Sebastian Muniz says: The rootkit consists of a binary modification to the IOS image downloaded from the device so it has a pretty big and obvious footprint. More stealth is not needed for the presentation to make the points I want to make.
Sean Comeau says: Are there any existing tools to detect unauthorized modification of IOS?
Sebastian Muniz says: Yes, CIR "Cisco Information Retrieval" created by FX is THE TOOL in this case.[...]so, if those functions are hooked by the rootkit, the result may not be correct.
http://eusecwest.com/sebastian-muniz-da-ios-rootkit.html