Cisco security flaw impacts critical SA infrastructure

So much for being a leader in Gartner's Magic Quadrant.

Sies Cisco. Any news from Dimension Data on this?
Got a response just before 15:00.

Dimension Data has been made aware of a cyber-attack affecting Cisco Clients.

We are working with Cisco to help resolve the issue. Affected Clients will be contacted directly by Cisco.
 
Got a response just before 15:00.

Dimension Data has been made aware of a cyber-attack affecting Cisco Clients.

We are working with Cisco to help resolve the issue. Affected Clients will be contacted directly by Cisco.
Bit of a hospital pass that. I suppose they are a value added reseller with no value.
 
Update from Seacom:

As an Internet Service Provider, our customers utilise IP addresses assigned by us, which can make it challenging to differentiate a customer’s private device from the SEACOM core network.

SEACOM customers manage their independent networks, but they connect to the SEACOM network using IP addresses provided by SEACOM. These IP addresses may associate a customer's device with the SEACOM network. It's important to emphasise that a device on a customer's private network, even if it uses a SEACOM-assigned IP address, does not introduce vulnerabilities to the SEACOM network.

SEACOM wants to reassure our customers that, even though we employ Cisco routers in specific sections of our network, we do not enable HTTP. Therefore, we can confirm that our network is not exposed to vulnerabilities.
 
Got a response just before 15:00.

Dimension Data has been made aware of a cyber-attack affecting Cisco Clients.

We are working with Cisco to help resolve the issue. Affected Clients will be contacted directly by Cisco.
Don’t mean to nitpick but how are they working with Cisco to resolve the issue when Cisco themselves doesn’t have a fix?
 
Don’t mean to nitpick but how are they working with Cisco to resolve the issue when Cisco themselves doesn’t have a fix?
You disable the http management server or some of the loadable modules.
 
i thought best practice was to disable any form of management (http/https/ssh) from the internet , and use a vpn :unsure::whistling::X3::rolleyes::confused::cautious:
 
Don’t mean to nitpick but how are they working with Cisco to resolve the issue when Cisco themselves doesn’t have a fix?

most likely some corporate bs language to deflect.
 
The arrogance of digital IT is inexcusable. Since the "invention" of Viruses, Worms, Exploits, any digital evil you can think of, its now how many years---Yes many enough, that no permanent cure is found, the problem just getting bigger and more, so where does this and the digital expenses leave your cutomers, I mean how long must we put up with this type on nonsense-?
 
The arrogance of digital IT is inexcusable. Since the "invention" of Viruses, Worms, Exploits, any digital evil you can think of, its now how many years---Yes many enough, that no permanent cure is found, the problem just getting bigger and more, so where does this and the digital expenses leave your cutomers, I mean how long must we put up with this type on nonsense-?
There will never be a permanent cure.
 
The arrogance of digital IT is inexcusable. Since the "invention" of Viruses, Worms, Exploits, any digital evil you can think of, its now how many years---Yes many enough, that no permanent cure is found, the problem just getting bigger and more, so where does this and the digital expenses leave your cutomers, I mean how long must we put up with this type on nonsense-?
You must have no idea how IT works. There will always be vulnerablies out there. No code is 100% secure nor will there ever be a 'cure' to make everything 100% secure. With enough time and resources almost everything can be exploited in some form or other.

The human is the weakest link with social engineering, unpatched systems, weak passwords. The list goes on.
 
There will never be a permanent cure.
There is but it will never be implemented for the sake of convenience. How many exploits use buffer overflows? Well every processor since ~2000 checks for execution and data only code and out of bounds access. Yet on Windows I could access and change every byte of memory with a crafted pointer. Even Linux started to use monolithic design.
 
Top
Sign up to the MyBroadband newsletter
X