Date: Sun, 26 Apr 2009 23:23:44 +0200
Subject: Re: [c-nsp] 6500 sup720-3bxl crash
Hmmm ... same today morning !?
Cache error detected!
CPO_ECC (reg 26/0): 0x0000009F
CPO_CACHERI (reg 27/0): 0xA0000000
CP0_CAUSE (reg 13/0): 0x00000800
Real cache error detected. System will be halted.
Error: Primary data cache, fields: data,
Actual physical addr 0x00000000,
virtual address is imprecise.
Imprecise Data Parity Error
Imprecise Data Parity Error
Interrupt exception, CPU signal 20, PC = 0x40E7BE6C
========= Start of Crashinfo Collection (07:05:17 GMT Sun Apr 26 2009) =========
IOS (tm) s72033_sp Software (s72033_sp-IPSERVICESK9-M), Version 12.2(18)SXF14, RELEASE SOFTWARE (fc1)
On Sun, Apr 26, 2009 at 01:13:05PM -0700, John van Oppen wrote:
> Has anyone seen this reload cause before? Sounds like bad memory but
> the memory addresses are pretty non machine sounding some I am wondering
> if it is a software bug.
>
>
> Cache error detected!
> CPO_ECC (reg 26/0): 0x000000F3
> CPO_CACHERI (reg 27/0): 0x84000000
> CP0_CAUSE (reg 13/0): 0x00004400
>
> Real cache error detected. System will be halted.
>
> Error: Primary data cache, fields: , 1st dword
> Actual physical addr 0x00000000,
> virtual address is imprecise.
>
> Imprecise Data Parity Error
>
>
> Software version is: s72033_sp-ADVIPSERVICESK9_WAN-M), Version
> 12.2(33)SXI, RELEASE SOFTWARE (fc2)
>
>
> Thanks,
> John
同時多発でCatalyst6500+Sup720-3BXLに問題発生か。
日本にもいっぱい入ってるんじゃないかな?大丈夫なのかな?
4/27/2009
4/09/2009
cisco-nsp@Apr 8, 2009
Date: Wed, 8 Apr 2009 12:01:39 -0400
From: Cisco Systems Product Security Incident Response Team
Subject: [c-nsp] Cisco Security Advisory: Multiple Vulnerabilities in
Cisco ASA Adaptive Security Appliance and Cisco PIX Security
Appliances
To: cisco-nsp@puck.nether.net
Cc: psirt@cisco.com
Message-ID: <200904081201.asa@psirt.cisco.com>
Content-Type: Text/Plain; charset="us-ascii"
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Cisco Security Advisory: Multiple Vulnerabilities in Cisco ASA Adaptive
Security Appliance and Cisco PIX Security Appliances
Advisory ID: cisco-sa-20090408-asa
http://www.cisco.com/warp/public/707/cisco-sa-20090408-asa.shtml
Revision 1.0
For Public Release 2009 April 08 1600 UTC (GMT)
Summary
=======
Multiple vulnerabilities exist in the Cisco ASA 5500 Series Adaptive
Security Appliances and Cisco PIX Security Appliances. This security
advisory outlines the details of these vulnerabilities:
* VPN Authentication Bypass when Account Override Feature is Used
vulnerability
* Crafted HTTP packet denial of service (DoS) vulnerability
* Crafted TCP Packet DoS vulnerability
* Crafted H.323 packet DoS vulnerability
* SQL*Net packet DoS vulnerability
* Access control list (ACL) bypass vulnerability
Workarounds are available for some of the vulnerabilities.
This advisory is posted at
http://www.cisco.com/warp/public/707/cisco-sa-20090408-asa.shtml.
Affected Products
=================
Vulnerable Products
+------------------
The following is a list of the products affected by each vulnerability
as described in detail within this advisory.
VPN Authentication Bypass Vulnerability
+--------------------------------------
Cisco ASA or Cisco PIX security appliances that are configured for IPsec
or SSL-based remote access VPN and have the Override Account Disabled
feature enabled are affected by this vulnerability.
Note: The Override Account Disabled feature was introduced in Cisco
ASA software version 7.1(1). Cisco ASA and PIX software versions 7.1,
7.2, 8.0, and 8.1 are affected by this vulnerability. This feature is
disabled by default.
Crafted HTTP Packet DoS Vulnerability
+------------------------------------
Cisco ASA security appliances may experience a device reload that can be
triggered by a series of crafted HTTP packets, when configured for SSL
VPNs or when configured to accept Cisco Adaptive Security Device Manager
(ASDM) connections. Only Cisco ASA software versions 8.0 and 8.1 are
affected by this vulnerability.
Crafted TCP Packet DoS Vulnerability
+-----------------------------------
Cisco ASA and Cisco PIX security appliances may experience a memory leak
that can be triggered by a series of crafted TCP packets. Cisco ASA and
Cisco PIX security appliances running versions 7.0, 7.1, 7.2, 8.0, and
8.1 are affected when configured for any of the following features:
* SSL VPNs
* ASDM Administrative Access
* Telnet Access
* SSH Access
* Cisco Tunneling Control Protocol (cTCP) for Remote Access VPNs
* Virtual Telnet
* Virtual HTTP
* Transport Layer Security (TLS) Proxy for Encrypted Voice
Inspection
* Cut-Through Proxy for Network Access
* TCP Intercept
Crafted H.323 Packet DoS Vulnerability
+-------------------------------------
Cisco ASA and Cisco PIX security appliances may experience a device
reload that can be triggered by a series of crafted H.323 packets, when
H.323 inspection is enabled. H.323 inspection is enabled by default.
Cisco ASA and Cisco PIX software versions 7.0, 7.1, 7.2, 8.0, and 8.1
are affected by this vulnerability.
SQL*Net Packet DoS Vulnerability
+-------------------------------
Cisco ASA and Cisco PIX security appliances may experience a device
reload that can be triggered by a series of SQL*Net packets, when
SQL*Net inspection is enabled. SQL*Net inspection is enabled by default.
Cisco ASA and Cisco PIX software versions 7.2, 8.0, and 8.1 are affected
by this vulnerability.
Access Control List Bypass Vulnerability
+---------------------------------------
A vulnerability exists in the Cisco ASA and Cisco PIX security
appliances that may allow traffic to bypass the implicit deny behavior
at the end of ACLs that are configured within the device. Cisco ASA and
Cisco PIX software versions 7.0, 7.1, 7.2, and 8.0 are affected by this
vulnerability.
Determination of Software Versions
+---------------------------------
The "show version" command-line interface (CLI) command can be used to
determine whether a vulnerable version of the Cisco PIX or Cisco ASA
software is running. The following example shows a Cisco ASA Adaptive
Security Appliance that runs software version 8.0(4):
ASA#show version
Cisco Adaptive Security Appliance Software Version 8.0(4)
Device Manager Version 6.0(1)
From: Cisco Systems Product Security Incident Response Team
Subject: [c-nsp] Cisco Security Advisory: Multiple Vulnerabilities in
Cisco ASA Adaptive Security Appliance and Cisco PIX Security
Appliances
To: cisco-nsp@puck.nether.net
Cc: psirt@cisco.com
Message-ID: <200904081201.asa@psirt.cisco.com>
Content-Type: Text/Plain; charset="us-ascii"
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Cisco Security Advisory: Multiple Vulnerabilities in Cisco ASA Adaptive
Security Appliance and Cisco PIX Security Appliances
Advisory ID: cisco-sa-20090408-asa
http://www.cisco.com/warp/public/707/cisco-sa-20090408-asa.shtml
Revision 1.0
For Public Release 2009 April 08 1600 UTC (GMT)
Summary
=======
Multiple vulnerabilities exist in the Cisco ASA 5500 Series Adaptive
Security Appliances and Cisco PIX Security Appliances. This security
advisory outlines the details of these vulnerabilities:
* VPN Authentication Bypass when Account Override Feature is Used
vulnerability
* Crafted HTTP packet denial of service (DoS) vulnerability
* Crafted TCP Packet DoS vulnerability
* Crafted H.323 packet DoS vulnerability
* SQL*Net packet DoS vulnerability
* Access control list (ACL) bypass vulnerability
Workarounds are available for some of the vulnerabilities.
This advisory is posted at
http://www.cisco.com/warp/public/707/cisco-sa-20090408-asa.shtml.
Affected Products
=================
Vulnerable Products
+------------------
The following is a list of the products affected by each vulnerability
as described in detail within this advisory.
VPN Authentication Bypass Vulnerability
+--------------------------------------
Cisco ASA or Cisco PIX security appliances that are configured for IPsec
or SSL-based remote access VPN and have the Override Account Disabled
feature enabled are affected by this vulnerability.
Note: The Override Account Disabled feature was introduced in Cisco
ASA software version 7.1(1). Cisco ASA and PIX software versions 7.1,
7.2, 8.0, and 8.1 are affected by this vulnerability. This feature is
disabled by default.
Crafted HTTP Packet DoS Vulnerability
+------------------------------------
Cisco ASA security appliances may experience a device reload that can be
triggered by a series of crafted HTTP packets, when configured for SSL
VPNs or when configured to accept Cisco Adaptive Security Device Manager
(ASDM) connections. Only Cisco ASA software versions 8.0 and 8.1 are
affected by this vulnerability.
Crafted TCP Packet DoS Vulnerability
+-----------------------------------
Cisco ASA and Cisco PIX security appliances may experience a memory leak
that can be triggered by a series of crafted TCP packets. Cisco ASA and
Cisco PIX security appliances running versions 7.0, 7.1, 7.2, 8.0, and
8.1 are affected when configured for any of the following features:
* SSL VPNs
* ASDM Administrative Access
* Telnet Access
* SSH Access
* Cisco Tunneling Control Protocol (cTCP) for Remote Access VPNs
* Virtual Telnet
* Virtual HTTP
* Transport Layer Security (TLS) Proxy for Encrypted Voice
Inspection
* Cut-Through Proxy for Network Access
* TCP Intercept
Crafted H.323 Packet DoS Vulnerability
+-------------------------------------
Cisco ASA and Cisco PIX security appliances may experience a device
reload that can be triggered by a series of crafted H.323 packets, when
H.323 inspection is enabled. H.323 inspection is enabled by default.
Cisco ASA and Cisco PIX software versions 7.0, 7.1, 7.2, 8.0, and 8.1
are affected by this vulnerability.
SQL*Net Packet DoS Vulnerability
+-------------------------------
Cisco ASA and Cisco PIX security appliances may experience a device
reload that can be triggered by a series of SQL*Net packets, when
SQL*Net inspection is enabled. SQL*Net inspection is enabled by default.
Cisco ASA and Cisco PIX software versions 7.2, 8.0, and 8.1 are affected
by this vulnerability.
Access Control List Bypass Vulnerability
+---------------------------------------
A vulnerability exists in the Cisco ASA and Cisco PIX security
appliances that may allow traffic to bypass the implicit deny behavior
at the end of ACLs that are configured within the device. Cisco ASA and
Cisco PIX software versions 7.0, 7.1, 7.2, and 8.0 are affected by this
vulnerability.
Determination of Software Versions
+---------------------------------
The "show version" command-line interface (CLI) command can be used to
determine whether a vulnerable version of the Cisco PIX or Cisco ASA
software is running. The following example shows a Cisco ASA Adaptive
Security Appliance that runs software version 8.0(4):
ASA#show version
Cisco Adaptive Security Appliance Software Version 8.0(4)
Device Manager Version 6.0(1)
4/08/2009
cisco-nsp@Apr 7, 2009
Date: Tue, 7 Apr 2009 18:51:44 +0300
From: Emanuel Popa
Subject: [c-nsp] carrier router models comparison
To: Cisco Mailing list
Message-ID:
<4981ce080904070851h6381d4f0qf35885793e959087@mail.gmail.com>
Content-Type: text/plain; charset=ISO-8859-1
hi there,
due to the increase in traffic volume in the last couple of years we
need to really think about the future of the network. we have deployed
and we are managing a 50GE multi-ring topology network with Cisco 7600
routers. i don't want to get into more details about ring topology
restrictions, platform limitations regarding wire speed, huge problems
with ether-channels or unpredictable load balancing behaviour. we've
been using these chassis since 2004 starting with STM-16 lines and the
PQ ratio looks pretty good so far.
coming back to nowadays, 40GE or 100GE is not available yet, and even
if it was, the price would be probably unaffordable. and now the
question pops: what is the next step? the best answer is of course a
mix of multiple 10GE lines with traffic engineering and partial mesh
topology and 100GE ready chassis. first thing that comes to mind is
the CRS-1 platform, but it is really expensive: from under 15K per
10GE port with the Cisco 7600 you have to pay more than 75K per 10GE
port with the CRS-1. so we have to take into consideration what are
the alternatives. i will try a short comparison:
- Cisco CRS-1 16 Slot
--- max 64 x 10GE
--- max 32 links in a bundle
--- 40Gbps per slot
--- 100GE ready
--- multi-chassis ready
--- 10.920W max power
--- 723kg max weight
--- full rack space
--- $5.115.000,00/chassis
--- $79.921,88/10GE
- Juniper T1600
--- max 64 x 10GE
--- max 16 links in a bundle
--- 100Gbps per slot
--- 100GE ready
--- multi-chassis ready
--- 8.352W max power
--- 274,88kg max weight
--- 1/2 rack space
--- $6.547.000,00/chassis
--- $102.296,88/10GE
- Brocade/ Foundry NetIron XMR 16000
--- max 64 x 10GE
--- max 32 links in a bundle
--- 50Gbps per slot
--- 100GE ready (* only full slots)
--- single-chassis
--- 5.572W max power
--- 107,00kg max weight
--- 1/3 rack space
--- $567.515,00/chassis
--- $8.867,42/10GE
I've also been looking at Huawei, Alcatel and HP gear but haven't been
able to find a device to support more than 24 x 10GE ports in a single
chassis.
Here's what I'm trying to figure out:
1. are there any other devices on the market with same hardware capabilities?
2. why the huge difference between foundry and cisco/juniper?
3. if foundry is so cheap why hasn't it gathered more market share?
instead it was bought by brocade a while ago...
4. is the netiron really a carrier router more than a carrier switch?
anybody experienced it?
5. how does the software perform when comparing with IOS XR and JunOS?
Please, any comments are welcomed.
Best regards,
Manu
40G、100Gインターフェースが出てくるときにどの大型ルータを買うべきか。
質問の形を取っているが、ここまで纏まっていれば自分で検討できるだろうに。
もしかして、これは新手のマーケティング・セールスなのか!
From: Emanuel Popa
Subject: [c-nsp] carrier router models comparison
To: Cisco Mailing list
Message-ID:
<4981ce080904070851h6381d4f0qf35885793e959087@mail.gmail.com>
Content-Type: text/plain; charset=ISO-8859-1
hi there,
due to the increase in traffic volume in the last couple of years we
need to really think about the future of the network. we have deployed
and we are managing a 50GE multi-ring topology network with Cisco 7600
routers. i don't want to get into more details about ring topology
restrictions, platform limitations regarding wire speed, huge problems
with ether-channels or unpredictable load balancing behaviour. we've
been using these chassis since 2004 starting with STM-16 lines and the
PQ ratio looks pretty good so far.
coming back to nowadays, 40GE or 100GE is not available yet, and even
if it was, the price would be probably unaffordable. and now the
question pops: what is the next step? the best answer is of course a
mix of multiple 10GE lines with traffic engineering and partial mesh
topology and 100GE ready chassis. first thing that comes to mind is
the CRS-1 platform, but it is really expensive: from under 15K per
10GE port with the Cisco 7600 you have to pay more than 75K per 10GE
port with the CRS-1. so we have to take into consideration what are
the alternatives. i will try a short comparison:
- Cisco CRS-1 16 Slot
--- max 64 x 10GE
--- max 32 links in a bundle
--- 40Gbps per slot
--- 100GE ready
--- multi-chassis ready
--- 10.920W max power
--- 723kg max weight
--- full rack space
--- $5.115.000,00/chassis
--- $79.921,88/10GE
- Juniper T1600
--- max 64 x 10GE
--- max 16 links in a bundle
--- 100Gbps per slot
--- 100GE ready
--- multi-chassis ready
--- 8.352W max power
--- 274,88kg max weight
--- 1/2 rack space
--- $6.547.000,00/chassis
--- $102.296,88/10GE
- Brocade/ Foundry NetIron XMR 16000
--- max 64 x 10GE
--- max 32 links in a bundle
--- 50Gbps per slot
--- 100GE ready (* only full slots)
--- single-chassis
--- 5.572W max power
--- 107,00kg max weight
--- 1/3 rack space
--- $567.515,00/chassis
--- $8.867,42/10GE
I've also been looking at Huawei, Alcatel and HP gear but haven't been
able to find a device to support more than 24 x 10GE ports in a single
chassis.
Here's what I'm trying to figure out:
1. are there any other devices on the market with same hardware capabilities?
2. why the huge difference between foundry and cisco/juniper?
3. if foundry is so cheap why hasn't it gathered more market share?
instead it was bought by brocade a while ago...
4. is the netiron really a carrier router more than a carrier switch?
anybody experienced it?
5. how does the software perform when comparing with IOS XR and JunOS?
Please, any comments are welcomed.
Best regards,
Manu
40G、100Gインターフェースが出てくるときにどの大型ルータを買うべきか。
質問の形を取っているが、ここまで纏まっていれば自分で検討できるだろうに。
もしかして、これは新手のマーケティング・セールスなのか!
4/04/2009
cisco-nsp@Apr 3, 2009
Date: Fri, 3 Apr 2009 10:14:52 -0400
From: Joe Loiacono
Subject: Re: [c-nsp] Monitoring External Web Server
To: "Aaron Riemer"
Cc: cisco-nsp-bounces@puck.nether.net, cisco-nsp@puck.nether.net
Message-ID:
Content-Type: text/plain; charset="US-ASCII"
If you want to go commercial, we use a software-as-a-service (SAAS)
product called Gomez. You periodically contact your server from
browser-client nodes on their backbone. You can also execute scripts from
these nodes that will walk through your web-site in a pre-determined way.
The pricing model is based on a 'cost per measurement' subscription where
a measurement is an access of a web-site from a test node. If you do it
hourly, that would be 24 per day, etc.
Joe
"Aaron Riemer"
Sent by: cisco-nsp-bounces@puck.nether.net
04/03/2009 12:50 AM
To
cc
Subject
[c-nsp] Monitoring External Web Server
Hey guys,
We have a requirement to monitor the external availability of a web
server that hangs off our ASA DMZ interface. I was thinking of running
an IP SLA probe from our external router to test the web requests but I
was wondering if anyone had done something with EEM that could possibly
try to establish a TCP connection to the web server and report the
statistics somehow. I don't want to place a machine outside for the
monitoring so would prefer to do it from our router if possible.
Any thoughts?
Thanks,
Aaron.
外部にあるWebサーバのモニタリングをするのはどうしたらいい?回線にはSLAがあるが
サーバは?という質問に対する返答。
Gomezという商用SaaS製品を使っていますという回答。
nagiosとかbigbrotherとかでもいいと思うんだけど。
From: Joe Loiacono
Subject: Re: [c-nsp] Monitoring External Web Server
To: "Aaron Riemer"
Cc: cisco-nsp-bounces@puck.nether.net, cisco-nsp@puck.nether.net
Message-ID:
Content-Type: text/plain; charset="US-ASCII"
If you want to go commercial, we use a software-as-a-service (SAAS)
product called Gomez. You periodically contact your server from
browser-client nodes on their backbone. You can also execute scripts from
these nodes that will walk through your web-site in a pre-determined way.
The pricing model is based on a 'cost per measurement' subscription where
a measurement is an access of a web-site from a test node. If you do it
hourly, that would be 24 per day, etc.
Joe
"Aaron Riemer"
Sent by: cisco-nsp-bounces@puck.nether.net
04/03/2009 12:50 AM
To
cc
Subject
[c-nsp] Monitoring External Web Server
Hey guys,
We have a requirement to monitor the external availability of a web
server that hangs off our ASA DMZ interface. I was thinking of running
an IP SLA probe from our external router to test the web requests but I
was wondering if anyone had done something with EEM that could possibly
try to establish a TCP connection to the web server and report the
statistics somehow. I don't want to place a machine outside for the
monitoring so would prefer to do it from our router if possible.
Any thoughts?
Thanks,
Aaron.
外部にあるWebサーバのモニタリングをするのはどうしたらいい?回線にはSLAがあるが
サーバは?という質問に対する返答。
Gomezという商用SaaS製品を使っていますという回答。
nagiosとかbigbrotherとかでもいいと思うんだけど。
4/01/2009
cisco-nsp@Mar 31, 2009
Date: Tue, 31 Mar 2009 10:29:19 +0200
From: luismi
Subject: Re: [c-nsp] IP Address management software
To: Gary Roberton
Cc: "cisco-nsp@puck.nether.net"
Message-ID: <1238488159.7827.0.camel@dsba-ipso>
Content-Type: text/plain; charset=utf-8
We use here IPPlan.
El mar, 31-03-2009 a las 09:17 +0100, Gary Roberton escribi?:
> Hello all
>
> What IP address management software do you use to control the allocation of
> subnets to your customers/department?
>
> Thanks
>
> Gary
IPアドレス管理にどのようなソフトを使っているかという質問に対しての返答。
IPPlanを使っているとの事。
Excelで管理したり、Wikiを使ったり、RADBやMyAPNICで管理したり色々あると思いますが。
From: luismi
Subject: Re: [c-nsp] IP Address management software
To: Gary Roberton
Cc: "cisco-nsp@puck.nether.net"
Message-ID: <1238488159.7827.0.camel@dsba-ipso>
Content-Type: text/plain; charset=utf-8
We use here IPPlan.
El mar, 31-03-2009 a las 09:17 +0100, Gary Roberton escribi?:
> Hello all
>
> What IP address management software do you use to control the allocation of
> subnets to your customers/department?
>
> Thanks
>
> Gary
IPアドレス管理にどのようなソフトを使っているかという質問に対しての返答。
IPPlanを使っているとの事。
Excelで管理したり、Wikiを使ったり、RADBやMyAPNICで管理したり色々あると思いますが。
3/27/2009
cisco-nsp@Mar 26, 2009
Date: Thu, 26 Mar 2009 10:10:17 -0700
From: Inca
Subject: [c-nsp] Free/low-cost traffic generator?
To: cisco-nsp@puck.nether.net
Message-ID:
Content-Type: text/plain; charset=ISO-8859-1
Does anyone know of a free (open source or otherwise) or low cost
traffic generator that we can use to stress test multiple gigabit
links simultaneously? Ideally, it would be a software package that one
can install on *nix/OSX/Windows.
Thanks!
いつもはCisco社製品に関する内容や相互接続性に関するような内容を議論する
メーリングリストなのですが、たまにこういう一般的な質問も出てきます。
回答としてNetperf,iperf,d-itgなどのTool紹介がありました。
From: Inca
Subject: [c-nsp] Free/low-cost traffic generator?
To: cisco-nsp@puck.nether.net
Message-ID:
Content-Type: text/plain; charset=ISO-8859-1
Does anyone know of a free (open source or otherwise) or low cost
traffic generator that we can use to stress test multiple gigabit
links simultaneously? Ideally, it would be a software package that one
can install on *nix/OSX/Windows.
Thanks!
いつもはCisco社製品に関する内容や相互接続性に関するような内容を議論する
メーリングリストなのですが、たまにこういう一般的な質問も出てきます。
回答としてNetperf,iperf,d-itgなどのTool紹介がありました。
3/26/2009
Multipost@Mar 25, 2009
Nordnog
Cisco Security Advisory: Cisco IOS cTCP Denial of Service Vulnerability
Cisco Security Advisory: Cisco IOS Software Multiple Features IP Sockets Vulnerability
Cisco Security Advisory: Cisco IOS Software Secure Copy Privilege Escalation Vulnerability
Cisco Security Advisory: Cisco IOS Software Mobile IP and Mobile IPv6 Vulnerabilities
Cisco Security Advisory: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability
Cisco Security Advisory: Cisco IOS Software Multiple Features Crafted TCP Sequence Vulnerability
Cisco Security Advisory: Cisco IOS Software Multiple Features Crafted UDP Packet Vulnerability
Cisco Security Advisory: Cisco IOS Software WebVPN and SSLVPN Vulnerabilities
JANOG
[janog:08829] Cisco Security Advisory: Cisco IOS cTCP Denial of Service Vulnerability
[janog:08830] Cisco Security Advisory: Cisco IOS Software Mobile IP and Mobile IPv6 Vulnerabilities
[janog:08831] Cisco Security Advisory: Cisco IOS Software Multiple Features IP Sockets Vulnerability
cisco-nsp
Cisco Security Advisory: Cisco IOS Software Mobile IP and Mobile IPv6 Vulnerabilities(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS cTCP Denial of Service Vulnerability(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software WebVPN and SSLVPN Vulnerabilities(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Secure Copy Privilege Escalation Vulnerability(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Multiple Features IP Sockets Vulnerability(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Multiple Features Crafted TCP Sequence Vulnerability(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Multiple Features Crafted UDP Packet Vulnerability(Cisco Systems Product Security Incident Response Team)
SANOG
[SANOG] Cisco Security Advisory: Cisco IOS Software Secure Copy Privilege Escalation Vulnerability
[SANOG] Cisco Security Advisory: Cisco IOS Software Multiple Features Crafted TCP Sequence Vulnerability
[SANOG] Cisco Security Advisory: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability
[SANOG] Cisco Security Advisory: Cisco IOS Software Multiple Features Crafted UDP Packet Vulnerability
[SANOG] Cisco Security Advisory: Cisco IOS Software WebVPN and SSLVPN Vulnerabilities
APOPS
Cisco Security Advisory: Cisco IOS Software Multiple Features Crafted TCP Sequence Vulnerability(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Multiple Features IP Sockets Vulnerability(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Multiple Features Crafted UDP Packet Vulnerability(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Mobile IP and Mobile IPv6 Vulnerabilities(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS cTCP Denial of Service Vulnerability (Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software WebVPN and SSLVPN Vulnerabilities(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Secure Copy Privilege Escalation Vulnerability(Cisco Systems Product Security Incident Response Team)
NANOG
Cisco Security Advisory: Cisco IOS cTCP Denial of Service Vulnerability (Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Mobile IP and Mobile IPv6 Vulnerabilities(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Secure Copy Privilege Escalation Vulnerability(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Multiple Features Crafted TCP Sequence Vulnerability(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software WebVPN and SSLVPN Vulnerabilities(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Multiple Features IP Sockets Vulnerability(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Multiple Features Crafted UDP Packet Vulnerability(Cisco Systems Product Security Incident Response Team)
CiscoSystems-PSIRTから出たセキュリティアドバイザリの案内が各MLに流れた。
cisco-nspは当然のこととして、NANOG,Nordnog,apopsは8件全て情報が流れた。
しかし、SANOGは5件、JANOGは3件(取りこぼしであればご容赦)。
各地域のネットワーク機器の状況を全てPSIRTのメンバーが知っているはずがないので脆弱性を選んで各MLに投げているとは思えない。
なんでこんな違いになるのだろう?
確認した限り、AusNOG, NZNOG, GTER等には流れていませんでした。これからかな?
Cisco Security Advisory: Cisco IOS cTCP Denial of Service Vulnerability
Cisco Security Advisory: Cisco IOS Software Multiple Features IP Sockets Vulnerability
Cisco Security Advisory: Cisco IOS Software Secure Copy Privilege Escalation Vulnerability
Cisco Security Advisory: Cisco IOS Software Mobile IP and Mobile IPv6 Vulnerabilities
Cisco Security Advisory: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability
Cisco Security Advisory: Cisco IOS Software Multiple Features Crafted TCP Sequence Vulnerability
Cisco Security Advisory: Cisco IOS Software Multiple Features Crafted UDP Packet Vulnerability
Cisco Security Advisory: Cisco IOS Software WebVPN and SSLVPN Vulnerabilities
JANOG
[janog:08829] Cisco Security Advisory: Cisco IOS cTCP Denial of Service Vulnerability
[janog:08830] Cisco Security Advisory: Cisco IOS Software Mobile IP and Mobile IPv6 Vulnerabilities
[janog:08831] Cisco Security Advisory: Cisco IOS Software Multiple Features IP Sockets Vulnerability
cisco-nsp
Cisco Security Advisory: Cisco IOS Software Mobile IP and Mobile IPv6 Vulnerabilities(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS cTCP Denial of Service Vulnerability(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software WebVPN and SSLVPN Vulnerabilities(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Secure Copy Privilege Escalation Vulnerability(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Multiple Features IP Sockets Vulnerability(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Multiple Features Crafted TCP Sequence Vulnerability(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Multiple Features Crafted UDP Packet Vulnerability(Cisco Systems Product Security Incident Response Team)
SANOG
[SANOG] Cisco Security Advisory: Cisco IOS Software Secure Copy Privilege Escalation Vulnerability
[SANOG] Cisco Security Advisory: Cisco IOS Software Multiple Features Crafted TCP Sequence Vulnerability
[SANOG] Cisco Security Advisory: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability
[SANOG] Cisco Security Advisory: Cisco IOS Software Multiple Features Crafted UDP Packet Vulnerability
[SANOG] Cisco Security Advisory: Cisco IOS Software WebVPN and SSLVPN Vulnerabilities
APOPS
Cisco Security Advisory: Cisco IOS Software Multiple Features Crafted TCP Sequence Vulnerability(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Multiple Features IP Sockets Vulnerability(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Multiple Features Crafted UDP Packet Vulnerability(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Mobile IP and Mobile IPv6 Vulnerabilities(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS cTCP Denial of Service Vulnerability (Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software WebVPN and SSLVPN Vulnerabilities(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Secure Copy Privilege Escalation Vulnerability(Cisco Systems Product Security Incident Response Team)
NANOG
Cisco Security Advisory: Cisco IOS cTCP Denial of Service Vulnerability (Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Mobile IP and Mobile IPv6 Vulnerabilities(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Secure Copy Privilege Escalation Vulnerability(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Multiple Features Crafted TCP Sequence Vulnerability(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software WebVPN and SSLVPN Vulnerabilities(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Multiple Features IP Sockets Vulnerability(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability(Cisco Systems Product Security Incident Response Team)
Cisco Security Advisory: Cisco IOS Software Multiple Features Crafted UDP Packet Vulnerability(Cisco Systems Product Security Incident Response Team)
CiscoSystems-PSIRTから出たセキュリティアドバイザリの案内が各MLに流れた。
cisco-nspは当然のこととして、NANOG,Nordnog,apopsは8件全て情報が流れた。
しかし、SANOGは5件、JANOGは3件(取りこぼしであればご容赦)。
各地域のネットワーク機器の状況を全てPSIRTのメンバーが知っているはずがないので脆弱性を選んで各MLに投げているとは思えない。
なんでこんな違いになるのだろう?
確認した限り、AusNOG, NZNOG, GTER等には流れていませんでした。これからかな?
登録:
投稿 (Atom)