All the latest UK technology news, reviews and analysis

Cert warns of web meltdown

by John Geralds in Silicon Valley

13 Feb 2002

Be the first to comment

  • Tweet this

The Computer Emergency Response Team (Cert) has warned that numerous security holes in the Simple Network Management Protocol (SNMP) could shut down or cut off routers, PCs and other devices from the internet. It has already notified more than 200 manufacturers about the flaws.

Caldera, 3Com, Cisco Systems, Compaq, Hewlett Packard, IBM, Juniper Networks, Sun Microsystems, Microsoft, Lucent, Nokia and Network Associates are among the vendors that have either reported or are working on fixes for software flaws that could leave the web's basic infrastructure in danger of disruption.

The vulnerabilities involve the way in which SNMP implementations, which enable network administrators to remotely monitor and configure routers, switches, operating systems and network management systems, handle warning and error messages and requests.

If exploited, the vulnerabilities could allow attackers to disable the networked devices, cause denial of service interruptions to websites and even gain administrative control over the devices, according to Cert.

The flaws were first discovered by the Secure Programming Group at Finland's Oulu University. The team found multiple vulnerabilities in the way SNMP version one is implemented in many vendors' products.

Cert said that hundreds of vendors use the internet protocol found to be at risk and recommended that administrators disable SNMP on any machine that does not need it for normal operations.

"Large scale outages of these devices could disable significant portions of the global network," Cert said in its alert.

The group also warned that the problem is most serious for internet service providers which use routers to manage the flow of messages across computer networks and the web.

More information about the vulnerabilities is available at www.cert.org/advisories/CA-2002-03.html.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Low Latency Network Engineer, Senior Network Engineer, Multicas

Low Latency Network Engineer, Senior Network Engineer...

SQL Server DBA - (North London)

SQL DBA - (North London) North London , £45k - 50k...

Business Architect – (North London)

Business Architect – (North London) £65,000 – 75,000k...

Graduate Software Engineer - Javascript OR Android

Graduate Software Engineer - Javascript OR Android...

To send to more than one email address, simply separate each address with a comma.