<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>CiscoZine</title>
	
	<link>http://www.ciscozine.com</link>
	<description>Daily reporting on Cisco technology</description>
	<lastBuildDate>Fri, 25 May 2012 19:44:35 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/Ciscozine" /><feedburner:info uri="ciscozine" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><creativeCommons:license>http://creativecommons.org/licenses/by-nc-nd/3.0/</creativeCommons:license><image><link>http://creativecommons.org/licenses/by-nc-nd/3.0/</link><url>http://creativecommons.org/images/public/somerights20.gif</url><title>Some Rights Reserved</title></image><feedburner:emailServiceId>Ciscozine</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><feedburner:feedFlare href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Ffeeds.feedburner.com%2FCiscozine" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2FCiscozine" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare href="http://feeds.my.aol.com/add.jsp?url=http%3A%2F%2Ffeeds.feedburner.com%2FCiscozine" src="http://o.aolcdn.com/favorites.my.aol.com/webmaster/ffclient/webroot/locale/en-US/images/myAOLButtonSmall.gif">Subscribe with My AOL</feedburner:feedFlare><feedburner:feedFlare href="http://www.bloglines.com/sub/http://feeds.feedburner.com/Ciscozine" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Ffeeds.feedburner.com%2FCiscozine" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare href="http://fusion.google.com/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2FCiscozine" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2FCiscozine" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><feedburner:feedFlare href="http://www.plusmo.com/add?url=http%3A%2F%2Ffeeds.feedburner.com%2FCiscozine" src="http://plusmo.com/res/graphics/fbplusmo.gif">Subscribe with Plusmo</feedburner:feedFlare><feedburner:feedFlare href="http://www.thefreedictionary.com/_/hp/AddRSS.aspx?http%3A%2F%2Ffeeds.feedburner.com%2FCiscozine" src="http://img.tfd.com/hp/addToTheFreeDictionary.gif">Subscribe with The Free Dictionary</feedburner:feedFlare><feedburner:feedFlare href="http://www.bitty.com/manual/?contenttype=rssfeed&amp;contentvalue=http%3A%2F%2Ffeeds.feedburner.com%2FCiscozine" src="http://www.bitty.com/img/bittychicklet_91x17.gif">Subscribe with Bitty Browser</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsalloy.com/?rss=http%3A%2F%2Ffeeds.feedburner.com%2FCiscozine" src="http://www.newsalloy.com/subrss3.gif">Subscribe with NewsAlloy</feedburner:feedFlare><feedburner:feedFlare href="http://www.live.com/?add=http%3A%2F%2Ffeeds.feedburner.com%2FCiscozine" src="http://tkfiles.storage.msn.com/x1piYkpqHC_35nIp1gLE68-wvzLZO8iXl_JMledmJQXP-XTBOLfmQv4zhj4MhcWEJh_GtoBIiAl1Mjh-ndp9k47If7hTaFno0mxW9_i3p_5qQw">Subscribe with Live.com</feedburner:feedFlare><feedburner:feedFlare href="http://mix.excite.eu/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2FCiscozine" src="http://image.excite.co.uk/mix/addtomix.gif">Subscribe with Excite MIX</feedburner:feedFlare><feedburner:feedFlare href="http://www.yourminis.com/subscribe.aspx?u=http%3A%2F%2Ffeeds.feedburner.com%2FCiscozine" src="http://www.yourminis.com/images/addtoyourminisbadge.gif">Subscribe with Yourminis.com</feedburner:feedFlare><feedburner:feedFlare href="http://download.attensa.com/app/get_attensa.html?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2FCiscozine" src="http://www.attensa.com/blogs/attensa/WindowsLiveWriter/BadgeredintoBadges_10C02/attensa_feed_button5.gif">Subscribe with Attensa for Outlook</feedburner:feedFlare><feedburner:feedFlare href="http://www.webwag.com/wwgthis.php?url=http%3A%2F%2Ffeeds.feedburner.com%2FCiscozine" src="http://www.webwag.com/images/wwgthis.gif">Subscribe with Webwag</feedburner:feedFlare><feedburner:feedFlare href="http://hub.netomat.net/account/account.autoSubscribe.jspa?urls=http%3A%2F%2Ffeeds.feedburner.com%2FCiscozine" src="http://www.netomat.net/blogger/images/icon_netomat_feedbutton.gif">Subscribe with netomat Hub</feedburner:feedFlare><feedburner:feedFlare href="http://www.podcastready.com/oneclick_bookmark.php?url=http%3A%2F%2Ffeeds.feedburner.com%2FCiscozine" src="http://www.podcastready.com/images/podcastready_button.gif">Subscribe with Podcast Ready</feedburner:feedFlare><feedburner:feedFlare href="http://www.flurry.com/pushRssFeed.do?r=fb&amp;url=http%3A%2F%2Ffeeds.feedburner.com%2FCiscozine" src="http://www.flurry.com/images/flurry_rss_logo2.gif">Subscribe with Flurry</feedburner:feedFlare><feedburner:feedFlare href="http://www.wikio.com/subscribe?url=http%3A%2F%2Ffeeds.feedburner.com%2FCiscozine" src="http://www.wikio.com/shared/img/add2wikio.gif">Subscribe with Wikio</feedburner:feedFlare><feedburner:feedFlare href="http://www.dailyrotation.com/index.php?feed=http%3A%2F%2Ffeeds.feedburner.com%2FCiscozine" src="http://www.dailyrotation.com/rss-dr2.gif">Subscribe with Daily Rotation</feedburner:feedFlare><item>
		<title>How to create self-signed certificates</title>
		<link>http://feedproxy.google.com/~r/Ciscozine/~3/ONitOr42LmI/</link>
		<comments>http://www.ciscozine.com/2012/05/25/how-to-create-self-signed-certificates/#comments</comments>
		<pubDate>Fri, 25 May 2012 13:32:54 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Tutorial]]></category>
		<category><![CDATA[CA]]></category>
		<category><![CDATA[Certificate]]></category>
		<category><![CDATA[PKI]]></category>
		<category><![CDATA[RSA]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=981</guid>
		<description>A digital certificate or identity certificate is an electronic document which uses a digital signature to bind a public key with an identity, information such as the name of a person or an organization, their address, and so forth. The certificate can be used to verify that a public key belongs to an individual. In a typical public key infrastructure (PKI) scheme, the signature will be of a certificate authority (CA). However, there are situations where it is not possible use a CA, so the only solutions is to use a self-signed certificate, an identity certificate that is signed by [...]&lt;img src="http://feeds.feedburner.com/~r/Ciscozine/~4/ONitOr42LmI" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.ciscozine.com/2012/05/25/how-to-create-self-signed-certificates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.ciscozine.com/2012/05/25/how-to-create-self-signed-certificates/</feedburner:origLink></item>
		<item>
		<title>April 2012: one Cisco vulnerability</title>
		<link>http://feedproxy.google.com/~r/Ciscozine/~3/WV1bGpXwskA/</link>
		<comments>http://www.ciscozine.com/2012/05/03/april-2012-one-cisco-vulnerability/#comments</comments>
		<pubDate>Thu, 03 May 2012 13:31:38 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>
		<category><![CDATA[WebEx]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=978</guid>
		<description>The Cisco Product Security Incident Response Team (PSIRT) has published one important vulnerability advisory: Buffer Overflow Vulnerabilities in the Cisco WebEx Player Buffer Overflow Vulnerabilities in the Cisco WebEx Player The Cisco WebEx Recording Format (WRF) player contains three buffer overflow vulnerabilities. In some cases, exploitation of the vulnerabilities could allow a remote attacker to execute arbitrary code on the system with the privileges of a targeted user. Vulnerable Products The vulnerabilities disclosed in this advisory affect the Cisco WebEx Recording Format (WRF) player. The following client builds of Cisco WebEx Business Suite (WBS 27) are affected by at least [...]&lt;img src="http://feeds.feedburner.com/~r/Ciscozine/~4/WV1bGpXwskA" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.ciscozine.com/2012/05/03/april-2012-one-cisco-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.ciscozine.com/2012/05/03/april-2012-one-cisco-vulnerability/</feedburner:origLink></item>
		<item>
		<title>Cisco Networking Academy NetRiders competitions</title>
		<link>http://feedproxy.google.com/~r/Ciscozine/~3/X2ONGxzuDh8/</link>
		<comments>http://www.ciscozine.com/2012/04/20/cisco-networking-academy-netriders-competitions/#comments</comments>
		<pubDate>Fri, 20 Apr 2012 12:29:53 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Stories]]></category>
		<category><![CDATA[Academy]]></category>
		<category><![CDATA[NetRiders]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=977</guid>
		<description>NetRiders competitions provide students with hands-on practice and experience in a competitive environment, a chance to test their skills and recognize their weaknesses, showcase their knowledge, and create interactive networking skills as well as new friendships across the world. And for Instructors, this is a great opportunity to lead students and showcase teaching skills as well. Organized by Cisco, these competitions are a great opportunity for Networking Academy students to learn valuable Networking/IT skills through a series of online exams and simulation activities using Cisco Packet Tracer. Competitions are offered for students currently or recently enrolled in a Cisco Networking [...]&lt;img src="http://feeds.feedburner.com/~r/Ciscozine/~4/X2ONGxzuDh8" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.ciscozine.com/2012/04/20/cisco-networking-academy-netriders-competitions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.ciscozine.com/2012/04/20/cisco-networking-academy-netriders-competitions/</feedburner:origLink></item>
		<item>
		<title>Unicast flooding due to asymmetric routing</title>
		<link>http://feedproxy.google.com/~r/Ciscozine/~3/Y1VHnbOVEgU/</link>
		<comments>http://www.ciscozine.com/2012/04/15/unicast-flooding-due-to-asymmetric-routing/#comments</comments>
		<pubDate>Sun, 15 Apr 2012 18:57:01 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Tutorial]]></category>
		<category><![CDATA[Asymmetric routing]]></category>
		<category><![CDATA[Flooding attack]]></category>
		<category><![CDATA[MAC]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[Unicast flooding]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=953</guid>
		<description>Asymmetric routing is a situation where a packet traverses from a source to a destination in one path and takes a different path when it returns to the source. This is commonly seen in Layer-3 routed networks, for instance on Internet. Asymmetric routing is not a problem by itself, but will cause problems when Network Address Translation (NAT) or firewalls are used in the routed path. For example, in firewalls, state information is built when the packets flow from a higher security domain to a lower security domain. The firewall will be an exit point from one security domain to [...]&lt;img src="http://feeds.feedburner.com/~r/Ciscozine/~4/Y1VHnbOVEgU" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.ciscozine.com/2012/04/15/unicast-flooding-due-to-asymmetric-routing/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		<feedburner:origLink>http://www.ciscozine.com/2012/04/15/unicast-flooding-due-to-asymmetric-routing/</feedburner:origLink></item>
		<item>
		<title>March 2012: twelve Cisco vulnerabilities</title>
		<link>http://feedproxy.google.com/~r/Ciscozine/~3/PAe5BdobV3k/</link>
		<comments>http://www.ciscozine.com/2012/04/02/march-2012-twelve-cisco-vulnerabilities/#comments</comments>
		<pubDate>Mon, 02 Apr 2012 10:03:25 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=950</guid>
		<description>The Cisco Product Security Incident Response Team (PSIRT) has published twelve important vulnerability advisories: Cisco IOS Software Reverse SSH Denial of Service Vulnerability Cisco IOS Software RSVP Denial of Service Vulnerability Vulnerabilities in Cisco IOS Software Traffic Optimization Features Cisco IOS Software Multicast Source Discovery Protocol Vulnerability Cisco IOS Software Network Address Translation Vulnerability Cisco IOS Internet Key Exchange Vulnerability Cisco IOS Software Smart Install Denial of Service Vulnerability Cisco IOS Software Command Authorization Bypass Cisco IOS Software Zone-Based Firewall Vulnerabilities Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances and Cisco Catalyst 6500 Series ASA Services Module Cisco [...]&lt;img src="http://feeds.feedburner.com/~r/Ciscozine/~4/PAe5BdobV3k" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.ciscozine.com/2012/04/02/march-2012-twelve-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.ciscozine.com/2012/04/02/march-2012-twelve-cisco-vulnerabilities/</feedburner:origLink></item>
		<item>
		<title>How to perform SSH RSA User Authentication</title>
		<link>http://feedproxy.google.com/~r/Ciscozine/~3/4JxA6FJj07U/</link>
		<comments>http://www.ciscozine.com/2012/03/27/how-to-perform-ssh-rsa-user-authentication/#comments</comments>
		<pubDate>Tue, 27 Mar 2012 11:32:35 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Tutorial]]></category>
		<category><![CDATA[Advanced configuration]]></category>
		<category><![CDATA[RSA]]></category>
		<category><![CDATA[Secure a router]]></category>
		<category><![CDATA[SSH]]></category>
		<category><![CDATA[Video]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=943</guid>
		<description>Cisco IOS SSH Version 2 (SSHv2) supports keyboard-interactive and password-based authentication methods. The SSHv2 Enhancements for RSA Keys feature also supports RSA-based public key authentication for the client and the server. RSA based user authentication uses a private/public key pair associated with each user for authentication. The user must generate a private/public key pair on the client and configure a public key on the Cisco IOS SSH server to complete the authentication. An SSH user trying to establish the credentials provides an encrypted signature using the private key. The signature and the user&amp;#8217;s public key are sent to the SSH [...]&lt;img src="http://feeds.feedburner.com/~r/Ciscozine/~4/4JxA6FJj07U" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.ciscozine.com/2012/03/27/how-to-perform-ssh-rsa-user-authentication/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.ciscozine.com/2012/03/27/how-to-perform-ssh-rsa-user-authentication/</feedburner:origLink></item>
		<item>
		<title>Cisco Linksys WVC200 Wireless-G PTZ Internet Video Camera buffer overflow</title>
		<link>http://feedproxy.google.com/~r/Ciscozine/~3/5EW8OhxiSzE/</link>
		<comments>http://www.ciscozine.com/2012/03/22/cisco-linksys-wvc200-wireless-g-ptz-internet-video-camera-buffer-overflow/#comments</comments>
		<pubDate>Thu, 22 Mar 2012 19:39:53 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Buffer overflows]]></category>
		<category><![CDATA[Linksys]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=944</guid>
		<description>The Cisco Linksys WVC200 Wireless-G PTZ Internet Video Camera PlayerPT ActiveX Control PlayerPT.ocx auffers a buffer overflow vulnerability. When viewing the device web interface it asks to install an ActiveX control with the following settings: ProductName: PlayerPT ActiveX Control Module File version: 1.0.0.15 Binary path: C:\WINDOWS\system32\PlayerPT.ocx CLSID: {9E065E4A-BD9D-4547-8F90-985DC62A5591} ProgID: PLAYERPT.PlayerPTCtrl.1 Safe for scripting (registry): True Safe for initialization (registry): True Vulnerability (Only for test): the SetSource() method is vulnerable to a buffer overflow vulnerability. Quickly, ollydbg dump: ... 03238225   8B5424 20        mov edx,dword ptr ss:[esp+20] 03238229   894424 10        mov dword ptr ss:[esp+10],eax 0323822D   B9 32000000      mov ecx,32 03238232   33C0             xor [...]&lt;img src="http://feeds.feedburner.com/~r/Ciscozine/~4/5EW8OhxiSzE" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.ciscozine.com/2012/03/22/cisco-linksys-wvc200-wireless-g-ptz-internet-video-camera-buffer-overflow/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.ciscozine.com/2012/03/22/cisco-linksys-wvc200-wireless-g-ptz-internet-video-camera-buffer-overflow/</feedburner:origLink></item>
		<item>
		<title>Cisco Linksys WAG54GS CSRF Change Admin Password</title>
		<link>http://feedproxy.google.com/~r/Ciscozine/~3/NoF8uttU4d8/</link>
		<comments>http://www.ciscozine.com/2012/03/02/cisco-linksys-wag54gs-csrf-change-admin-password/#comments</comments>
		<pubDate>Fri, 02 Mar 2012 13:50:09 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=941</guid>
		<description>The Cisco Linksys WAG54GS ADSL router suffers a cross site request forgery vulnerability. Below the source of the exploit (Only for test!) +--------------------------------------------------------------------------------------------------------------------------------+ # Exploit Title : Cisco Linksys WAG54GS (ADSL Router) change admin password # Date          : 20-02-2012 # Author        : Ivano Binetti (http://ivanobinetti.com) # Vendor site   : http://www.linksysbycisco.com # Version       : WAG54GS # Tested on     : Firmware Version: V1.01.03 +--------------------------------------------------------------------------------------------------------------------------------+ +------------------------------------------[Change Admin Account Password by Ivano Binetti]--------------------------------------+ Summary 1)Introduction 2)Vulnerability Description 3)Exploit +---------------------------------------------------------------------------------------------------------------------------------+ 1)Introduction Cisco Linksys WAG54GS is an ADSL Router which uses a web management interface -listening to default on tcp/ip port 80 - and "admin" as [...]&lt;img src="http://feeds.feedburner.com/~r/Ciscozine/~4/NoF8uttU4d8" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.ciscozine.com/2012/03/02/cisco-linksys-wag54gs-csrf-change-admin-password/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.ciscozine.com/2012/03/02/cisco-linksys-wag54gs-csrf-change-admin-password/</feedburner:origLink></item>
		<item>
		<title>Cisco 2011 Annual Security Report</title>
		<link>http://feedproxy.google.com/~r/Ciscozine/~3/hm4yaeVsD0I/</link>
		<comments>http://www.ciscozine.com/2012/02/10/cisco-2011-annual-security-report/#comments</comments>
		<pubDate>Fri, 10 Feb 2012 13:47:13 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Stories]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=936</guid>
		<description>The Cisco Annual Security Report provides an overview of the combined security intelligence of the entire Cisco organization. The report encompasses threat information and trends collected between January and November 2011. It also provides a snapshot of the state of security for that period, with special attention paid to key security trends expected for 2012. “The older generation assumes everything is private, except what they choose to make public,” explains David Evans, chief futurist for Cisco. “To the younger generation, everything is public, except what they choose to make private. This default position—that everything is public—goes against how enterprises have [...]&lt;img src="http://feeds.feedburner.com/~r/Ciscozine/~4/hm4yaeVsD0I" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.ciscozine.com/2012/02/10/cisco-2011-annual-security-report/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.ciscozine.com/2012/02/10/cisco-2011-annual-security-report/</feedburner:origLink></item>
		<item>
		<title>Nmap for IOS? No, IOSMap</title>
		<link>http://feedproxy.google.com/~r/Ciscozine/~3/ZmhRxbV8AWs/</link>
		<comments>http://www.ciscozine.com/2012/02/08/nmap-for-ios-no-iosmap/#comments</comments>
		<pubDate>Wed, 08 Feb 2012 09:24:44 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Tutorial]]></category>
		<category><![CDATA[Advanced configuration]]></category>
		<category><![CDATA[Nmap]]></category>
		<category><![CDATA[Port Scanning]]></category>
		<category><![CDATA[Tcl]]></category>
		<category><![CDATA[Video]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=933</guid>
		<description>The Tcl shell can be used to run Cisco IOS CLI EXEC commands within a Tcl script. Using the Tcl shell to run CLI commands allows customers to build menus to guide novice users through tasks, to automate repetitive tasks, and to create custom output for show commands. Not everyone knows that it is possible to implement a port scanning tool like a light Nmap. Surfing the web I have found a tool named IOSMap, a Cisco port scanning tool. It is not mandatory know Tcl to use this script; the only thing you need to know is how execute a [...]&lt;img src="http://feeds.feedburner.com/~r/Ciscozine/~4/ZmhRxbV8AWs" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.ciscozine.com/2012/02/08/nmap-for-ios-no-iosmap/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.ciscozine.com/2012/02/08/nmap-for-ios-no-iosmap/</feedburner:origLink></item>
		<item>
		<title>How to monitor devices with Cacti</title>
		<link>http://feedproxy.google.com/~r/Ciscozine/~3/GAhotuEp2DU/</link>
		<comments>http://www.ciscozine.com/2012/02/02/how-to-monitor-devices-with-cacti/#comments</comments>
		<pubDate>Thu, 02 Feb 2012 08:50:21 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Tutorial]]></category>
		<category><![CDATA[Basic configuration]]></category>
		<category><![CDATA[Cacti]]></category>
		<category><![CDATA[SNMP]]></category>
		<category><![CDATA[Video]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=928</guid>
		<description>There are many ways to monitor devices: netflow, span port, switchport and so on. Today I will explain how to monitor bandwith, CPU, &amp;#8230; of routers and switches using SNMP and Cacti. Simple Network Management Protocol (SNMP) is an &amp;#8220;Internet-standard protocol for managing devices on IP networks. Devices that typically support SNMP include routers, switches, servers, workstations, printers, modem racks, and more.&amp;#8221; It is used mostly in network management systems to monitor network-attached devices for conditions that warrant administrative attention. SNMP is a component of the Internet Protocol Suite as defined by the Internet Engineering Task Force (IETF). It consists [...]&lt;img src="http://feeds.feedburner.com/~r/Ciscozine/~4/GAhotuEp2DU" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.ciscozine.com/2012/02/02/how-to-monitor-devices-with-cacti/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://www.ciscozine.com/2012/02/02/how-to-monitor-devices-with-cacti/</feedburner:origLink></item>
		<item>
		<title>January 2012: three Cisco vulnerabilities</title>
		<link>http://feedproxy.google.com/~r/Ciscozine/~3/MjpAyw-9vD4/</link>
		<comments>http://www.ciscozine.com/2012/02/01/january-2012-three-cisco-vulnerabilities/#comments</comments>
		<pubDate>Wed, 01 Feb 2012 13:19:21 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=930</guid>
		<description>The Cisco Product Security Incident Response Team (PSIRT) has published three important vulnerability advisories: Cisco IronPort Appliances Telnet Remote Code Execution Vulnerability Cisco IP Video Phone E20 Default Root Account Cisco Digital Media Manager Privilege Escalation Vulnerability Cisco IronPort Appliances Telnet Remote Code Execution Vulnerability Cisco IronPort Email Security Appliances (ESA) and Cisco IronPort Security Management Appliances (SMA) contain a vulnerability that may allow a remote, unauthenticated attacker to execute arbitrary code with elevated privileges. Vulnerable Products The following Cisco IronPort Email Security Appliances (ESA) and Cisco IronPort Security Management Appliances (SMA) are affected by this vulnerability: Cisco IronPort Email [...]&lt;img src="http://feeds.feedburner.com/~r/Ciscozine/~4/MjpAyw-9vD4" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.ciscozine.com/2012/02/01/january-2012-three-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.ciscozine.com/2012/02/01/january-2012-three-cisco-vulnerabilities/</feedburner:origLink></item>
		<item>
		<title>November 2011: two Cisco vulnerabilities</title>
		<link>http://feedproxy.google.com/~r/Ciscozine/~3/A4R9CTWH9TQ/</link>
		<comments>http://www.ciscozine.com/2011/12/02/november-2011-two-cisco-vulnerabilities/#comments</comments>
		<pubDate>Fri, 02 Dec 2011 16:42:57 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Inject data]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=925</guid>
		<description>The Cisco Product Security Incident Response Team (PSIRT) has published two important vulnerability advisories: Cisco TelePresence System Integrator C Series and Cisco TelePresence EX Series Device Default Root Account Manufacturing Error Cisco Small Business SRP500 Series Command Injection Vulnerability Cisco TelePresence System Integrator C Series and Cisco TelePresence EX Series Device Default Root Account Manufacturing Error Software that runs on Cisco TelePresence System Integrator C Series and Cisco TelePresence EX Series devices was updated to include secure default configurations beginning with the TC4.0 release. This change was accompanied by the release of Cisco Security Advisory cisco-sa-20110202-tandberg. Vulnerable Products All Cisco [...]&lt;img src="http://feeds.feedburner.com/~r/Ciscozine/~4/A4R9CTWH9TQ" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.ciscozine.com/2011/12/02/november-2011-two-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.ciscozine.com/2011/12/02/november-2011-two-cisco-vulnerabilities/</feedburner:origLink></item>
		<item>
		<title>October 2011: ten Cisco vulnerabilities</title>
		<link>http://feedproxy.google.com/~r/Ciscozine/~3/Wg95jOheGtM/</link>
		<comments>http://www.ciscozine.com/2011/12/02/october-2011-ten-cisco-vulnerabilities/#comments</comments>
		<pubDate>Fri, 02 Dec 2011 16:27:15 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=923</guid>
		<description>The Cisco Product Security Incident Response Team (PSIRT) has published ten important vulnerability advisories: Buffer Overflow Vulnerabilities in the Cisco WebEx Player Cisco Unified Contact Center Express Directory Traversal Vulnerability Denial of Service Vulnerability in Cisco Video Surveillance IP Cameras Cisco Security Agent Remote Code Execution Vulnerabilities Cisco Unified Communications Manager Directory Traversal Vulnerability CiscoWorks Common Services Arbitrary Command Execution Vulnerability Cisco Show and Share Security Vulnerabilities Directory Traversal Vulnerability in Cisco Network Admission Control Manager Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances and Cisco Catalyst 6500 Series ASA Services Module Multiple Vulnerabilities in Cisco Firewall Services [...]&lt;img src="http://feeds.feedburner.com/~r/Ciscozine/~4/Wg95jOheGtM" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.ciscozine.com/2011/12/02/october-2011-ten-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.ciscozine.com/2011/12/02/october-2011-ten-cisco-vulnerabilities/</feedburner:origLink></item>
		<item>
		<title>IP traffic export: how to mirror traffic on a router</title>
		<link>http://feedproxy.google.com/~r/Ciscozine/~3/Nk3PlUuahTI/</link>
		<comments>http://www.ciscozine.com/2011/11/17/ip-traffic-export-how-to-mirror-traffic-on-a-router/#comments</comments>
		<pubDate>Thu, 17 Nov 2011 20:41:12 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Tutorial]]></category>
		<category><![CDATA[Advanced configuration]]></category>
		<category><![CDATA[Dump]]></category>
		<category><![CDATA[IP traffic export]]></category>
		<category><![CDATA[SPAN]]></category>
		<category><![CDATA[Video]]></category>
		<category><![CDATA[Wireshark]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=910</guid>
		<description>The Switched Port Analyzer (SPAN) feature, which is sometimes called port mirroring or port monitoring, selects network traffic, from a switched port, for analysis by a network analyzer. Unfotunately this feature works only on switches or switches Layer3. And in a router, what can I do to copy the traffic? In a previous article, I explained the Embedded Packet Capture, a powerful feature to capture data packets directly on the NVRAM. Another good solution is the &amp;#8216;IP traffic export&amp;#8216;. Introduced in 12.3(4)T IOS, the IP Traffic Export feature allows users to configure their router to export IP packets that are [...]&lt;img src="http://feeds.feedburner.com/~r/Ciscozine/~4/Nk3PlUuahTI" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.ciscozine.com/2011/11/17/ip-traffic-export-how-to-mirror-traffic-on-a-router/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.ciscozine.com/2011/11/17/ip-traffic-export-how-to-mirror-traffic-on-a-router/</feedburner:origLink></item>
		<item>
		<title>Cisco completes acquisition of BNI Video</title>
		<link>http://feedproxy.google.com/~r/Ciscozine/~3/eeColSNs31M/</link>
		<comments>http://www.ciscozine.com/2011/11/15/cisco-completes-acquisition-of-bni-video/#comments</comments>
		<pubDate>Tue, 15 Nov 2011 22:47:48 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[New products]]></category>
		<category><![CDATA[BNI Video]]></category>
		<category><![CDATA[Business]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=914</guid>
		<description>Cisco announced it has completed its acquisition of privately-held BNI Video. Headquartered in Boxborough, Mass., BNI Video supplies service providers with two major video products that offer video back-office and content delivery network (CDN) analytic capabilities. The acquisition advances the capabilities of Cisco&amp;#8217;s Videoscape TV platform, which allows service providers to deliver compelling video experiences to any device over any Internet Protocol (IP) network. BNI Video&amp;#8217;s technology also helps Cisco&amp;#8217;s service provider customers reduce their operational costs and complexity, while expanding monetization opportunities. BNI Video is already well recognized by the largest service providers as having built a differentiated solution [...]&lt;img src="http://feeds.feedburner.com/~r/Ciscozine/~4/eeColSNs31M" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.ciscozine.com/2011/11/15/cisco-completes-acquisition-of-bni-video/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.ciscozine.com/2011/11/15/cisco-completes-acquisition-of-bni-video/</feedburner:origLink></item>
		<item>
		<title>Cisco TelePresence exploits</title>
		<link>http://feedproxy.google.com/~r/Ciscozine/~3/XFO6Qw2CwT0/</link>
		<comments>http://www.ciscozine.com/2011/10/24/cisco-telepresence-exploits/#comments</comments>
		<pubDate>Mon, 24 Oct 2011 06:55:58 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Exploit]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>
		<category><![CDATA[TelePresence]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=909</guid>
		<description>Cisco TelePresence is an umbrella term for Video Conferencing Hardware and Software, Infrastructure and Endpoints. The C &amp;#38; MXP Series are the Endpoints used on desks or in boardrooms to provide users with a termination point for Video Conferencing. 1. Post-authentication HTML Injection &amp;#8211; CVE-2011-2544 (CSCtq46488): Cisco TelePresence Endpoints have a web interface (HTTP or HTTPS) for managing, configuring and reporting. It is possible to set the Call ID (with H.323 or SIP) to a HTML value. If a call is made to another endpoint and an authenticated user browses to the web interface on the endpoint receiving the call [...]&lt;img src="http://feeds.feedburner.com/~r/Ciscozine/~4/XFO6Qw2CwT0" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.ciscozine.com/2011/10/24/cisco-telepresence-exploits/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.ciscozine.com/2011/10/24/cisco-telepresence-exploits/</feedburner:origLink></item>
		<item>
		<title>September 2011: fifteen Cisco vulnerabilities</title>
		<link>http://feedproxy.google.com/~r/Ciscozine/~3/Pi_hMqNru2A/</link>
		<comments>http://www.ciscozine.com/2011/10/11/september-2011-fifteen-cisco-vulnerabilities/#comments</comments>
		<pubDate>Tue, 11 Oct 2011 20:16:18 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Access-list]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=906</guid>
		<description>The Cisco Product Security Incident Response Team (PSIRT) has published fifteen important vulnerability advisories: Cisco IOS Software IP Service Level Agreement Vulnerability Cisco Identity Services Engine Database Default Credentials Vulnerability Cisco IOS Software IPv6 over MPLS Vulnerabilities Cisco IOS Software IPv6 Denial of Service Vulnerability Cisco 10000 Series Denial of Service Vulnerability Cisco IOS Software Smart Install Remote Code Execution Vulnerability Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities Cisco IOS Software IPS and Zone-Based Firewall Vulnerabilities Cisco IOS Software Data-Link Switching Vulnerability Cisco IOS Software Network Address Translation Vulnerabilities Cisco Unified Communications Manager Session Initiation Protocol Memory [...]&lt;img src="http://feeds.feedburner.com/~r/Ciscozine/~4/Pi_hMqNru2A" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.ciscozine.com/2011/10/11/september-2011-fifteen-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.ciscozine.com/2011/10/11/september-2011-fifteen-cisco-vulnerabilities/</feedburner:origLink></item>
		<item>
		<title>Wake on LAN through Internet</title>
		<link>http://feedproxy.google.com/~r/Ciscozine/~3/WmOMf0MOGEE/</link>
		<comments>http://www.ciscozine.com/2011/10/04/wake-on-lan-through-internet/#comments</comments>
		<pubDate>Tue, 04 Oct 2011 11:48:31 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Tutorial]]></category>
		<category><![CDATA[Arp]]></category>
		<category><![CDATA[Nat]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[WOL]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=898</guid>
		<description>I write this tutorial to show how it is simple wakup a PC through Internet using WOL feature. What is WOL feature? Wake-on-LAN (WOL) is an Ethernet computer networking standard that allows a computer to be turned on or woken up by a network message. The message is usually sent by a program executed on another computer on the same local area network. It is also possible to initiate the message from another network by using Subnet directed broadcasts or a WOL gateway service. Wake-on-LAN is implemented using a special network message called a magic packet. The magic packet contains [...]&lt;img src="http://feeds.feedburner.com/~r/Ciscozine/~4/WmOMf0MOGEE" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.ciscozine.com/2011/10/04/wake-on-lan-through-internet/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://www.ciscozine.com/2011/10/04/wake-on-lan-through-internet/</feedburner:origLink></item>
		<item>
		<title>Cisco completes acquisition of AXIOSS Software Assets</title>
		<link>http://feedproxy.google.com/~r/Ciscozine/~3/NpqAsExrfBI/</link>
		<comments>http://www.ciscozine.com/2011/09/13/cisco-completes-acquisition-of-axioss-software-assets/#comments</comments>
		<pubDate>Tue, 13 Sep 2011 13:02:15 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[New products]]></category>
		<category><![CDATA[Axiom Systems]]></category>
		<category><![CDATA[AXIOSS]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=897</guid>
		<description>Cisco has completed its acquisition of service fulfillment software assets and associated employees from the UK subsidiary (formerly Axiom Systems) of Comptel Corporation (NASDAQ OMX Helsinki: CTL1V).  The acquisition gives Cisco the abilityto extend network and service management technologies across its next-generation Internet Protocol (IP) network platforms, allowing service providers to quickly and efficiently launch new video, data, mobility and cloud services to their customers. Cisco acquired the AXIOSS software suite, a fulfillment platform that strengthens the Cisco service provider management offering by automating ordering and fulfillment.  The software provides management capabilities for network services across Cisco&amp;#8217;s five company priorities.  [...]&lt;img src="http://feeds.feedburner.com/~r/Ciscozine/~4/NpqAsExrfBI" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.ciscozine.com/2011/09/13/cisco-completes-acquisition-of-axioss-software-assets/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.ciscozine.com/2011/09/13/cisco-completes-acquisition-of-axioss-software-assets/</feedburner:origLink></item>
		<item>
		<title>August 2011: five Cisco vulnerabilities</title>
		<link>http://feedproxy.google.com/~r/Ciscozine/~3/0U4MuQDoIjs/</link>
		<comments>http://www.ciscozine.com/2011/09/12/august-2011-five-cisco-vulnerabilities/#comments</comments>
		<pubDate>Mon, 12 Sep 2011 12:59:48 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=894</guid>
		<description>The Cisco Product Security Incident Response Team (PSIRT) has published five important vulnerability advisories: Apache HTTPd Range Header Denial of Service Vulnerability Denial of Service Vulnerability in Cisco TelePresence Codecs Open Query Interface in Cisco Unified Communications Manager and Cisco Unified Presence Server Cisco Unified Communications Manager Denial of Service Vulnerabilities Denial of Service Vulnerabilities in Cisco Intercompany Media Engine Apache HTTPd Range Header Denial of Service Vulnerability The Apache HTTPd server contains a denial of service vulnerability when it handles multiple, overlapping ranges. Multiple Cisco products may be affected by this vulnerability. Vulnerable Products The following products are confirmed [...]&lt;img src="http://feeds.feedburner.com/~r/Ciscozine/~4/0U4MuQDoIjs" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.ciscozine.com/2011/09/12/august-2011-five-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.ciscozine.com/2011/09/12/august-2011-five-cisco-vulnerabilities/</feedburner:origLink></item>
		<item>
		<title>July 2011: three Cisco vulnerabilities</title>
		<link>http://feedproxy.google.com/~r/Ciscozine/~3/HlOoRVMJLPo/</link>
		<comments>http://www.ciscozine.com/2011/08/05/july-2011-three-cisco-vulnerabilities/#comments</comments>
		<pubDate>Fri, 05 Aug 2011 13:17:51 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>
		<category><![CDATA[SQL injection]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=892</guid>
		<description>The Cisco Product Security Incident Response Team (PSIRT) has published three important vulnerability advisories: Cisco TelePresence Recording Server Default Credentials for Root Account Vulnerability Cisco SA 500 Series Security Appliances Web Management Interface Vulnerabilities Cisco ASR 9000 Series Routers Line Card IP Version 4 Denial of Service Vulnerability &amp;#160; Cisco TelePresence Recording Server Default Credentials for Root Account Vulnerability Cisco TelePresence Recording Server Software Release 1.7.2.0 includes a root administrator account that is enabled by default. Successful exploitation of the vulnerability could allow a remote attacker to use these default credentials to modify the system configuration and settings. Vulnerable Products [...]&lt;img src="http://feeds.feedburner.com/~r/Ciscozine/~4/HlOoRVMJLPo" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.ciscozine.com/2011/08/05/july-2011-three-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.ciscozine.com/2011/08/05/july-2011-three-cisco-vulnerabilities/</feedburner:origLink></item>
		<item>
		<title>Cisco AnyConnect VPN Client ActiveX URL Property Download and Execute exploit</title>
		<link>http://feedproxy.google.com/~r/Ciscozine/~3/d6sHXIu3gkM/</link>
		<comments>http://www.ciscozine.com/2011/07/07/cisco-anyconnect-vpn-client-activex-url-property-download-and-execute-exploit/#comments</comments>
		<pubDate>Thu, 07 Jul 2011 13:36:01 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Exploit]]></category>
		<category><![CDATA[AnyConnect VPN Client]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=890</guid>
		<description>The Cisco AnyConnect Secure Mobility Client, previously known as the Cisco AnyConnect VPN Client, is affected by the following vulnerabilities: Arbitrary Program Execution Vulnerability Local Privilege Escalation Vulnerability Cisco has released free software updates that address these vulnerabilities. There are no workarounds for this vulnerabilities. Below the source of the exploit (Only for test!). ## # $Id: cisco_anyconnect_exec.rb 12872 2011-06-06 20:15:51Z bannedit $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions. Please see the Metasploit # Framework web site for more information on licensing and terms of [...]&lt;img src="http://feeds.feedburner.com/~r/Ciscozine/~4/d6sHXIu3gkM" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.ciscozine.com/2011/07/07/cisco-anyconnect-vpn-client-activex-url-property-download-and-execute-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.ciscozine.com/2011/07/07/cisco-anyconnect-vpn-client-activex-url-property-download-and-execute-exploit/</feedburner:origLink></item>
		<item>
		<title>Cisco Unified Operations Manager exploits</title>
		<link>http://feedproxy.google.com/~r/Ciscozine/~3/BPwr8Szebz8/</link>
		<comments>http://www.ciscozine.com/2011/07/06/cisco-unified-operations-manager-exploits/#comments</comments>
		<pubDate>Wed, 06 Jul 2011 09:23:44 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Directory traversal vulnerability]]></category>
		<category><![CDATA[Remote Control]]></category>
		<category><![CDATA[SQL injection]]></category>
		<category><![CDATA[XSS vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=889</guid>
		<description>Cisco Unified Operations Manager (CuOM) is a NMS for voice developed by Cisco Systems. Operations Manager monitors and evaluates the current status of both the IP communications infrastructure and the underlying transport infrastructure in your network. Multiple vulnerabilities have been identified in Cisco Unified Operations Manager and associated products. These vulnerabilities include: multiple blind SQL injections multiple XSS directory traversal vulnerability Below the source of the exploit (Only for test!). Blind SQL injection vulnerabilities that affect CuOM (CVE-2011-0960): The Variable CCMs of PRTestCreation can trigger a blind SQL injection vulnerability by supplying a single quote, followed by a time delay [...]&lt;img src="http://feeds.feedburner.com/~r/Ciscozine/~4/BPwr8Szebz8" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.ciscozine.com/2011/07/06/cisco-unified-operations-manager-exploits/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.ciscozine.com/2011/07/06/cisco-unified-operations-manager-exploits/</feedburner:origLink></item>
		<item>
		<title>Cisco Security Agent Management Console ‘st_upload’ RCE Exploit</title>
		<link>http://feedproxy.google.com/~r/Ciscozine/~3/QTEjqZ1vyEg/</link>
		<comments>http://www.ciscozine.com/2011/07/05/cisco-security-agent-management-console-%e2%80%98st_upload%e2%80%99-rce-exploit/#comments</comments>
		<pubDate>Tue, 05 Jul 2011 09:21:28 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Cisco Security Agent]]></category>
		<category><![CDATA[Code execution]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=888</guid>
		<description>Cisco Security Agent provides threat protection for server and desktop computing systems. Cisco Security Agent can function in a standalone manner or can be managed by the Management Center for Cisco Security Agent. The Management Center for Cisco Security Agent is affected by a vulnerability that could allow an unauthenticated attacker to perform remote code execution on the affected device. A successful exploit could allow the attacker to modify agent policies and system configuration and perform other administrative tasks. Note: This vulnerability can be exploited only by sending certain packets to the web management interface, which by default listens on [...]&lt;img src="http://feeds.feedburner.com/~r/Ciscozine/~4/QTEjqZ1vyEg" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.ciscozine.com/2011/07/05/cisco-security-agent-management-console-%e2%80%98st_upload%e2%80%99-rce-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.ciscozine.com/2011/07/05/cisco-security-agent-management-console-%e2%80%98st_upload%e2%80%99-rce-exploit/</feedburner:origLink></item>
		<item>
		<title>June 2011: four Cisco vulnerabilities</title>
		<link>http://feedproxy.google.com/~r/Ciscozine/~3/1fwDPgDWmy8/</link>
		<comments>http://www.ciscozine.com/2011/07/04/june-2011-four-cisco-vulnerabilities/#comments</comments>
		<pubDate>Mon, 04 Jul 2011 16:27:41 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=886</guid>
		<description>The Cisco Product Security Incident Response Team (PSIRT) has published four important vulnerability advisories: Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client Multiple Vulnerabilities in Cisco Unified IP Phones 7900 Series Default Credentials Vulnerability in Cisco Network Registrar Default Credentials for root Account on the Cisco Media Experience Engine 5600 Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client The Cisco AnyConnect Secure Mobility Client, previously known as the Cisco AnyConnect VPN Client, is affected by the following vulnerabilities: Arbitrary Program Execution Vulnerability Local Privilege Escalation Vulnerability Vulnerable Products The vulnerabilities described in this document apply to the Cisco AnyConnect Secure [...]&lt;img src="http://feeds.feedburner.com/~r/Ciscozine/~4/1fwDPgDWmy8" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.ciscozine.com/2011/07/04/june-2011-four-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.ciscozine.com/2011/07/04/june-2011-four-cisco-vulnerabilities/</feedburner:origLink></item>
		<item>
		<title>EPC: an Embedded Packet Capture</title>
		<link>http://feedproxy.google.com/~r/Ciscozine/~3/SjWXPyVhA-o/</link>
		<comments>http://www.ciscozine.com/2011/06/22/epc-an-embedded-packet-capture/#comments</comments>
		<pubDate>Wed, 22 Jun 2011 12:45:47 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Tutorial]]></category>
		<category><![CDATA[Advanced configuration]]></category>
		<category><![CDATA[Dump]]></category>
		<category><![CDATA[EPC]]></category>
		<category><![CDATA[Video]]></category>
		<category><![CDATA[Wireshark]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=878</guid>
		<description>Started with IOS 12.4(20)T version, EPC or Embedded Packet Capture, is a powerful feature to capture data packets flowing through, to, and from, a Cisco router. In contrast with SPAN feature, EPC permits to save the dump directly on the NVRAM and for this reason, Embedded Packet Capture is useful whenever a network protocol analyzer might be useful in debugging a problem, but when it&amp;#8217;s not practical to install such a device. The features are: The ability to capture IPv4 and IPv6 packets in the Cisco Express Forwarding path A flexible method for specifying the capture buffer size and type [...]&lt;img src="http://feeds.feedburner.com/~r/Ciscozine/~4/SjWXPyVhA-o" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.ciscozine.com/2011/06/22/epc-an-embedded-packet-capture/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://www.ciscozine.com/2011/06/22/epc-an-embedded-packet-capture/</feedburner:origLink></item>
		<item>
		<title>May 2011: five Cisco vulnerabilities</title>
		<link>http://feedproxy.google.com/~r/Ciscozine/~3/fEYuepGP4t8/</link>
		<comments>http://www.ciscozine.com/2011/06/01/may-2011-five-cisco-vulnerabilities/#comments</comments>
		<pubDate>Wed, 01 Jun 2011 06:58:37 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=877</guid>
		<description>The Cisco Product Security Incident Response Team (PSIRT) has published five important vulnerability advisories: Cisco Content Delivery System Internet Streamer: Web Server Vulnerability Cisco RVS4000 and WRVS4400N Web Management Interface Vulnerabilities Cisco IOS XR Software IP Packet Vulnerability Cisco XR 12000 Series Shared Port Adapters Interface Processor Vulnerability Cisco IOS XR Software SSHv1 Denial of Service Vulnerability Cisco Content Delivery System Internet Streamer: Web Server Vulnerability The Cisco Internet Streamer application, part of the Cisco Content Delivery System (Cisco CDS), contains a vulnerability in its web server component that could cause the web server engine to crash when processing specially [...]&lt;img src="http://feeds.feedburner.com/~r/Ciscozine/~4/fEYuepGP4t8" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.ciscozine.com/2011/06/01/may-2011-five-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.ciscozine.com/2011/06/01/may-2011-five-cisco-vulnerabilities/</feedburner:origLink></item>
		<item>
		<title>April 2011: two Cisco vulnerabilities</title>
		<link>http://feedproxy.google.com/~r/Ciscozine/~3/osmgdR5KqD0/</link>
		<comments>http://www.ciscozine.com/2011/05/02/april-2011-two-cisco-vulnerabilities/#comments</comments>
		<pubDate>Mon, 02 May 2011 12:44:16 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Inject data]]></category>
		<category><![CDATA[Privilege escalation]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=872</guid>
		<description>The Cisco Product Security Incident Response Team (PSIRT) has published two important vulnerability advisories: Multiple Vulnerabilities in Cisco Unified Communications Manager Cisco Wireless LAN Controllers Denial of Service Vulnerability Multiple Vulnerabilities in Cisco Unified Communications Manager Cisco Unified Communications Manager (previously known as Cisco CallManager) contains the following vulnerabilities: Three denial of service (DoS) vulnerabilities that affect Session Initiation Protocol (SIP) services Directory transversal vulnerability Two SQL injection vulnerabilities Vulnerable Products The following products are affected by at least one of the vulnerabilities that are described in this advisory: Cisco Unified Communications Manager 6.x Cisco Unified Communications Manager 7.x Cisco [...]&lt;img src="http://feeds.feedburner.com/~r/Ciscozine/~4/osmgdR5KqD0" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.ciscozine.com/2011/05/02/april-2011-two-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.ciscozine.com/2011/05/02/april-2011-two-cisco-vulnerabilities/</feedburner:origLink></item>
		<item>
		<title>Speed up your reload</title>
		<link>http://feedproxy.google.com/~r/Ciscozine/~3/RvANhInz2qs/</link>
		<comments>http://www.ciscozine.com/2011/04/30/speed-up-your-reload/#comments</comments>
		<pubDate>Sat, 30 Apr 2011 12:18:37 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Tutorial]]></category>
		<category><![CDATA[Advanced configuration]]></category>
		<category><![CDATA[Reload]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[Video]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=871</guid>
		<description>How long does it take to reload your router? 3 or 4 minutes? Do you know that is possible to speed up your reboot? If your answer is negative, read how warm reload is faster than cold (classic) reload. Introduced in Cisco IOS Release 12.3(2)T, the warm reload feature allows users to reload their routers without reading images from storage. That is, the Cisco IOS image reboots without ROM monitor mode (ROMMON) intervention by restoring the read-write data from a previously saved copy in the RAM and by starting execution without either copying the image from flash to RAM or [...]&lt;img src="http://feeds.feedburner.com/~r/Ciscozine/~4/RvANhInz2qs" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://www.ciscozine.com/2011/04/30/speed-up-your-reload/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.ciscozine.com/2011/04/30/speed-up-your-reload/</feedburner:origLink></item>
	</channel>
</rss>

