<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Cisco Security Advisory: FWSM Crafted ICMP Message Vulnerability</title>
	<atom:link href="http://www.firstdigest.com/2009/08/cisco-security-advisory-fwsm-crafted-icmp-message-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.firstdigest.com/2009/08/cisco-security-advisory-fwsm-crafted-icmp-message-vulnerability/</link>
	<description>Cisco  &#124;  How to do it</description>
	<lastBuildDate>Sun, 14 Mar 2010 08:38:04 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Calin</title>
		<link>http://www.firstdigest.com/2009/08/cisco-security-advisory-fwsm-crafted-icmp-message-vulnerability/comment-page-1/#comment-771</link>
		<dc:creator>Calin</dc:creator>
		<pubDate>Thu, 03 Sep 2009 06:41:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.firstdigest.com/?p=1721#comment-771</guid>
		<description>&lt;p&gt;Jayson, in the lab test I could not crash a FWSM with all kind of ICMP traffic. In our real environment we have some FWSM modules, but also I didn&#039;t noticed any bad behavior due to some strange ICMP traffic. On web, forums, blogs and so on...nobody strongly suggest that they had such a problem.&lt;/p&gt;
&lt;p&gt;So, I believe that it exist indeed, but the probability to happen is not high for the moment as there is not a known exploit for this vulnerability.&lt;/p&gt;</description>
		<content:encoded><![CDATA[<p>Jayson, in the lab test I could not crash a FWSM with all kind of ICMP traffic. In our real environment we have some FWSM modules, but also I didn&#8217;t noticed any bad behavior due to some strange ICMP traffic. On web, forums, blogs and so on&#8230;nobody strongly suggest that they had such a problem.</p>
<p>So, I believe that it exist indeed, but the probability to happen is not high for the moment as there is not a known exploit for this vulnerability.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jayson</title>
		<link>http://www.firstdigest.com/2009/08/cisco-security-advisory-fwsm-crafted-icmp-message-vulnerability/comment-page-1/#comment-731</link>
		<dc:creator>Jayson</dc:creator>
		<pubDate>Fri, 28 Aug 2009 06:51:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.firstdigest.com/?p=1721#comment-731</guid>
		<description>Hi Calin,
So is this vulnerability only a lab case from Cisco?  There are no user reports that were affected with this?
Thanks!</description>
		<content:encoded><![CDATA[<p>Hi Calin,<br />
So is this vulnerability only a lab case from Cisco?  There are no user reports that were affected with this?<br />
Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Calin</title>
		<link>http://www.firstdigest.com/2009/08/cisco-security-advisory-fwsm-crafted-icmp-message-vulnerability/comment-page-1/#comment-727</link>
		<dc:creator>Calin</dc:creator>
		<pubDate>Thu, 27 Aug 2009 13:51:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.firstdigest.com/?p=1721#comment-727</guid>
		<description>&lt;p&gt;Chintan, if we take Cisco&#039;s words  &quot;...the following ACL, when deployed on a Cisco IOS 	 device in front of the FWSM...&quot; than you can apply it on the VLAN on C6500. I believe in this case doesn&#039;t matter if the device in front is a real separate device, connected with a cooper/fiber/etc cable to the chassis holding the FWSM or through backplane.&lt;/p&gt;
&lt;p&gt;The important thing is that this crafted ICMP packets not to arrive /travel through FWSM. Anyway for me the description of this vulnerability is a little bit ambiguous due to the fact that we don&#039;t know for sure what ICMP packet can make FWSM crash.&lt;/p&gt;
&lt;p&gt;I tested with a FWSM, with different type of ICMP packets and different patterns, but I could not crash the device...&lt;/p&gt;</description>
		<content:encoded><![CDATA[<p>Chintan, if we take Cisco&#8217;s words  &#8220;&#8230;the following ACL, when deployed on a Cisco IOS 	 device in front of the FWSM&#8230;&#8221; than you can apply it on the VLAN on C6500. I believe in this case doesn&#8217;t matter if the device in front is a real separate device, connected with a cooper/fiber/etc cable to the chassis holding the FWSM or through backplane.</p>
<p>The important thing is that this crafted ICMP packets not to arrive /travel through FWSM. Anyway for me the description of this vulnerability is a little bit ambiguous due to the fact that we don&#8217;t know for sure what ICMP packet can make FWSM crash.</p>
<p>I tested with a FWSM, with different type of ICMP packets and different patterns, but I could not crash the device&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chintan</title>
		<link>http://www.firstdigest.com/2009/08/cisco-security-advisory-fwsm-crafted-icmp-message-vulnerability/comment-page-1/#comment-722</link>
		<dc:creator>Chintan</dc:creator>
		<pubDate>Thu, 27 Aug 2009 11:19:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.firstdigest.com/?p=1721#comment-722</guid>
		<description>If i have 6500 with FWSM installed Can I apply this w/a (ACL) on 6500 itself on logical VLAN interface towards FWSM ? will this protect ?</description>
		<content:encoded><![CDATA[<p>If i have 6500 with FWSM installed Can I apply this w/a (ACL) on 6500 itself on logical VLAN interface towards FWSM ? will this protect ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: &#160; Cisco Security Advisory: FWSM Crafted ICMP Message Vulnerability &#8230;&#160;by&#160;Cisco Information Technology</title>
		<link>http://www.firstdigest.com/2009/08/cisco-security-advisory-fwsm-crafted-icmp-message-vulnerability/comment-page-1/#comment-671</link>
		<dc:creator>&#160; Cisco Security Advisory: FWSM Crafted ICMP Message Vulnerability &#8230;&#160;by&#160;Cisco Information Technology</dc:creator>
		<pubDate>Fri, 21 Aug 2009 15:17:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.firstdigest.com/?p=1721#comment-671</guid>
		<description>[...] View post: Cisco Security Advisory: FWSM Crafted ICMP Message Vulnerability &#8230; [...]</description>
		<content:encoded><![CDATA[<p>[...] View post: Cisco Security Advisory: FWSM Crafted ICMP Message Vulnerability &#8230; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cisco Security Advisory: FWSM Crafted ICMP Message Vulnerability &#8230; &#124; Hack In The Box</title>
		<link>http://www.firstdigest.com/2009/08/cisco-security-advisory-fwsm-crafted-icmp-message-vulnerability/comment-page-1/#comment-670</link>
		<dc:creator>Cisco Security Advisory: FWSM Crafted ICMP Message Vulnerability &#8230; &#124; Hack In The Box</dc:creator>
		<pubDate>Fri, 21 Aug 2009 14:20:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.firstdigest.com/?p=1721#comment-670</guid>
		<description>[...] Cisco Security Advisory: FWSM Crafted ICMP Message Vulnerability &#8230;   Share and [...]</description>
		<content:encoded><![CDATA[<p>[...] Cisco Security Advisory: FWSM Crafted ICMP Message Vulnerability &#8230;   Share and [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Calin</title>
		<link>http://www.firstdigest.com/2009/08/cisco-security-advisory-fwsm-crafted-icmp-message-vulnerability/comment-page-1/#comment-669</link>
		<dc:creator>Calin</dc:creator>
		<pubDate>Fri, 21 Aug 2009 10:39:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.firstdigest.com/?p=1721#comment-669</guid>
		<description>&lt;p&gt;Thanks for the comment. I updated my post to avoid confusions!&lt;/p&gt;</description>
		<content:encoded><![CDATA[<p>Thanks for the comment. I updated my post to avoid confusions!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: João Sena Ribeiro</title>
		<link>http://www.firstdigest.com/2009/08/cisco-security-advisory-fwsm-crafted-icmp-message-vulnerability/comment-page-1/#comment-668</link>
		<dc:creator>João Sena Ribeiro</dc:creator>
		<pubDate>Fri, 21 Aug 2009 10:23:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.firstdigest.com/?p=1721#comment-668</guid>
		<description>Those ACLs don&#039;t block &quot;regular&quot; pings, only less commonly used ICMP packet types. As you can see, ICMP &#039;echo&#039;, &#039;echo-reply&#039;, &#039;host-unreachable&#039;, etc. are still allowed.
Regards.</description>
		<content:encoded><![CDATA[<p>Those ACLs don&#8217;t block &#8220;regular&#8221; pings, only less commonly used ICMP packet types. As you can see, ICMP &#8216;echo&#8217;, &#8216;echo-reply&#8217;, &#8216;host-unreachable&#8217;, etc. are still allowed.<br />
Regards.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
