Re: Cisco Smart Install script

Gordon Fyodor Lyon <[email protected]> Mon, 9 Sep 2019 10:33:39 -0700
Newsgroups gmane.comp.security.nmap.devel
Message-ID <CAJjO9MkcDrZ00fbauvtvstzh2fzWuAX-3ZAdFmYt5LU5ZmKM1w@mail.gmail.com>
--===============2843975095040991199==
Content-Type: multipart/alternative; boundary="0000000000005aea3c0592223228"

--0000000000005aea3c0592223228
Content-Type: text/plain; charset="UTF-8"

On Mon, Aug 26, 2019 at 4:08 AM XenoN. w0w <[email protected]> wrote:

> Hello guys, during penetration testing engagements I often come to cisco
> devices which allows me to grab their config over smart install protocol.
>
> I would like to make a script and add functionality of testing and getting
> config within the script.
>
> Here is the link for reference exploit https://github.com/Sab0tag3d/SIET
>
>
>
> What do you guys think about it?
>

Thanks for the details.  And wow, the Cisco advisory[1] really tries to
shirk all responsibility for this mess by writing:

"Cisco does not consider this a vulnerability in Cisco IOS, IOS XE, or the
Smart Install feature itself but a misuse of the Smart Install protocol,
which does not require authentication by design."

Well maybe they shouldn't have introduced such a lame "feature" in the
first place.  And even though it is broken by design, there are lots of
ways that Cisco could have at least mitigated the problem.  Apparently they
only recently added a command to turn this crap off.

Anyway, yeah, we'd like to see an NSE script or other Nmap features related
to this.  For example, does Nmap version detection (-sV) detect this
properly? Are there good ways to detect the vulnerability (beyond just port
4786 being open) without reconfiguring the device or otherwise being too
intrusive?  I mean an exploitation feature is nice too, but often Nmap
users just want to learn as much as possible about the device and
vulnerability without doing anything too intrusive.

Cheers,
Fyodor


[1]
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170214-smi

--0000000000005aea3c0592223228
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quote">=
<div dir=3D"ltr" class=3D"gmail_attr">On Mon, Aug 26, 2019 at 4:08 AM XenoN=
. w0w &lt;<a href=3D"mailto:[email protected]">[email protected]</a>&gt=
; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px=
 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">





<div lang=3D"EN-US">
<div class=3D"gmail-m_-2586403025385974687WordSection1">
<p class=3D"MsoNormal"><span style=3D"font-size:11pt">Hello guys, during pe=
netration testing engagements I often come to cisco devices which allows me=
 to grab their config over smart install protocol.
<u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11pt">I would like to make =
a script and add functionality of testing and getting config within the scr=
ipt.<u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11pt">Here is the link for =
reference exploit
<a href=3D"https://github.com/Sab0tag3d/SIET" target=3D"_blank">https://git=
hub.com/Sab0tag3d/SIET</a><u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11pt"><u></u>=C2=A0<u></u><=
/span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11pt">What do you guys thin=
k about it?</span></p></div></div></blockquote><div><br></div><div>Thanks f=
or the details.=C2=A0 And wow, the Cisco advisory[1] really tries to shirk =
all responsibility for this mess by writing:</div><div><br></div><div>&quot=
;Cisco does not consider this a vulnerability in Cisco IOS, IOS XE, or the =
Smart Install feature itself but a misuse of the Smart Install protocol, wh=
ich does not require authentication by design.&quot;</div></div><div class=
=3D"gmail_quote"><br></div><div class=3D"gmail_quote">Well maybe they shoul=
dn&#39;t have introduced such a lame &quot;feature&quot; in the first place=
.=C2=A0 And even though it is broken by design, there are lots of ways that=
 Cisco could have at least mitigated the problem.=C2=A0 Apparently they onl=
y recently added a command to turn this crap off.</div><div class=3D"gmail_=
quote"><br></div><div class=3D"gmail_quote">Anyway, yeah, we&#39;d like to =
see an NSE script or other Nmap features related to this.=C2=A0 For example=
, does Nmap version detection (-sV) detect this properly? Are there good wa=
ys to detect the vulnerability (beyond just port 4786 being open) without r=
econfiguring the device or otherwise being too intrusive?=C2=A0 I mean an e=
xploitation feature is nice too, but often Nmap users just want to learn as=
 much as possible about the device and vulnerability without doing anything=
 too intrusive.</div><div class=3D"gmail_quote"><br></div><div class=3D"gma=
il_quote">Cheers,</div><div class=3D"gmail_quote">Fyodor</div><div class=3D=
"gmail_quote"><br></div><div class=3D"gmail_quote"><br></div><div class=3D"=
gmail_quote">[1]=C2=A0<a href=3D"https://tools.cisco.com/security/center/co=
ntent/CiscoSecurityAdvisory/cisco-sa-20170214-smi">https://tools.cisco.com/=
security/center/content/CiscoSecurityAdvisory/cisco-sa-20170214-smi</a><br>=
<div><br></div><div>=C2=A0<br></div></div></div>

--0000000000005aea3c0592223228--

--===============2843975095040991199==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Sent through the dev mailing list
https://nmap.org/mailman/listinfo/dev
Archived at http://seclists.org/nmap-dev/
--===============2843975095040991199==--