DoS hole in Cisco IOS endangers internet providers’ routers [Update]
Summary
In 2007 a DoS hole in Cisco’s IOS allowed routers to be forced to restart via the command “show ip bgp regexp” with certain regular expressions. Many providers offered such commands publicly via telnet route servers or looking glass websites; repeated restarts could cause other networks to ignore the provider’s routes. As a workaround, providers filtered the expressions or blocked the command, and Cisco recommended the “Deterministic Regular Expression Engine”.
Ideas
- Public diagnostic access to routers becomes attack surface.
- A router restart forces the BGP table to be rebuilt.
- Routes that frequently drop out are temporarily suppressed by other networks.
- Looking glass websites often pass parameters to core routers unfiltered.
Insights
- Through BGP dampening, a local crash can make an entire network unreachable.
- Dedicated route servers without routing tasks limit the risk of public diagnostic services.
Facts
- According to Cisco, the bug resembled a problem known since 2005.
- Details of the hole were already circulating in IRC channels before an update was available.
References
Critique
- The scope remains vague because it is unclear how many providers passed looking glass requests directly to production routers.
Recommendations
- Never pass public looking glass and route server requests to production core routers.
- Restrict diagnostic commands with free parameters to trusted users.
Links to the original source and the Web Archive open in a new tab.