Core researcher Sebastian Muñiz´ presentation, "Cisco IOS Rootkits" highlights a technique he developed through which Cisco routers running the vendor´s Internetwork Operating System (IOS) can be made vulnerable to generic rootkits. Developed by Muñiz through the reverse engineering of a legitimate IOS upgrade file, the demonstration does not take advantage of any vulnerability (known or unknown) present in Cisco´s software. Instead, the presentation illustrates how someone who has access to IOS firmware files or administrative login credentials to an enterprise network´s routing or switching equipment could abuse privileges to plant a rootkit program into the device´s memory.
Date: May 22, 2008
Location: London, UK











