Re: Cisco Smart Install script

Robin Wood <[email protected]> Thu, 19 Sep 2019 08:06:39 +0100
Newsgroups gmane.comp.security.nmap.devel
Message-ID <CALmccy7PhNDi-tRT3uwRgm_xNYVb0kisN3=XupcWBGYtwXpckA@mail.gmail.com>
--===============5051725684711871159==
Content-Type: multipart/alternative; boundary="00000000000003dee10592e2995a"

--00000000000003dee10592e2995a
Content-Type: text/plain; charset="UTF-8"

If it's the same issue I think it is, Nessus reports it as an info. The one
that they report on can also be used to do unauthenticated code exec but is
a feature not "vulnerability" so not a problem.

Robin

On Mon, 9 Sep 2019, 18:34 Gordon Fyodor Lyon, <[email protected]> wrote:

>
>
> On Mon, Aug 26, 2019 at 4:08 AM XenoN. w0w <[email protected]> wrote:
>
>> Hello guys, during penetration testing engagements I often come to cisco
>> devices which allows me to grab their config over smart install protocol.
>>
>> I would like to make a script and add functionality of testing and
>> getting config within the script.
>>
>> Here is the link for reference exploit https://github.com/Sab0tag3d/SIET
>>
>>
>>
>> What do you guys think about it?
>>
>
> Thanks for the details.  And wow, the Cisco advisory[1] really tries to
> shirk all responsibility for this mess by writing:
>
> "Cisco does not consider this a vulnerability in Cisco IOS, IOS XE, or the
> Smart Install feature itself but a misuse of the Smart Install protocol,
> which does not require authentication by design."
>
> Well maybe they shouldn't have introduced such a lame "feature" in the
> first place.  And even though it is broken by design, there are lots of
> ways that Cisco could have at least mitigated the problem.  Apparently they
> only recently added a command to turn this crap off.
>
> Anyway, yeah, we'd like to see an NSE script or other Nmap features
> related to this.  For example, does Nmap version detection (-sV) detect
> this properly? Are there good ways to detect the vulnerability (beyond just
> port 4786 being open) without reconfiguring the device or otherwise being
> too intrusive?  I mean an exploitation feature is nice too, but often Nmap
> users just want to learn as much as possible about the device and
> vulnerability without doing anything too intrusive.
>
> Cheers,
> Fyodor
>
>
> [1]
> https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170214-smi
>
>
> _______________________________________________
> Sent through the dev mailing list
> https://nmap.org/mailman/listinfo/dev
> Archived at http://seclists.org/nmap-dev/

--00000000000003dee10592e2995a
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"auto">If it&#39;s the same issue I think it is, Nessus reports =
it as an info. The one that they report on can also be used to do unauthent=
icated code exec but is a feature not &quot;vulnerability&quot; so not a pr=
oblem.<div dir=3D"auto"><br></div><div dir=3D"auto">Robin</div></div><br><d=
iv class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Mon, 9 Se=
p 2019, 18:34 Gordon Fyodor Lyon, &lt;<a href=3D"mailto:[email protected]">fy=
[email protected]</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" sty=
le=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div d=
ir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quote"><div d=
ir=3D"ltr" class=3D"gmail_attr">On Mon, Aug 26, 2019 at 4:08 AM XenoN. w0w =
&lt;<a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D"norefer=
rer">[email protected]</a>&gt; wrote:<br></div><blockquote class=3D"gmail=
_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204=
,204);padding-left:1ex">





<div lang=3D"EN-US">
<div class=3D"m_1723389174890974703gmail-m_-2586403025385974687WordSection1=
">
<p class=3D"MsoNormal"><span style=3D"font-size:11pt">Hello guys, during pe=
netration testing engagements I often come to cisco devices which allows me=
 to grab their config over smart install protocol.
<u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11pt">I would like to make =
a script and add functionality of testing and getting config within the scr=
ipt.<u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11pt">Here is the link for =
reference exploit
<a href=3D"https://github.com/Sab0tag3d/SIET" target=3D"_blank" rel=3D"nore=
ferrer">https://github.com/Sab0tag3d/SIET</a><u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11pt"><u></u>=C2=A0<u></u><=
/span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11pt">What do you guys thin=
k about it?</span></p></div></div></blockquote><div><br></div><div>Thanks f=
or the details.=C2=A0 And wow, the Cisco advisory[1] really tries to shirk =
all responsibility for this mess by writing:</div><div><br></div><div>&quot=
;Cisco does not consider this a vulnerability in Cisco IOS, IOS XE, or the =
Smart Install feature itself but a misuse of the Smart Install protocol, wh=
ich does not require authentication by design.&quot;</div></div><div class=
=3D"gmail_quote"><br></div><div class=3D"gmail_quote">Well maybe they shoul=
dn&#39;t have introduced such a lame &quot;feature&quot; in the first place=
.=C2=A0 And even though it is broken by design, there are lots of ways that=
 Cisco could have at least mitigated the problem.=C2=A0 Apparently they onl=
y recently added a command to turn this crap off.</div><div class=3D"gmail_=
quote"><br></div><div class=3D"gmail_quote">Anyway, yeah, we&#39;d like to =
see an NSE script or other Nmap features related to this.=C2=A0 For example=
, does Nmap version detection (-sV) detect this properly? Are there good wa=
ys to detect the vulnerability (beyond just port 4786 being open) without r=
econfiguring the device or otherwise being too intrusive?=C2=A0 I mean an e=
xploitation feature is nice too, but often Nmap users just want to learn as=
 much as possible about the device and vulnerability without doing anything=
 too intrusive.</div><div class=3D"gmail_quote"><br></div><div class=3D"gma=
il_quote">Cheers,</div><div class=3D"gmail_quote">Fyodor</div><div class=3D=
"gmail_quote"><br></div><div class=3D"gmail_quote"><br></div><div class=3D"=
gmail_quote">[1]=C2=A0<a href=3D"https://tools.cisco.com/security/center/co=
ntent/CiscoSecurityAdvisory/cisco-sa-20170214-smi" target=3D"_blank" rel=3D=
"noreferrer">https://tools.cisco.com/security/center/content/CiscoSecurityA=
dvisory/cisco-sa-20170214-smi</a><br><div><br></div><div>=C2=A0<br></div></=
div></div>
_______________________________________________<br>
Sent through the dev mailing list<br>
<a href=3D"https://nmap.org/mailman/listinfo/dev" rel=3D"noreferrer norefer=
rer" target=3D"_blank">https://nmap.org/mailman/listinfo/dev</a><br>
Archived at <a href=3D"http://seclists.org/nmap-dev/" rel=3D"noreferrer nor=
eferrer" target=3D"_blank">http://seclists.org/nmap-dev/</a></blockquote></=
div>

--00000000000003dee10592e2995a--

--===============5051725684711871159==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Sent through the dev mailing list
https://nmap.org/mailman/listinfo/dev
Archived at http://seclists.org/nmap-dev/
--===============5051725684711871159==--