Re: Cisco Smart Install script
Robin Wood <[email protected]> Thu, 19 Sep 2019 08:06:39 +0100
| Newsgroups | gmane.comp.security.nmap.devel |
|---|---|
| Message-ID | <CALmccy7PhNDi-tRT3uwRgm_xNYVb0kisN3=XupcWBGYtwXpckA@mail.gmail.com> |
--===============5051725684711871159== Content-Type: multipart/alternative; boundary="00000000000003dee10592e2995a" --00000000000003dee10592e2995a Content-Type: text/plain; charset="UTF-8" If it's the same issue I think it is, Nessus reports it as an info. The one that they report on can also be used to do unauthenticated code exec but is a feature not "vulnerability" so not a problem. Robin On Mon, 9 Sep 2019, 18:34 Gordon Fyodor Lyon, <[email protected]> wrote: > > > On Mon, Aug 26, 2019 at 4:08 AM XenoN. w0w <[email protected]> wrote: > >> Hello guys, during penetration testing engagements I often come to cisco >> devices which allows me to grab their config over smart install protocol. >> >> I would like to make a script and add functionality of testing and >> getting config within the script. >> >> Here is the link for reference exploit https://github.com/Sab0tag3d/SIET >> >> >> >> What do you guys think about it? >> > > Thanks for the details. And wow, the Cisco advisory[1] really tries to > shirk all responsibility for this mess by writing: > > "Cisco does not consider this a vulnerability in Cisco IOS, IOS XE, or the > Smart Install feature itself but a misuse of the Smart Install protocol, > which does not require authentication by design." > > Well maybe they shouldn't have introduced such a lame "feature" in the > first place. And even though it is broken by design, there are lots of > ways that Cisco could have at least mitigated the problem. Apparently they > only recently added a command to turn this crap off. > > Anyway, yeah, we'd like to see an NSE script or other Nmap features > related to this. For example, does Nmap version detection (-sV) detect > this properly? Are there good ways to detect the vulnerability (beyond just > port 4786 being open) without reconfiguring the device or otherwise being > too intrusive? I mean an exploitation feature is nice too, but often Nmap > users just want to learn as much as possible about the device and > vulnerability without doing anything too intrusive. > > Cheers, > Fyodor > > > [1] > https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170214-smi > > > _______________________________________________ > Sent through the dev mailing list > https://nmap.org/mailman/listinfo/dev > Archived at http://seclists.org/nmap-dev/ --00000000000003dee10592e2995a Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"auto">If it's the same issue I think it is, Nessus reports = it as an info. The one that they report on can also be used to do unauthent= icated code exec but is a feature not "vulnerability" so not a pr= oblem.<div dir=3D"auto"><br></div><div dir=3D"auto">Robin</div></div><br><d= iv class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Mon, 9 Se= p 2019, 18:34 Gordon Fyodor Lyon, <<a href=3D"mailto:[email protected]">fy= [email protected]</a>> wrote:<br></div><blockquote class=3D"gmail_quote" sty= le=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div d= ir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quote"><div d= ir=3D"ltr" class=3D"gmail_attr">On Mon, Aug 26, 2019 at 4:08 AM XenoN. w0w = <<a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D"norefer= rer">[email protected]</a>> wrote:<br></div><blockquote class=3D"gmail= _quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204= ,204);padding-left:1ex"> <div lang=3D"EN-US"> <div class=3D"m_1723389174890974703gmail-m_-2586403025385974687WordSection1= "> <p class=3D"MsoNormal"><span style=3D"font-size:11pt">Hello guys, during pe= netration testing engagements I often come to cisco devices which allows me= to grab their config over smart install protocol. <u></u><u></u></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:11pt">I would like to make = a script and add functionality of testing and getting config within the scr= ipt.<u></u><u></u></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:11pt">Here is the link for = reference exploit <a href=3D"https://github.com/Sab0tag3d/SIET" target=3D"_blank" rel=3D"nore= ferrer">https://github.com/Sab0tag3d/SIET</a><u></u><u></u></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:11pt"><u></u>=C2=A0<u></u><= /span></p> <p class=3D"MsoNormal"><span style=3D"font-size:11pt">What do you guys thin= k about it?</span></p></div></div></blockquote><div><br></div><div>Thanks f= or the details.=C2=A0 And wow, the Cisco advisory[1] really tries to shirk = all responsibility for this mess by writing:</div><div><br></div><div>"= ;Cisco does not consider this a vulnerability in Cisco IOS, IOS XE, or the = Smart Install feature itself but a misuse of the Smart Install protocol, wh= ich does not require authentication by design."</div></div><div class= =3D"gmail_quote"><br></div><div class=3D"gmail_quote">Well maybe they shoul= dn't have introduced such a lame "feature" in the first place= .=C2=A0 And even though it is broken by design, there are lots of ways that= Cisco could have at least mitigated the problem.=C2=A0 Apparently they onl= y recently added a command to turn this crap off.</div><div class=3D"gmail_= quote"><br></div><div class=3D"gmail_quote">Anyway, yeah, we'd like to = see an NSE script or other Nmap features related to this.=C2=A0 For example= , does Nmap version detection (-sV) detect this properly? Are there good wa= ys to detect the vulnerability (beyond just port 4786 being open) without r= econfiguring the device or otherwise being too intrusive?=C2=A0 I mean an e= xploitation feature is nice too, but often Nmap users just want to learn as= much as possible about the device and vulnerability without doing anything= too intrusive.</div><div class=3D"gmail_quote"><br></div><div class=3D"gma= il_quote">Cheers,</div><div class=3D"gmail_quote">Fyodor</div><div class=3D= "gmail_quote"><br></div><div class=3D"gmail_quote"><br></div><div class=3D"= gmail_quote">[1]=C2=A0<a href=3D"https://tools.cisco.com/security/center/co= ntent/CiscoSecurityAdvisory/cisco-sa-20170214-smi" target=3D"_blank" rel=3D= "noreferrer">https://tools.cisco.com/security/center/content/CiscoSecurityA= dvisory/cisco-sa-20170214-smi</a><br><div><br></div><div>=C2=A0<br></div></= div></div> _______________________________________________<br> Sent through the dev mailing list<br> <a href=3D"https://nmap.org/mailman/listinfo/dev" rel=3D"noreferrer norefer= rer" target=3D"_blank">https://nmap.org/mailman/listinfo/dev</a><br> Archived at <a href=3D"http://seclists.org/nmap-dev/" rel=3D"noreferrer nor= eferrer" target=3D"_blank">http://seclists.org/nmap-dev/</a></blockquote></= div> --00000000000003dee10592e2995a-- --===============5051725684711871159== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Sent through the dev mailing list https://nmap.org/mailman/listinfo/dev Archived at http://seclists.org/nmap-dev/ --===============5051725684711871159==--