<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>qBang Solutions Blog &#187; Security</title>
	<atom:link href="http://blog.qbangsolutions.com/category/technology/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.qbangsolutions.com</link>
	<description>qBang Solutions &#124; solutions you want. done.</description>
	<lastBuildDate>Sun, 07 Mar 2010 21:36:25 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Bank security is not really improved</title>
		<link>http://blog.qbangsolutions.com/bank-security-is-not-really-improved/</link>
		<comments>http://blog.qbangsolutions.com/bank-security-is-not-really-improved/#comments</comments>
		<pubDate>Thu, 18 Jun 2009 20:51:40 +0000</pubDate>
		<dc:creator>high</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[q!News]]></category>

		<guid isPermaLink="false">http://www.qbangsolutions.com/blog/index.php/2009/06/18/bank-security-is-not-really-improved/</guid>
		<description><![CDATA[Stumbled upon an article from New Scientist titled Cash Machines Hacked to Spew out Card Details, which tells about a new type of attack on bank ATM machines.
As the idea of using false fronts on bank card insertion slots to scan the magentic stripes on bank cards has become well known, banks have put in [...]]]></description>
			<content:encoded><![CDATA[<p>Stumbled upon an article from <a title="New Scientist online" href="http://www.newscientist.com">New Scientist</a> titled <a target="_blank" title="New Scientist:  Cash Machines Hacked to Spew out Card Details" href="http://www.newscientist.com/article/mg20227135.700-cash-machines-hacked-to-spew-out-card-details.html?full=true"><em>Cash Machines Hacked to Spew out Card Details</em></a>, which tells about a new type of attack on bank ATM machines.</p>
<p>As the idea of using false fronts on bank card insertion slots to scan the magentic stripes on bank cards has become well known, banks have put in protections against this scheme and begun to thwart criminals.  However, some clever criminals in Russia and Ukraine have devised a new type of attack where they insert a specially formatted bank card which tells the ATM machine to print out a list of all bank cards used during the day along with the cards&#8217; PIN numbers and expiration dates.  This information is then used to create &#8220;clone&#8221; bank cards and clean out the bank accounts of unsuspecting customers.</p>
<p>Even more shocking is that the criminals&#8217; special bank card can also be used to eject a cash storage cassette from the front of some older model ATM machines.</p>
<p>How do they accomlish this?  It was discovered that the crooks had used a malware program disguised as the lsass.exe file on the Windows operating system of the ATM machines to create a back door which can be triggered with the special bank cards.  You might wonder how the criminals could get the malware onto the ATM machine&#8217;s Windows OS in the first place.  According to the security analysts hired by the banks, it looks like the crooks had some inside help from bank or ATM employees bribed or coerced by the criminals.</p>
<p>As bad as all this sounds, the real pants-around-the-ankles fact here is that the ATM machines actually store the customers&#8217; bank card numbers, PINs, and expiration dates without any encryption.  What were they thinking?  I hope that the rest of the banks and ATM manufacturers from around the world are taking note of the situation in Russia and Ukraine.  They need to update their ATM infrastructure immediately to protect against such abuses.  Of course, in my opinion, it&#8217;s extreme negligence to not have encrypted any crucial bank card data in the first place.  An ATM machine might be very physically secure against the outside world, but we know that the majority of security breaches in business come from employees, not 15 year old kids in their parents&#8217; basement.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.qbangsolutions.com/bank-security-is-not-really-improved/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Secure Linux Appliances in Your Enterprise</title>
		<link>http://blog.qbangsolutions.com/secure-linux-appliances-in-your-enterprise/</link>
		<comments>http://blog.qbangsolutions.com/secure-linux-appliances-in-your-enterprise/#comments</comments>
		<pubDate>Tue, 27 Feb 2007 07:23:44 +0000</pubDate>
		<dc:creator>high</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Open source]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.qbangsolutions.com/blog/index.php/2007/02/26/secure-linux-appliances-in-your-enterprise/</guid>
		<description><![CDATA[(Article originally posted at InfoWorld Magazine)
By now you&#8217;ve either seen them or read about them. Companies are selling all kinds of useful appliances based on embedded Linux. Some are for small tasks like wireless APs, mobile devices, or cell phones. Others are geared towards enterprise needs like load balancers, routers, and NAS (network attached storage) [...]]]></description>
			<content:encoded><![CDATA[<p><em>(Article originally posted at <a target="infoworld" title="InfoWorld Magazine" href="http://weblog.infoworld.com/geeks/archives/2007/01/secure_linux_ap.html">InfoWorld Magazine</a>)</em></p>
<p>By now you&#8217;ve either seen them or read about them. Companies are selling all kinds of useful appliances based on embedded Linux. Some are for small tasks like wireless APs, mobile devices, or cell phones. Others are geared towards enterprise needs like load balancers, routers, and NAS (network attached storage) and SANs (storage attached network). They all run some version of Linux or BSD. You know you have a couple of Linux geeks working for you in the IT department. Why aren&#8217;t they coming up with some of these cool Linux appliances for your own company to use? The excellent <a title="Debian Router Project Page" target="_blank" href="http://gate-bunker.p6.msu.ru/~berk/router.html">Debian Router</a> project by Vadim Berkgaut is the help that your Linux admins need to develop their very own Linux appliances.</p>
<p>At my company, <a title="q!Bang Solutions" target="_blank" href="http://www.qbangsolutions.com">q!Bang Solutions</a>, we provide all types of IT solutions, but our strong suit is our solutions built upon Open Source software. Our employees have used the Debian Router Project (which we refer to as &#8220;DebRouter&#8221;) to build numerous solutions, including firewalls, OSPF and BGP routers, DNS servers, and even VoIP servers. DebRouter is a cornerstone of our technology solutions.</p>
<p>What&#8217;s great about DebRouter is that you get a fully functional <a target="_blank" title="Debian Linux" href="http://www.debian.org">Debian Linux</a> installation. So you can add whatever software packages you want to extend the functionality of the DebRouter. This is implemented through the usual Debian package management utilities, which means that you can change a DebRouter&#8217;s functionality on the fly and in the field after it&#8217;s been deployed.</p>
<p>Another important feature of DebRouter is that it boots from a flash device like a compact flash card (via an IDE adapter) or a USB flash drive. So if there are any problems with changes you&#8217;ve made, a reboot takes you back to the previous known-good version of your  running system. Does this mean that you lose changes you&#8217;ve made when power to the DebRouter goes out? No. DebRouter implements a &#8220;write to flash&#8221; function much like a hardware router or manageable switch. So you can install and configure new packages, test them out, and write your changes to the flash-based boot media if everything went well in testing. If your tests revealed there was a problem, then just reboot without writing the changes to flash and you will roll back to the same state of the filesystem that you had before your changes.  This makes it extremely easy to test potentially unstable software and configuration changes. If things don&#8217;t work, just reboot, and voila! Your working system is back within seconds.</p>
<p>This also means that the machines are harder for crackers to abuse if they succeed in infiltrating the DebRouter. If you discover that your DebRouter has been compromised, you can reboot and be rid of the cracker. Then you check for security updates from Debian, install them, write your changes, and you&#8217;re back up and running. I can tell you from experience that eradicating a cracker&#8217;s presence from a normal machine with hard drives whose data persists across reboots is not this easy!</p>
<p>The boot process of the DebRouter provides another nice benefit. DebRouter boots from flash media, creates a RAM disk, copies the flash media&#8217;s filesystem to the RAM disk and then unmounts the flash media filesystem and runs from the RAM disk. RAM is fast &#8211; lot faster than any hard drive. So now your filesystem I/O speed is absurdly fast. So if you install the Apache web server and put up some HTML and image files, you now have one of the fastest web servers available &#8211; without the hassle of a special configuration to load your pages into a ramdisk. It can also run web scripts (such as PHP, Perl, Python, Ruby, etc.) as fast as your normal hard drive based servers do.</p>
<p>What can you build with a DebRouter? Here are a few ideas to get you started:</p>
<ul>
<li>Add the <a target="_blank" title="Quagga Souftware Routing Suite" href="http://www.quagga.net/">Quagga</a> routing software package to make an OSPF/RIP/BGP router</li>
<li>Install the Apache web server with Perl/PHP/Python/etc scripting environments</li>
<li>Use the <a target="_blank" title="Asterisk - The Open Source PBX and Telephony Toolkit" href="http://www.asterisk.org/">Asterisk</a> software for a cheap VoIP server for a remote office</li>
<li>NAT/Firewall</li>
<li>Web content filtering via the <a title="Squid Web Proxy Cache" target="_blank" href="http://www.squid-cache.org/">Squid</a> proxy package</li>
<li>Make a captive portal system for wireless networks in cafes or other public access areas</li>
<li>DNS server using the venerable and always popular <a title="Internet Systems Consortium - BIND" target="_blank" href="http://www.isc.org/index.pl?/sw/bind/">BIND</a> software</li>
<li>Create a network sniffer with the tcpdump utility which writes data to a remote NAS or other storage device</li>
<li>Combined with a NAS (Network Attached Storage) or an NFS server, a DebRouter can do most anything.</li>
</ul>
<p>Since most enterprises will try to install all machines in racks, I checked a couple of online vendors to see how much it would cost to build a good 1RU DebRouter machine. I found that a 1RU machine far above the minimum specs can be had for $500, including shipping. This includes a 1RU case, motherboard with all essential functionality on board, a P4 2.8GHz CPU, 1GB ram, and a 512MB CF card and IDE-based CF reader.</p>
<p>So how about a $500 router that can do RIP/OSPF/BGP? Consider both the business and technology reasons that your company might want to use a DebRouter instead of a router from Cisco or one of the other routing big boys. The business side is easy. The hardware is cheap, even for a system with generous amounts of RAM and CPU. For the price of a typical router support contract, you can buy a couple of extra DebRouters to have sitting around as spares ready to jump into action if you have a hardware failure on your primary DebRouter. Subsequent years of support contracts you don&#8217;t need to buy equal money that remains in your coffers helping to fatten up your Christmas bonus next year. Of course, let&#8217;s not forget that most router vendors charge extra for the advanced software like OSPF or BGP routing, or encryption software so that you can use the more secure SSH instead of the gaping security hole called Telnet to remotely connect to your router. DebRouter has all that (and so much more) for free!</p>
<p>On the technology side, with the screaming fast processors available today, a DebRouter can pretty well hold its own against most of the major router vendors&#8217; offerings. And it&#8217;s the versatility of the DebRouter that will likely interest your techies. Did I mention that Linux does 802.1q VLANs? How about an OSPF router that does double duty as a slave DNS server? Or perhaps an edge router that also acts as a VPN concentrator with strong encryption for hundreds of tunnels?</p>
<p>So walk on down to IT and find those two Linux guys tucked away in their cubicles and let them loose on a Debian Router project. They should be glad to have an interesting project to work on instead of trying to recover emails that Marge from Accounting accidentally deleted the other day, and you just might get some nifty devices from them  that save you some cash on your bottom line. Your Linux admins are welcome to <a href="mailto:infoworld@qbangsolutions.com?subject=Secure%20Linux%20Appliances%20in%20Your%20Enterprise">reach out to me</a> if they need some help or just want to share their ideas on a new use for a Debian Router.</p>
<p>In the future, I&#8217;ll touch on embedded Linux in extremely cheap devices that are excellent for smaller tasks.<br />
<strong>[My q!Bang Solutions co-owner Josh Kuo beat me to the punch. Read his article <a target="_blank" title="Beef Up Your Wireless Router" href="http://weblog.infoworld.com/geeks/archives/2007/02/beef_up_your_wi.html">"Beef Up Your Wireless Router"</a>.]</strong></p>
<p><a href="mailto:infoworld@qbangsolutions.com?subject=Secure%20Linux%20Appliances%20in%20Your%20Enterprise">High Mobley</a><br />
Co-Owner of <a target="qbangsolutions" title="q!Bang Solutions: Solutions You Want. Done." href="http://www.qbangsolutions.com">q!Bang Solutions</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.qbangsolutions.com/secure-linux-appliances-in-your-enterprise/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Computer security explained for the masses</title>
		<link>http://blog.qbangsolutions.com/computer-security-explained-for-the-masses/</link>
		<comments>http://blog.qbangsolutions.com/computer-security-explained-for-the-masses/#comments</comments>
		<pubDate>Tue, 27 Feb 2007 07:17:18 +0000</pubDate>
		<dc:creator>high</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[q!News]]></category>

		<guid isPermaLink="false">http://www.qbangsolutions.com/blog/index.php/2007/02/26/computer-security-explained-for-the-masses/</guid>
		<description><![CDATA[(Originally posted on InfoWorld Magazine)
It is often cited that the biggest issue in the fight against worms and viruses and other such malware is uneducated users. If a person doesn&#8217;t understand why it&#8217;s a bad thing to open email attachments from people that he doesn&#8217;t know, then you can bet that he will open every [...]]]></description>
			<content:encoded><![CDATA[<p><em>(Originally posted on <a title="InfoWorld Magazine" target="InfoWorld" href="http://weblog.infoworld.com/geeks/archives/2007/01/computer_securi.html">InfoWorld Magazine</a>)</em></p>
<p>It is often cited that the biggest issue in the fight against worms and viruses and other such malware is uneducated users. If a person doesn&#8217;t understand why it&#8217;s a bad thing to open email attachments from people that he doesn&#8217;t know, then you can bet that he will open every attachment which comes to him. Several email clients (not just MS Outlook!) will happily open and execute any Visual Basic or batch file that a user clicks on. Then wham! &#8211; You&#8217;ve got an infected machine that&#8217;s probably already calling home to the nasty individual who wrote the malware and now &#8220;owns&#8221; the user&#8217;s computer &#8211; which you as the IT department have to go and fix&#8230;</p>
<p>Of course the various network security and bug tracking sites are great about announcing the security flaws and exploits that are found, but arguably their audience is only people who are already pretty savvy about security issues. So I was pleased to see an article written more for public consumption at <a title="How Stuff Works" target="_blank" href="http://www.howstuffworks.com">howstuffworks.com</a> today, entitled <a target="_blank" title="What's the Problems with Microsoft Word?" href="http://computer.howstuffworks.com/ref/word-flaws.htm?cid=rss1">&#8220;What&#8217;s the problem with Microsoft Word?&#8221;</a>. The author, <a target="_blank" title="About Julia Layton" href="http://computer.howstuffworks.com/ref/about-author.htm#layton">Julia Layton</a>, does an excellent job of explaining some computer security jargon and bringing the layman up to speed with the MS Word zero-day flaws which were recently announced. I hope that this is a sign of a new trend of educating the end user in a comprehensible language.</p>
<p>When I was a full time sysadmin and helpdesk tech responsible for a few hundred users and 50 servers, I struggled to explain the same topics to the many end users individually. So instead, I sent out ocassional messages via email with some helpful tip on how to use their computer or a link to a web article that contained some useful information on a subject that I knew would tweak their interest. So I always had these sorts of articles bookmarked to send out to my users. They appreciated that I was trying to educate them and I appreciated that I had fewer infected machines to reformat and reinstall.</p>
<p><a href="mailto:infoworld@qbangsolutions.com?subject=Computer%20Security%20Explained%20for%20the%20Masses">High Mobley</a><br />
Co-Owner of <a title="q!Bang Solutions: Solutions You Want. Done." target="qbangsolutions" href="http://www.qbangsolutions.com">q!Bang Solutions</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.qbangsolutions.com/computer-security-explained-for-the-masses/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Beef Up Your Wireless Router article posted at InfoWorld Magazine</title>
		<link>http://blog.qbangsolutions.com/beef-up-your-wireless-router-article-posted-at-infoworld-magazine/</link>
		<comments>http://blog.qbangsolutions.com/beef-up-your-wireless-router-article-posted-at-infoworld-magazine/#comments</comments>
		<pubDate>Mon, 05 Feb 2007 20:28:21 +0000</pubDate>
		<dc:creator>high</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Open source]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Systems]]></category>
		<category><![CDATA[VoIP]]></category>
		<category><![CDATA[q!News]]></category>

		<guid isPermaLink="false">http://www.qbangsolutions.com/blog/index.php/2007/02/05/beef-up-your-wireless-router-article-posted-at-infoworld-magazine/</guid>
		<description><![CDATA[Josh Kuo has posted his article Beef Up Your Wireless Router on the InfoWorld magazine web site. This is a good overview on the opportunities presented by instaling the Linux based OpenWRT OS on your wireless router device. As always, your comments are appreciated.
]]></description>
			<content:encoded><![CDATA[<p>Josh Kuo has posted his article <em><a title="InfoWorld: Beef Up Your Wireless Router" target="_blank" href="http://weblog.infoworld.com/geeks/archives/2007/02/beef_up_your_wi.html">Beef Up Your Wireless Router</a></em> on the InfoWorld magazine web site. This is a good overview on the opportunities presented by instaling the Linux based OpenWRT OS on your wireless router device. As always, your comments are appreciated.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.qbangsolutions.com/beef-up-your-wireless-router-article-posted-at-infoworld-magazine/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Secure Linux Appliances article posted to InfoWorld Magazine</title>
		<link>http://blog.qbangsolutions.com/secure-linux-appliances-article-posted-to-infoworld-magazine/</link>
		<comments>http://blog.qbangsolutions.com/secure-linux-appliances-article-posted-to-infoworld-magazine/#comments</comments>
		<pubDate>Mon, 05 Feb 2007 20:22:39 +0000</pubDate>
		<dc:creator>high</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Open source]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Systems]]></category>
		<category><![CDATA[VoIP]]></category>
		<category><![CDATA[q!News]]></category>

		<guid isPermaLink="false">http://www.qbangsolutions.com/blog/index.php/2007/02/05/secure-linux-appliances-article-posted-to-infoworld-magazine/</guid>
		<description><![CDATA[High Mobley&#8217;s article Secure Linux Appliances in Your Enterprise has been posted to the InfoWolrd magazine web site. This article is an informative overview of the Debian Router Project, and the myriad possibiltiies that it presents for Linux appliances that you can easily make yourself. Your comments are appreciated.
]]></description>
			<content:encoded><![CDATA[<p>High Mobley&#8217;s article <em><a title="InfoWorld: Secure Linux Appliances in Your Enterprise" target="_blank" href="http://weblog.infoworld.com/geeks/archives/2007/01/secure_linux_ap.html">Secure Linux Appliances in Your Enterprise</a></em> has been posted to the InfoWolrd magazine web site. This article is an informative overview of the Debian Router Project, and the myriad possibiltiies that it presents for Linux appliances that you can easily make yourself. Your comments are appreciated.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.qbangsolutions.com/secure-linux-appliances-article-posted-to-infoworld-magazine/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Computer Security Explained Article Posted to InfoWorld Magazine</title>
		<link>http://blog.qbangsolutions.com/first-article-posted-to-infoworld-magazine/</link>
		<comments>http://blog.qbangsolutions.com/first-article-posted-to-infoworld-magazine/#comments</comments>
		<pubDate>Thu, 01 Feb 2007 23:47:44 +0000</pubDate>
		<dc:creator>high</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[q!News]]></category>

		<guid isPermaLink="false">http://www.qbangsolutions.com/blog/index.php/2007/02/01/first-article-posted-to-infoworld-magazine/</guid>
		<description><![CDATA[The article Computer Security Explained for the Masses by q!Bang co-owner High Mobley has been published on the InfoWorld magazine blog site. Please give it a read and post your comments.
]]></description>
			<content:encoded><![CDATA[<p>The article <em><a target="_blank" title="InfoWorld - Computer Security Explained for the Masses" href="http://weblog.infoworld.com/geeks/archives/2007/01/computer_securi.html">Computer Security Explained for the Masses</a></em> by q!Bang co-owner High Mobley has been published on the InfoWorld magazine blog site. Please give it a read and post your comments.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.qbangsolutions.com/first-article-posted-to-infoworld-magazine/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco owners be very afraid</title>
		<link>http://blog.qbangsolutions.com/cisco-owners-be-very-afraid/</link>
		<comments>http://blog.qbangsolutions.com/cisco-owners-be-very-afraid/#comments</comments>
		<pubDate>Thu, 25 Jan 2007 23:15:01 +0000</pubDate>
		<dc:creator>John Jones</dc:creator>
				<category><![CDATA[Networking]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.qbangsolutions.com/blog/index.php/2007/01/25/cisco-owners-be-very-afraid/</guid>
		<description><![CDATA[Cisco Systems Inc. security has announced 3 remotely exploitable flaws for the Cisco IOS software:

Crafted TCP Packet Can Cause Denial of Service
Crafted IP Option Vulnerability
IPv6 Routing Header Vulnerability

Usually these security notifications are released to large customers before the general public, so large customers have time to update or protect their equipment. However, it&#8217;s the smaller [...]]]></description>
			<content:encoded><![CDATA[<p>Cisco Systems Inc. security has announced 3 remotely exploitable flaws for the Cisco IOS software:</p>
<ul>
<li><a title="Crafted TCP Packet Can Cause Denial of Service" href="http://www.cisco.com/warp/public/707/cisco-sa-20070124-crafted-tcp.shtml">Crafted TCP Packet Can Cause Denial of Service</a></li>
<li><a target="_blank" title="Crafted IP Option Vulnerability" href="http://www.cisco.com/en/US/products/products_security_advisory09186a00807cb157.shtml">Crafted IP Option Vulnerability</a></li>
<li><a title="IPv6 Routing Header Vulnerability" href="http://www.cisco.com/en/US/products/products_security_advisory09186a00807cb0fd.shtml">IPv6 Routing Header Vulnerability</a></li>
</ul>
<ol />Usually these security notifications are released to large customers before the general public, so large customers have time to update or protect their equipment. However, it&#8217;s the smaller networks that are at  the greatest risk. Many don&#8217;t have Cisco support contracts (or can&#8217;t afford them), or don&#8217;t have an individual on staff to upgrade their equipment.</p>
<p>When will the first exploit code be released? Will anybody admit to being compromised by the exploit? How will a common user realize they have a problem? The small business customers who think owning Cisco is the way to go need to address the total cost of keeping those systems up to date. Many times a customer won&#8217;t upgrade a core router or switch because they don&#8217;t know how or don&#8217;t know they have a problem. How many service providers will contact their customers warning them about these flaws? Most small businesses don&#8217;t have a clue if they are vulnerable or not. How does Cisco fix this issue? What means does a small company have to keep all their systems up to date? Most end users barely can keep up with Windows, virus, adware and spyware updates little alone keeping up with all their network equipment. How many people have updated the software on your home router?</p>
<p>I believe the next great worm will be targeted towards networking equipment. How about taking over all the Linksys routers/access points and making them spam bots or open relays? What about using a Cisco vulnerability to create tunnels to specific locations to monitor all traffic through a router. More to come &#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.qbangsolutions.com/cisco-owners-be-very-afraid/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
