PDA

Click to See Complete Forum and Search --> : Cisco.com compromised


sweet_angel
August 3rd, 2005, 09:30 PM
IMPORTANT NOTICE:

* Cisco has determined that Cisco.com password protection has been compromised.
* As a precautionary measure, Cisco has reset your password. To receive your new password, send a blank e-mail, from the account which you entered upon registration, to cco-locksmith@cisco.com. Account details with a new random password will be e-mailed to you.
* Because of a large number of requests, registered Cisco.com users may experience delays in receiving the new passwords.
* This incident does not appear to be due to a weakness in Cisco products or technologies.

http://www.cisco.com/cgi-bin/login

After michael lynn case..? I think every security researcher have been watching Cisco now..

stevel
August 3rd, 2005, 11:29 PM
As they say... mess with the bull, you get the horns. I wonder how long their servers will be overloaded.

Egaladeist
August 4th, 2005, 02:07 AM
Looks good on them ! :D

hesperus
August 4th, 2005, 02:22 AM
Yes, but remember :

* This incident does not appear to be due to a weakness in Cisco products or technologies.

Whew ! ! At least no one else needs to worry . . . ::ha-sign:

Noia
August 4th, 2005, 08:52 AM
is it just me, or could a spoofed e-mail with a reply-to tag cause alot of problems right about now?? Just a thought...

IKnowNot
August 4th, 2005, 12:09 PM
Well, I'm drunk now, but when I first read this on isc.incidents.org yesterday I thought something similar.

Why would they put up such a notice unless they had some sort of defense against it ??????

IKnowNot
August 5th, 2005, 09:37 PM
Well Noia , it seems others ( not Cisco ) think the same way we do!

From Handlers Diary August 4th 2005 (http://isc.sans.org/diary.php?date=2005-08-04)

Cisco CCO Password Reset Reply-To Spoof Concern
Testing confirmed a spoofed reply-to field in a message to the CCO Locksmith would be accepted.
We notified the Cisco PSIRT team and they are reviewing the spoofed reply-to issue.