hacking tools used to break into the computers of adversaries such as Russia and China, U.S. officials said.
“We fired Harold Martin as soon as we learnt of his arrest, and we have been fully cooperating with the FBI’s investigation,” Booz Allen spokesman Craig Veith said. “We are determined to learn from this incident and look more broadly at our processes and practices.”
Reuters

Friday, October 7, 2016

Challenges to tackle Insider threat regains focus after the arrest of former NSA contractor

Challenges to tackle Insider threat regains focus after the arrest of former NSA contractor

The arrest of a former National Security Agency contractor for allegedly stealing classified information represents the second known case since 2013 of a government contractor being publicly accused of removing secret data from the intelligence agency. The latest case comes as the NSA has worked to reform security after the Edward Snowden disclosures, especially with regard to insider threats.
Harold Thomas Martin III, 51, of Glen Burnie, Maryland, was arrested by the FBI in August after federal prosecutors say he illegally removed highly classified information and stored the material in his home and car. A defence attorney said Martin did not intend to betray his country.
The arrest was not made public until Wednesday when the Justice Department unsealed a criminal complaint that accused Martin of having been in possession of top-secret information that could cause “exceptionally grave danger” to national security if disclosed.
It’s not yet clear when the documents were removed. But the fact that Snowden and Martin – both working for Booz Allen Hamilton as contractors for the NSA – were accused of leaving the NSA with highly classified documents raises questions about the effectiveness and adequacy of the intelligence agency’s internal security controls. The NSA, which put security upgrades into place following the Snowden disclosures, has declined to comment.
“One key thing we don’t have visibility into now is how he was caught because that would provide some insight into whether the reforms that were put in post-Snowden were effective or not or their relative efficacy,” said Rajesh De, who was the NSA’s general counsel when the Snowden story broke. Snowden’s 2013 theft of documents that were leaked to journalists revealed the NSA’s bulk collection of millions of Americans’ phone records.
Rep. Adam Schiff of California, the senior Democrat on the House Permanent Select Committee on Intelligence, said in a statement that “it is painfully clear that the intelligence community still has much to do to institutionalise reforms designed to protect (U.S. government secrets) from insider threats.”
White House spokesman Josh Earnest said the federal government has made important changes since Snowden’s disclosures. He said the government has reduced the number of people who need security clearances by 17 percent and has enhanced the quality of background checks. Martin’s arrest appears to illustrate the difficulty of guarding against an insider threat given that employees, by virtue of their clearance level and jobs, must be

Thursday, October 6, 2016

NSA contractor working for Edward Snowden's former employer charged with stealing secrets





By Rob Thubron on October 6, 2016, 10:30 AM


In what appears to be a case of history repeating itself, the NSA has arrested a contractor working for Booz Allen Hamilton, the same firm that employed Edward Snowden, and charged him with unauthorized removal and retention of classified materials, as well as theft of government property.

According to a statement from the Department of Justice, the contractor is 51-year old Maryland resident Harold Thomas Martin III. The criminal complaint against him states that investigators found thousands of physical and digital documents marked as top secret when they searched his home on August 27.

TechCrunch reports that the material contained hacking codes for government systems in Russia, China and North Korea. Moreover, six of the discovered documents were said to be of an extremely sensitive nature.

According to the complaint, Martin initially denied taking the documents but later admitted to storing them in his home and car, despite knowing they were classified. “Martin stated that he knew what he had done was wrong and that he should not have done it because he knew it was unauthorized,” the affidavit states.

Edward Snowden famously passed NSA documents on to journalists in 2013. It’s unclear if Martin leaked the information in the his documents, or if he passed them on to a third party. His lawyers told the New York Times: “We have not seen any evidence. But what we know is that Hal Martin loves his family and his country. There is no evidence that he intended to betray his country.”

While no connection between Martin and Snowden has been made, investigators discovered Martin’s alleged theft when they were looking into the recent Shadow Brokers leak, which exposed what appeared to be malware used by the NSA. The leak took place two weeks before Martin’s arrest, suggesting he may not have any connection to it.

If found guilty, Martin could face up to ten years behind bars for his crimes. If it’s discovered that he shared the information with anyone, the contractor may face charges under the Espionage Act, just as Edward Snowden does.

NSA contractor arrested for stealing highly classified information

NSA contractor arrested for stealing highly classified information

Image Credit: Wikimedia.org
A National Security Agency contractor has been arrested and charged with stealing highly classified information, authorities said on Wednesday, a data breach that could mark a damaging new leak about the US government’s surveillance efforts.
Harold Thomas Martin, 51, who worked for Booz Allen Hamilton, was taken into custody in Maryland in August, said a US official, speaking on condition of anonymity. Booze Allen is the consulting firm that employed Edward Snowden when he revealed the collection of metadata by the NSA in 2013.
Booz Allen said in a statement that when the company “learned of the arrest of one of its employees by the FBI,” they immediately fired the employee and offered full cooperation to the FBI.
The same month Martin was arrested, some of the NSA’s most sophisticated hacking tools were dumped onto public websites by a group calling itself Shadow Brokers.
The company’s stock was down 3.7 percent to $30.33 a share, following the report.
The US Justice Department charged Martin, who had top secret national security clearance, with theft of classified government material, according to

Tuesday, October 4, 2016

Anyone? Anyone? Hackers find little demand for their stolen NSA hacking tools





Hackers claim to have stolen files that may belong to the NSA. Credit: National Security Agency


Michael Kan
IDG News Service
Oct 3, 2016 12:18 PM
The ShadowBrokers' auction for the hacking tools has so far generated little interest.
The hackers who are auctioning off cyberweapons allegedly stolen from the National Security Agency are growing annoyed and want cash.

The ShadowBrokers' sale of the stolen tools has so far generated little interest, and over the weekend, the hackers complained in a message posted online, using broken English.


"TheShadowBrokers is not being interested in fame. TheShadowBrokers is selling to be making money," the hackers said.

As of Monday, their auction only had one substantial bid at 1.5 bitcoins, or US $918. Many of the other bids were valued at less than $1.

The hackers originally dumped a sample of the stolen hacking tools back in mid-August, and independent security experts later found the tools to actually work. The tools include exploits designed to compromise firewall and router products from Cisco, Juniper Networks, and Fortinet and are probably worth a fortune.

The hackers claim they have more cyber weapons to sell. However, they've taken the unusual step of offering them up through an open online auction relying on bitcoin.

Although anyone can participate, the hackers haven't said when they'll accept the final bid. The hackers also hoped to receive 1 million bitcoins, or $611 million, in exchange for leaking all they stole for free to the public.

The unusual conditions have led some security researchers to suspect the auction is a publicity stunt. But the ShadowBrokers claim in their latest posting that the auction is real, despite "sounding crazy."

"Expert peoples is saying Equation Group Firewall Tool Kit worth $1 million," the group said

Tuesday, September 27, 2016

Cisco finds new Zero-Day Exploit linked to NSA Hackers


Cisco finds new Zero-Day Exploit linked to NSA Hackers
Network equipment vendor Cisco is finally warning its customers of another zero-day vulnerability the company discovered in the trove of NSA's hacking exploits and implants leaked by the group calling itself "The Shadow Brokers."

Last month, the Shadow Brokers published firewall exploits, implants, and hacking tools allegedly stolen from the NSA's Equation Group, which was designed to target major vendors including, Cisco, Juniper, and Fortinet.

A hacking exploit, dubbed ExtraBacon, leveraged a zero-day vulnerability (CVE-2016-6366) resided in the Simple Network Management Protocol (SNMP) code of Cisco ASA software that could allow remote attackers to cause a reload of the affected system or execute malicious code.

Now Cisco has found another zero-day exploit, dubbed "Benigncertain," which targets PIX firewalls.

Cisco analyzed the exploit and noted that it had not identified any new flaws related to this exploit in its current products.

But, further analysis of Benigncertain revealed that the exploit also affects Cisco products running IOS, IOS XE and IOS XR software.

Benigncertain leveraged the vulnerability (CVE-2016-6415) that resides in the IKEv1 packet processing code and affects several Cisco devices running IOS operating system and all Cisco PIX firewalls.

IKE (Internet Key Exchange) is a protocol used for firewalls, to provide virtual private networks (VPNs), and even manage industrial control systems.

A remote, unauthorized attacker could use this vulnerability to retrieve memory contents from traffic and disclose critical information such as RSA private keys and configuration information by sending specially crafted IKEv1 packets to affected devices.

"The vulnerability is due to insufficient condition checks in the part of the code that handles IKEv1 security negotiation requests. An attacker could exploit this vulnerability by sending a crafted IKEv1 packet to an affected device configured to accept IKEv1 security negotiation requests," Cisco said in itsadvisory.

Cisco's IOS operating system XR versions 4.3.x, 5.0.x, 5.1.x and 5.2.x, as well as PIX firewalls versions 6.x and earlier, are vulnerable to this flaw, though the company has not supported PIX since 2009.

Neither Cisco has developed a patch for the flaw, nor any workarounds are available.

The company said the vulnerability is currently under exploit, advising its customers to employ intrusion detection system (IDS) and intrusion prevention systems (IPS) to help stop the attacks.

Cisco promised to release software updates to patch CVE-2016-6415 but did not specify a time frame.
Related Posts Plugin for WordPress, Blogger...