<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>elamb &#187; john chambers ceo</title>
	<atom:link href="http://elamb.org/category/john-chambers-ceo/feed/" rel="self" type="application/rss+xml" />
	<link>http://elamb.org</link>
	<description>information system security, risk management, scam research</description>
	<lastBuildDate>Mon, 28 Nov 2011 02:27:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Cisco to be under scrutiny again at Black Hat</title>
		<link>http://elamb.org/cisco-to-be-under-scrutiny-again-at-black-hat/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cisco-to-be-under-scrutiny-again-at-black-hat</link>
		<comments>http://elamb.org/cisco-to-be-under-scrutiny-again-at-black-hat/#comments</comments>
		<pubDate>Fri, 21 Jul 2006 14:54:18 +0000</pubDate>
		<dc:creator>elamb</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Defcon]]></category>
		<category><![CDATA[DIGG]]></category>
		<category><![CDATA[john chambers ceo]]></category>
		<category><![CDATA[Main Digg]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/cisco-to-be-under-scrutiny-again-at-black-hat/</guid>
		<description><![CDATA[&#8220;Cisco Systems Inc.&#8217;s products will again come under scrutiny at this year&#8217;s Black Hat USA 2006 conference, which kicks off later this month in Las Vegas. Conference organizers say that 15 new exploits will be discussed at this year&#8217;s event &#8230; <a href="http://elamb.org/cisco-to-be-under-scrutiny-again-at-black-hat/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>&#8220;Cisco Systems Inc.&#8217;s products will again come under scrutiny at this year&#8217;s Black Hat USA 2006 conference, which kicks off later this month in Las Vegas. Conference organizers say that 15 new exploits will be discussed at this year&#8217;s event and that two of them target NAC (Network Admission Control).&#8221;</p>
<p>Now if Cisco had any understanding of the importants of transparency with the technical community in this age of free information, they would break this news themselves and have solutions and mitigations to fix it. Instead they are too worried about the bottom line (the shareholders) which will take a hit anyway once the media gets a hold of it.</p>
<p>Mr. John Chambers, despite the security issues you&#8217;ve got great products, but get a clue about how to deal with these problems.</p>
<p><a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&#038;articleId=9001885">read more</a>Â |Â <a href="http://digg.com/security/Cisco_to_be_under_scrutiny_again_at_Black_Hat">digg story</a></p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/cisco-to-be-under-scrutiny-again-at-black-hat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CISCO LEAP (lightweight Extensible Authentication Protocol) Weak?</title>
		<link>http://elamb.org/cisco-leap-lightweight-extensible-authentication-protocol-weak/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cisco-leap-lightweight-extensible-authentication-protocol-weak</link>
		<comments>http://elamb.org/cisco-leap-lightweight-extensible-authentication-protocol-weak/#comments</comments>
		<pubDate>Wed, 31 Aug 2005 21:43:36 +0000</pubDate>
		<dc:creator>elamb.security</dc:creator>
		<br />
<b>Warning</b>:  Invalid argument supplied for foreach() in <b>/home/elamb_security/elamb.org/wp-content/plugins/autometa/autometa.php</b> on line <b>300</b><br />
		<category><![CDATA[Dictionary Attacks]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Internet and Information Technology Security]]></category>
		<category><![CDATA[john chambers ceo]]></category>
		<category><![CDATA[Passwords]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Awareness]]></category>
		<category><![CDATA[Wireless]]></category>

	<!-- AutoMeta Start -->
	<!-- AutoMeta End -->
	
		<guid isPermaLink="false">http://elamb.org/?p=175</guid>
		<description><![CDATA[Light weight EAP is Cisco&#39;s proprietary version of Extensible Authentication Protocol (EAP, used mainly for wireless&#160;LANs).&#160; Cisco graciously allowed vendors to&#160;support LEAP using Cisco Certified Extenstion (CCX).&#160; Cisco owns about 60% of the wireless market with 46% of those using &#8230; <a href="http://elamb.org/cisco-leap-lightweight-extensible-authentication-protocol-weak/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Light weight EAP is Cisco&#39;s proprietary version of Extensible Authentication Protocol (EAP, used mainly for wireless&nbsp;LANs).&nbsp; Cisco graciously allowed vendors to&nbsp;support LEAP using Cisco Certified Extenstion (CCX).&nbsp;</p>
<p>Cisco owns about 60% of the wireless market with 46% of those using Light Weight Extensible Authentication Protocol according to the research group nemertes.&nbsp; </p>
<p align="center"><strong>HAZZAAA!! Cisco is secure&#8230;</strong></p>
<p align="center"><strong>(except against Dictionary Attacks)</strong></p>
<p>With such a large piece of the wireless market using LEAP, Cisco had sucessfully advertised LEAP as a secure protocol.&nbsp; Unfortunately, LEAP is weak against Dictionary Attacks (<a href="http://www.computerworld.com/printthis/2003/0,4814,85637,00.html">Brewin</a>).</p>
<p>At <strong>DEFCON 11</strong>, on August 1, 2003, Joshua Wright did a presentation on the <a href="http://home.jwu.edu/jwright/presentations/asleap-defcon.pdf">weakness of LEAP</a>.&nbsp; </p>
<p>&nbsp;</p>
<p><strong>Here is Cisco&#39;s response to Leap Dictionary attacks:</strong></p>
<blockquote>
<p>To help our customers respond to the possibility of dictionary attacks, Cisco strongly recommends that all of our customers to review their security policies and institute the previously published best practices that are outlined below and in the <a href="http://www.cisco.com/en/US/netsol/ns340/ns394/ns171/ns128/networking_solutions_package.html">Cisco SAFE White Papers</a>. </p>
<p>&#8226;<img height="2" src="http://www.cisco.com/warp/public/illus/images/blank.gif" width="19" border="0">Use a strong password policy (as detailed below) and periodically expire user passwords (recommended at least every three months) giving users advanced warning to change passwords before they expire. </p>
<p>&#8226;<img height="2" src="http://www.cisco.com/warp/public/illus/images/blank.gif" width="19" border="0">If unable to implement a strong password policy, consider migrating to another EAP type like EAP-FAST, PEAP or EAP-TLS whose authentication methods are not susceptible to dictionary attacks: </p>
<p>&#8211;<img height="2" src="http://www.cisco.com/warp/public/illus/images/blank.gif" width="17" border="0">EAP-FAST is an authentication protocol that creates a secure tunnel without using certificates. </p>
<p>&#8211;<img height="2" src="http://www.cisco.com/warp/public/illus/images/blank.gif" width="17" border="0">PEAP is a hybrid authentication protocol that creates a secured TLS tunnel between the WLAN user and the RADIUS server to authenticate the user to the network. </p>
<p>&#8211;<img height="2" src="http://www.cisco.com/warp/public/illus/images/blank.gif" width="17" border="0">EAP-TLS uses pre-issued digital certificates to authenticate a user to the network.</p>
<p>&nbsp;</p>
</blockquote>
<p align="center"><strong>FINAL NOTE:</strong></p>
<p>&#8220;1 month of audits by l33t security companies: No vulnerabilities<br />1 month of architecture research by CCIE&#39;s: No vulnerabilities<br />2 days of hacking by DaBubble, Bishop, and Evol: Root.<br />There&#39;s some things that fackers should audit (WEBAPPS) for everything else, get a real hacker.&#8221; &#8212; <a href="http://securityfocus.com/archive/1/340184">SecurityFocus</a></p>
<p><strong>Why doesn&#39;t Cisco become more hacker friendly.</strong>&nbsp; They pissed off the Security Profesionals and Hackers alike with that <a href="http://elamb.blogharbor.com/blog/_archives/2005/8/2/1100703.html">CiscoGate fiasco</a>, don&#39;t have any <a href="http://derad.typepad.com/onlinecrimebytes/2005/08/stupidity_from_.html">cool hacker parties at the Defcon</a>.. I mean what is the deal, <a href="http://newsroom.cisco.com/dlls/tln/exec_team/chambers/">John Chambers</a>?!&nbsp; </p>
<p>John, I doubt you will ever read this blog, but here goes anyway, I think that Cisco has great products.&nbsp; I believe in Cisco&#39;s amazing engineering, but if you guys don&#39;t aggressively attack security issues PROACTIVELY, you will drop from first class to third class quickly.&nbsp; I&#39;m not trying to tell you how to run cisco, I&#39;m just saying, why not use hackers and their finding to your advantage.&nbsp; </p>
<p>Take the IE browser as an example: they used to own 95% of the market, consumners got so fed up with its lack of security that now Firefox (co-created by&nbsp;Blake Ross Intern/Hacker) is doing something not even Netscape could do.&nbsp;&nbsp; </p>
<p>&nbsp;</p>
<p align="center"><strong>Reference:</strong></p>
<p>EAP. <a href="http://www.faqs.org/rfcs/rfc2284.html">RFC 2284</a>. Extensible Authentication Protocol. </p>
<p>EAP, <a href="http://en.wikipedia.org/wiki/Extensible_Authentication_Protocol">Extensible Authentication Protocol Wiki</a>. Wikipedia.org</p>
<p>George C. Ou. <a href="http://www.lanarchitect.net/Articles/Wireless/LEAP/">Leap: A looming disaster in Enterprise Wireless LANs</a>.&nbsp; Lanarchitecture.net</p>
<p>nemertes, <a href="http://www.nemertes.com/node/view/94">Cisco Warns its WLAN Security can be Cracked</a>. nemertes.com</p>
<p>Brewin, Bob. <a href="http://www.computerworld.com/printthis/2003/0,4814,85637,00.html">Cisco Warn its WLAN Security can be Cracked</a>. computerworld.com</p>
<p>Cisco, <a href="http://home.jwu.edu/jwright/presentations/asleap-defcon.pdf">Abusing 802.11: Weaknesses in LEAP Challenge/Response</a>. Defcon 11/2003</p>
<p>Cisco. <a href="http://www.cisco.com/en/US/products/hw/wireless/ps430/prod_bulletin09186a00801cc901.html">Cisco Response to Dictionary Attacks on Cisco Leap</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://elamb.org/cisco-leap-lightweight-extensible-authentication-protocol-weak/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

