Talos is releasing an advisory for multiple vulnerabilities that have been found within the Total Commander FileInfo Plugin. These vulnerabilities are local denial of service flaws and have been assigned CVE-2015-2869. In accordance with our Vendor Vulnerability Reporting and Disclosure policy, these vulnerabilities have been disclosed to the plugin author(s) and CERT. This post serves as a summary of the advisory.
Credit for these discoveries belongs to Marcin Noga of Talos.
An attacker who controls the content of a COFF Archive Library (.lib) file can can cause an out of bounds read by specifying overly large values for the ‘Size’ field of the Archive Member Header or the “Number Of Symbols” field in the 1st Linker Member. The second half of the vulnerability concerns an attacker who controls the content of a Linear Executable file can cause an out of bounds read by specifying overly large values for the “Resource Table Count” field of the LE Header or the “Object” field at offset 0x8 from a “Resource Table Entry”. An attacker who successfully exploits this vulnerability can cause the Total Commander application to unexpectedly terminate.
These vulnerabilities has been tested against FileInfo 2.21 and FileInfo 2.22.
Finding and disclosing zero-day vulnerabilities responsibly helps improve the overall security of the devices and software people use on a day-to-day basis. Talos is committed to this effort via developing programmatic ways to identify problems or flaws that could be otherwise exploited by malicious attackers. These developments help secure the platforms and software customers use and also help provide insight into how Cisco can improve its own processes to develop better products.
Ecosystem partners are an important adjunct to Cisco Connected Mobile Experience (CMX). They augment the analytic and customer engagement capabilities of the solution with innovative business outcomes. This blog is one in a series that will highlight several of our CMX Ecosystem Partners. Today—Aislelabs.
Based in Toronto, Canada, Aislelabs is a Cisco Solutions partner with a portfolio of advanced location-based technologies serving large indoor venues such as shopping malls, airports, big box retail stores, convention centers, and other large spaces. Working with the Connected Mobile Experiences solution, their portfolio leverages the Wi-Fi and BLE beacon location information collected and calculated by Cisco.
Aislelabs Flow: Detailed venue analytics utilizing anonymous Wi-Fi data with no required app. Taps directly into existing Wi-Fi and delivers highly granular, customizable analytics around customer behavior.
Aislelabs Social Wi-Fi: Social analytics for the physical space to further understand guest’s interests, demographics, and where they spend most of their time. Enables email and social marketing campaigns targeting guests as well as advanced re-targeting (social, display ads) once they have left the venue. Continue reading “Aislelabs and Cisco Take Off”
In the past year, Cisco has significantly ramped up its use of renewable energy with a focus on solar. We’ve been sharing these activities in press releases, blog posts, videos and our annual CSR report, but we haven’t talked about why – and these reasons are deeper than just a commitment to the environment.
Here’s a short summary of some of our recent activities with renewable energy:
Signed an agreement with NRG Renew LLC, a wholly owned subsidiary of NRG Energy, Inc. (NYSE:NRG), to purchase the output of a 20 MW solar energy facility located in Blythe, California for our San Jose headquarters and surrounding Bay Area locations
Completed 4 on-site solar projects at our sites in Texas, Massachusetts, and Bangalore, India taking our total solar production capacity over 2 MW (see photos below)
Launched a solar discount program for employees and contractors, along with their friends and family, to simplify and reduce the cost of installing solar panels on their homes leading to over 50 installations totaling over 250 kW in less than 1 year
Free standing solar PV array in the parking area of Cisco’s campus in Boxborough, MassachusettsSolar PV array on top of Cisco’s data center in Allen, Texas
Why have we undertaken these activities? Certainly, each of these actions are helping bring more renewable power on line, reducing greenhouse gas emissions and moving us toward a better environment. But any company, in any industry, can make the same claim. To be authentic, it has to hold a special significance related to why Cisco exists.
A few weeks ago, we brought a video crew up to the Cisco Spark office in San Francisco. We asked product managers Taylor, Renaldo, and Eric to show us Cisco Spark and chat about product development.
Given Taylor is a former Stanford football player, Eric used to do standup comedy, and Renaldo is just “the man,” I figured it couldn’t hurt to go a little off script with these characters. We set up what MTV’s Real World might call a “confessional” with a person in front of a rolling camera and an open mic. If you were hoping for sobbing monologues or ill-tempered rants, you’ll have to tune into the latest summer reality show. But we definitely got some good stuff about their day jobs, and here it is:
I caught up with Danilo Ribeiro, Strategic Alliance Program Manager from OSIsoft, at Cisco Live recently, and shot a video of the OSIsoft demonstration he was showing. In the video, Danilo talks about Fog Computing and thermal imaging analytics at the edge using the OSIsoft PI System and Cisco IOx.
The PI System is used by many, if not most, industrial companies to capture real-time data and events and manage an historian, interfacing to critical ERP, BI, process monitoring and office systems.
Danilo’s demonstration shows a thermal imaging camera detecting a gas ‘flare’ from the field (in the demo it’s a heat source mounted above the booth in this case to show the real-time data capture). The OSIsoft system is able to detect the anomaly and alert remote operators rapidly so that corrective action can be taken.
In the video Danilo talks about how the demonstration simulates a flare monitoring system. This is the kind of monitoring that happened in oil and gas fields like the one in operation at PETRONAS Penapisan Melake, Malaysia. PETRONAS has evolved into a fully integrated multinational oil and gas company. PETRONAS’ refining capacity, at 323,300 bpd (2012) is over half of the 2012 total refining capacity in Malaysia. PETRONAS CARIGALI is the upstream arm of Malaysia’s state-owned, fully integrated oil and gas company. Continue reading “Thermal Imaging Analysis – easy as PI with OSIsoft at Cisco Live”
To see the growing role that technology is playing in law enforcement, all we need to do is turn on the news. From the growing call for police body worn cameras to the lack of physical security surveillance capabilities in an aged correctional facility system, there is an increased demand for law enforcement organizations to respond more quickly and effectively and with greater transparency to crises. In order to improve the collaboration and communication within agencies and with the broader community of public safety officials, Cisco and Verizon have teamed up to create a national public safety collaboration cloud for the eco-system of public safety organizations.
The National Sheriffs’ Association Collaboration Cloud will enable sheriff offices to easily acquire, deploy and communicate using video technology. The Sheriffs will also expand this collaboration to their public safety partners in all 3080 counties of the United States, so law enforcement organizations will be able to allow their personnel to quickly communicate within their own department or with other local, state or federal agencies to conduct their business. Using the cloud, law enforcement organizations can respond more effectively to real-time incidences as they occur and work together on inter-department or inter-agency task forces with ease.
The new cloud based collaboration technology will improve many areas of law enforcement activities, including patrol vehicle applications and drug and gang task force collaboration. The areas of probation and parole will also benefit from this service as they interact with correctional facilities, prosecutors, defense lawyers and the courts.
For example, the collaboration cloud can be used for video meetings and hearings with attorneys, judges and inmates at correctional facilities. This helps law enforcement organizations to significantly reduce transportation and overtime costs for personnel. It can also reduce other public safety risks including reduced movement of incarcerated individuals by enabling legal teams and providers of numerous inmate services to communicate with inmates via video.
The National Sheriffs’ Association Collaboration Cloud will give law enforcement organizations better access to resources to train their personnel on emerging response tactics and mandated training certifications. By equipping training rooms for remote training and accreditation services, organizations will be able to expand their programming significantly. This collaboration cloud also enables real-time communication between patrol cars, emergency operations centers, 911 centers and dispatch locations using a myriad of devices including tablets, smart phones and laptop computers. It opens the pathway of reducing the largest budget number in corrections through the delivery of telehealth in county jails, juvenile detention centers and state prisons.
As the demand for technology in public safety grows, Cisco remains committed to working with these organizations as they move into this new technology-driven future. Whether through connected justice initiatives, cybersecurity or collaboration efforts such as the Sheriffs’ Association’s Collaboration Cloud, Cisco is dedicated to improving efficiency across all areas of public safety, harnessing the power of the Internet of Everything (IoE) to transform the eco-system of justice and improve community public safety.
To learn more about how Cisco is leveraging IoE in the justice, public safety and security sectors, click here.
Several years ago, an employee at an organization I worked for was terminated from his job, effective immediately. While being escorted from the facility this user picked up “his” backup media and started to leave the building. Fortunately, the security guards thought this was a little suspicious and escorted the user to the data center to ask whether this was permitted. They learned it wasn’t permitted and the user challenged the company’s right to confiscate of “his backup media”. In this case, the company had the foresight to implement an early version of a cybersecurity management program (CMP) backed by a CEO endorsed cybersecurity policy. This program contained a simple, mostly overlooked clause in the user account agreement that assigned ownership of all data created or stored on media written on by company computers, and the media itself, to the company without reservation. Since the user had signed this user account agreement, he had given up all rights to the media and its contents. The company retained the media and the former employee was summarily escorted off premises. The backup media contained some of the company’s latest designs, which he was attempting to steal. Without their CMP, the company could have been exposed to serious financial risk and potentially reputational damage. Continue reading “Top 5 Success Factors for Cybersecurity Management Programs”
The Cisco ACI partner eco-system is growing rapidly. I was privileged to see prima-facie, at Cisco Live San Diego last month, the excitement surrounding AVI’s solution announcement with Cisco ACI and the growing customer interest. Though a late-comer to the ADC (Application delivery controller) market, AVI packs a punch to make customers and partners sit up and listen. What’s impressive is that, more than 20 customer deployments are already under way, both in private clouds and on premise Data Centers. In this blog, I want so share some of the key value-props and architectural benefits Cisco ACI-AVI joint solution brings to Application deployment in Data Centers.
The highly complementary nature of the AVI CADP (Cloud Application delivery platform) and Cisco ACI solution is achieved through a common architecture featuring unified management and control planes, as well as the ability to scale data plane resources elastically, on-demand as application requirements dictate.
The AVI solution integrates into Cisco ACI environments through RESTful APIs, providing end-users with holistic application delivery, security and load balancing, in addition to real-time visibility, monitoring, and integrated (inline) analytics of their on premise and cloud-based applications.
A simple architectural depiction will help understand how Cisco ACI and AVI Networks solution works.
The collaboration between Cisco and AVI Networks has delivered a highly integrated, L2–L7 solution that automates and simplifies the insertion, provisioning and scaling of key network services into a Cisco ACI fabric. The solution also delivers end-to-end visibility and analytics that provide actionable insights into application performance and the end-user experience, which are critical in modern data centers.
The Cisco ACI – AVI Networks CADP joint solution provides customers key benefits such as:
Quick deployment with a high degree of automation
Quick app provisioning with zero-touch L4-L7 service lifecycle management
Full-stack L2-L7 visibility and closed-loop analytics
Stay tuned for more exciting news on the ACI-AVI solution front.
#CiscoChampion Radio is a podcast series by Cisco Champions as technologists. Today we’ll be talking about getting started in I.T. with Cisco Champions Rowell Dionicio and Justin Parisi. Our guest hosts this week are Networking Academy members Tim Harmon and Nick Saylor.
Learn about the Cisco Champions Program HERE.
See a list of all #CiscoChampion Radio podcasts HERE. Ask about the next round of Cisco Champions nominations. EMAIL US.
Highlights Up and coming skills for new professionals
Getting your foot in the door
What hiring managers look for
Overcoming lack of experience
The most important tools you’ll need to jump start your career
Networking and Tech Groups Continue reading “#CiscoChampion Radio S2|Ep 27. Getting Started in I.T.”