RE: Cisco vulnerability scanning increase

Jose Nazario <[email protected]>
Newsgroups gmane.comp.security.incidents
Message-ID <[email protected]>
as noted on the nanog list recently, this vulnerability is from 2001 and
has been fixed in the 12.x releases of IOS.

	http://www.cisco.com/warp/public/707/IOS-httplevel-pub.html

from the advisory:

The workaround for this vulnerability is to disable HTTP server on the
router or to use TACACS+ or Radius for authentication.

To disable HTTP server, use the following commands:

Router# configure terminal
Enter configuration commands, one per line.  End with CNTL/Z.
Router(config)# no ip http server





hope this helps,

________
jose nazario, ph.d.			[email protected]
http://monkey.org/~jose/ 		http://infosecdaily.net/
					http://www.wormblog.com/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.