main

iDefense Alert: Cisco Web Administration DDoS Vulnerability

malebolgia   on 01 April 2004 - 21:44 · 5 comments & 414 views

Advertisement (Why?)
Security intelligence firm iDefense Inc. on April 1, reported that remote exploitation of a design error vulnerability in Cisco Systems Inc.' 600 series Web Administration service allows for a distributed-denial-of-service (DDoS) condition. The company rated the severity of this security event as high.

The Web Administration service on the Cisco 627, 633, 673, 675, 675E, 677, 677i and 678 routers are unable to properly handle multiple 'GET' requests from separate clients. When the Cisco 600 series router is accessed via the HTTP protocol (TCP port 80) through multiple connections, the Cisco 600 series router will fail, the Reston, Va.-based security company said in Thursday's alert report.

News source: eWeek


Change Log:


  • added Italian, French and Hungarian translations
  • fixed IP groups disabling
  • several minor fixes in advanced packet filter editor


For home users, Kerio Personal Firewall 4 is available in two flavors - the full edition and the limited free edition. After installation, KPF works as the full edition for 30 days, after which it becomes the limited free edition. Limited free edition does not provide the content filtering capabilities such as blocking pop-up windows, ads, VB scripts, cookies, etc. and other extra features.

Post a comment · Send to friend Comments · There are 5 additional comments
(1 reply) #1 saweetnesstrev on 01 Apr 2004 - 21:45
April Fools?
#1.1 thenewbrgnewman on 02 Apr 2004 - 00:12
lol, i bet
#2 StaticX on 01 Apr 2004 - 22:06
who in the hell still uses the 600 series routers anyway?
#3 benstudley on 02 Apr 2004 - 03:19
Most definitely not an April Fool's joke.
#4 KrAzY on 02 Apr 2004 - 04:04
This is TRUE. It is also affecting VINAs and Larscom Voice/Data Routers.

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)