Archive for January, 2007

Dark Sun Rising for BrightStor Clients

January 31, 2007 by Jose Nazario

In the past few months, the folks at LSsecurity have found and disclosed several buffer overflows in the CA BrightStor product lines. These are all remotely exploitable vulnerabilities, and exploit code has been released for several of these issues, including CVE-2006-5143 describing issues in msgeng.exe on TCP port 6503, and CVE-2006-6076 for issues in the [...]

Read More

The ‘Attack’ IP Option Against Core Infrastructure (Cisco’s Triple Vuln Play)

January 26, 2007 by Jose Nazario

A couple of days ago a series of three vulnerabilities in Cisco IOS and IOS XR were disclosed. The most severe of these may allow for remote code execution on the affected device, a possibility made less theoretical after Blackhat 2005. The three issues are: Cisco Security Advisory: Crafted IP Option Vulnerability, the most serious [...]

Read More

On DDoS Attack Activity

January 26, 2007 by Danny McPherson

We’ve been doing analysis on the DDoS attack and network traffic distribution data some of our Peakflow SP customers are providing and I figured I’d share a bit of a teaser. The data is shared with Arbor via an optional module within Peakflow SP, so if you’re wondering how it’s gathered have a look here. [...]

Read More