Re: Cisco Smart Install script

"XenoN. w0w" <[email protected]> Thu, 19 Sep 2019 07:09:44 +0000
Newsgroups gmane.comp.security.nmap.devel
Message-ID <VI1PR0902MB17896F77F296C8D7CDC94F55FC890@VI1PR0902MB1789.eurprd09.prod.outlook.com>
--===============4653352368636186790==
Content-Language: en-US
Content-Type: multipart/alternative;
	boundary="_000_VI1PR0902MB17896F77F296C8D7CDC94F55FC890VI1PR0902MB1789_"

--_000_VI1PR0902MB17896F77F296C8D7CDC94F55FC890VI1PR0902MB1789_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

What do you think should i submit PR for it at all? Even though it is featu=
re, during pentesting engagements you can find out a lots of information an=
d perhaps gain code exec depending on ios version.
________________________________
From: Robin Wood <[email protected]>
Sent: Thursday, September 19, 2019 9:06:39 AM
To: Fyodor <[email protected]>
Cc: XenoN. w0w <[email protected]>; nmap list <[email protected]>
Subject: Re: Cisco Smart Install script

If it's the same issue I think it is, Nessus reports it as an info. The one=
 that they report on can also be used to do unauthenticated code exec but i=
s a feature not "vulnerability" so not a problem.

Robin

On Mon, 9 Sep 2019, 18:34 Gordon Fyodor Lyon, <[email protected]<mailto:fyodo=
[email protected]>> wrote:


On Mon, Aug 26, 2019 at 4:08 AM XenoN. w0w <[email protected]<mailto:e-ne=
[email protected]>> wrote:
Hello guys, during penetration testing engagements I often come to cisco de=
vices which allows me to grab their config over smart install protocol.
I would like to make a script and add functionality of testing and getting =
config within the script.
Here is the link for reference exploit https://github.com/Sab0tag3d/SIET

What do you guys think about it?

Thanks for the details.  And wow, the Cisco advisory[1] really tries to shi=
rk all responsibility for this mess by writing:

"Cisco does not consider this a vulnerability in Cisco IOS, IOS XE, or the =
Smart Install feature itself but a misuse of the Smart Install protocol, wh=
ich does not require authentication by design."

Well maybe they shouldn't have introduced such a lame "feature" in the firs=
t place.  And even though it is broken by design, there are lots of ways th=
at Cisco could have at least mitigated the problem.  Apparently they only r=
ecently added a command to turn this crap off.

Anyway, yeah, we'd like to see an NSE script or other Nmap features related=
 to this.  For example, does Nmap version detection (-sV) detect this prope=
rly? Are there good ways to detect the vulnerability (beyond just port 4786=
 being open) without reconfiguring the device or otherwise being too intrus=
ive?  I mean an exploitation feature is nice too, but often Nmap users just=
 want to learn as much as possible about the device and vulnerability witho=
ut doing anything too intrusive.

Cheers,
Fyodor


[1] https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/c=
isco-sa-20170214-smi


_______________________________________________
Sent through the dev mailing list
https://nmap.org/mailman/listinfo/dev
Archived at http://seclists.org/nmap-dev/

--_000_VI1PR0902MB17896F77F296C8D7CDC94F55FC890VI1PR0902MB1789_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
</head>
<body>
<style id=3D"ms-outlook-ios-style" type=3D"text/css">html {
background-color: transparent !important;
}

body {
background-color: transparent !important;
color: #333;
line-height: 150%;
font-family: "-apple-system", "HelveticaNeue";
margin: 0;
}

.ms-outlook-ios-reference-expand {
display: block;
color: #999;
padding: 20px 0px;
text-decoration: none;
}

.ms-outlook-ios-availability-container {
max-width: 500px;
margin: auto;
padding: 12px 15px 15px 15px;
border: 1px solid #C7E0F4;
border-radius: 4px;
}

.ms-outlook-ios-availability-container > .ms-outlook-ios-availability-delet=
e-button {
width: 25px;
height: 25px;
right: -12px;
top: -12px;
background-image: url("data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAEgAAA=
BICAYAAABV7bNHAAAAAXNSR0IArs4c6QAACeVJREFUeAHtnMuPHcUVxmveY/CMX7IxDoo8RjAIg=
YhNVpFlEKCgbOMkigRCAoHEBhaIBfAHGBagSLBBAhEJsUBJzDZyBCiMElYByyGLmCiMEyFjbAbb=
MwbmPXy/dp+eunfqdlf3fcxg3086U7erq0+d+u6p09Vd506P6yBWVlZ61d1+yR2S8VTGVI5KRlJ=
R4WZSmVY5KTmZygmVx3t6epZVdgQ97e5FpOxRH4cl90rukmyVNIMLuvgDyXuSoyLrdDPK1uVakT=
IseUByTLIkaRfQTR/0Nbwugy3TqYzcLHla8oWk06BP+t5cxuaOtJVR/ZKnJF9J1hvYgC39HRl8U=
Scy5KDkn5KNBmw6WGR/286r80HJy5JlyUYFtmHjYFUiKt3F1OE+dfgHyZ1VO+7wdR+pv9/ojvdZ=
2X5LEyRy7lEn70i2lO1sndtfVP+/FEnvl7GjFEEi59dS/pakssti3HcLK256dsl9u7DsZiVzSyt=
uaRnhrHN9Wk729fa4ob4eNzzQ666RjA73uU0Dpcy9rKz277wOHxRJf6ytbnwU3aPIeUxqXpWwGi=
6Nmblld+7Sojv/3aJbECFVMCDCtm3qdzs397uRoUpm0C1fw+Mi6bUYG6IISj3nbSksbdXUt0vu8=
wvz8prUPWKsimizSV51w9ZBt+OavojWa5pgzG9jPKmQoDTm/FkKS02raXnM/8/Pu0tzS2us69X0=
2aopY9NmuL83mVJMLcBUY8rNLi5n0/GCpuSy6uqxeajP/XjboBst71FMt18UxaRcgkTOPin5WBI=
dkOcWV9ypr+eTqeQPpl/TY7umxzZ941tEjjgqBbi5KJLOyyO/1jRdrJumTL292wfdUH8pxQTuAy=
Lps0bGNNQmcvCYDyXRt3K85j/nZmtiDMH2+tEBt0dSlpRGRkPW6ekF94UETzMQo27aOVzWm1gC/=
Ewk4VFrkEfQy2r9xJorGlScVQDGc7QyS1qoQ7dLwfSGLQMOw9sBgv3nFxccfesLTbroVb94En2X=
wCuy98lQ+6Dl6owl+oQkeL5e0SnFmjP6Ng2DiinjO4fctYOlY7qpKFV+M7/sTp6bc/OKWYbd8ti=
9ik2RgN1DIulv9e3XECByoJ64c3t949BxPTkjCpo3i5x2eU3IBurwpk9F0ox3UyhJ0idSQzxa9P=
sIfcW4WhQ5uLbvOaxPbt093HFyGBBfCH1jgwHbsDESjHnNNKvxIHkP71L+J9lepJSA/O8vZ7OYg=
2E37hgquqwj5/87NZcsSumMmHTLddGBe0qX7JUXXTJD6z3ocZ0oJIdbOXcrC8hMq30bhBwGhi3Y=
BLARW7E5AjvUBg4yZB4k7+GV5aRkd3a2wYeTZ+eydQ4B+fZ1mlYNzEuqiUmfnJnNAjfrpPFdUR5=
+RgrG5EWzKPI96LCOC8lhavE8BaQkuVt1OiAnnRf8wSbupNgIsBnbIwAHcJHAJ+ghq8wreXwwsN=
bo1K3c+ixTYpu/HvJtL9CTcZEQpOm1RxfcV3CR48HTnq1YIbMILMLv/j7lfvT8p+7ZY2ddVBQoU=
IgOdKET3UXARmwF2M4YInBfykk2xX6li3xvCurgqdzA40PM1HpxYip5LHjhr+fco0dPN0US5KAD=
XTxqoLsI2IitBn8MVhco4SKZZkYKm3q54H2OvbLgwZNnqxg8dGB1n/CNf5yvTJKRgw6Dr9vqQiU=
EYTNgDIwlAgknvXIlSDpUdAEvuww8lcc+eB65f5d75Kfb7FJXhaQQOehEdwzgBpsN/lisLlDeBT=
eQs1+y+jUHWlJldy4+88oiFnxvrx/eU5mkRuSg87JPxFni2+yPJedqONkPQSQS5IJ3yPaalJddv=
M8pg6oktYocbE3eQaVuz1gYUwTugCCyLHLBC3YDbwJjp5ddQ1mWpFaSQ//YjO0Gf0xWFyjHowhi=
98HAa9KqiCWp1eSYvb7t/pjsfKAcJ3KNBU7UVLE1Y2h268VIQp/dkawkrgBu5VbHMQG5bMzhunr=
4tvtjqm/nHY9B0KhXEfzoP+jxgr1ZNCLJosLvvVt5q8jBZt92f0w54xmFoJGcBskpJeFkTWxVml=
VU/BAiyScGta0kB32+7f6YONcAI7hDMUGrM0ydNFBVodpIethbJ5ka6loxrUwfpW+77eL65wOfE=
4IC9d0qYwB/mLGDRmUF5hupqqm3u1X91KIRdc0+u9V0pgPfa/wx1bfzjmfiCErfqXChvw/lKSr9=
0cjx71ZMK3+6ca6VJPm2+/Eox/gZgjSptrlgt3I2fRRjO3iov/paiI5C5FhA5jyxyYizshXxCNs=
NZI5EYBoPmixqSAqKIXKJbs3XlHnkYLIFbggztMqTfNv9MVk/gXKSkZOknQvycwyRS3RrXlMWkW=
ON20WSb7s/Jus3UJ6MIshfoidZFoy0JGLJMbWtJoktfGw3+GOyukCZEHQicKKmiiW6vT0kBYUsi=
zIoS47pbiVJ2GzpM4zFf+yw/gLlCTzouIT0/lywbWIgBSUWVckx/a0iybfZH4v1Eyjh5Lg2HpMf=
hkwEGtRU+Vu65Od4WSc17eoPntMLdrsTcc7uVgw8Fo1IQncMsBWbDf5YrC5QfgA3Fn3fCzSoqSI=
nkLQ3QPISL81j8ObHq85ZhRzrI0SSr9vahUpstYQrxhCZ35hwYgT9SYpXFwmhXlRHTqCB5CV7y2=
h1ofLpQzuSF/zP3L2z6WcrIwldbBqguwjYiK0GfwxWFyjh4ij1mafrBfUxHf+cyjz8S9u5tjd23=
ciAG1Oy0kbGpJK6vpy5TBD5jLdpmzwCf9H0up925kF8fpM/RSBh0kBqCclLGxXY5qe/+LYX2Jxx=
4ROES7FxnwuySe0uIK9LMrtiplqu0jacxCayzrARYHNkJiwcJNOL6zKC5FJkM7xEZRHIAbR1EWl=
vZHZdNqPoys6cxxZsspQ8bMXmSLyUcpE0z2IQR2KbBKpTksLod1UmUIk5MquOSAqBu/rfCruVZH=
atpyfRt59dxiCwMXJq0fxIygGfE9R4EDXyIpbM3STOhB7vNp8eJ4VIOqgPE5I1BPrt7HN9pusVn=
QZsgxZJ3UTyPA8RQYT9DyV3GmlFJYH7qvkpAmSIpH0qiEfdH7NASAgi6R7Vd38OFSLH6kQSP8V8=
W5ItLO1cUXnF/6DOCBBJ3Z9kGhmNytST3tL56HV7SBe7C7xAz37Uqyx49sptY49NPfatflA/6rW=
BpjHpHR1HB267dp3Li+q/9M/CS8cULcXfV0cHJB+t84DLdI+t/NQJ2zsDedJV8a8pmmZTRHX/uU=
kRiyKp++9xikjivIjq/oOlSKKumH/RFfU6I4aURm3kVaSu8mOZeyWHJGSwNwM22iYk70ra/k/e2=
k6Qz4TIIrHoJxKy+0lgR8YkZNqOpKJi4/ybwO8BdPFbSx34AtIAAAAASUVORK5CYII=3D");
background-size: 25px 25px;
background-position: center;
}

#ms-outlook-ios-main-container {
margin: 0 0 0 0;
margin-top: 120;
padding: 8;
}

#ms-outlook-ios-content-container {
padding: 0;
padding-top: 12;
padding-bottom: 20;
}

.ms-outlook-ios-mention {
color: #333;
background-color: #f1f1f1;
border-radius: 4px;
padding: 0 2px 0 2px;
pointer-events: none;
text-decoration: none;
}

.ms-outlook-ios-mention-external {
color: #ba8f0d;
background-color: #fdf7e7;
}

.ms-outlook-ios-mention-external-clear-design {
color: #ba8f0d;
background-color: #f1f1f1;
}</style><style id=3D"ms-outlook-ios-dark-mode-style" type=3D"text/css">.ms=
-outlook-ios-dark-mode {
color: #E1E1E1 !important;
}

.ms-outlook-ios-dark-mode .ms-outlook-ios-reference-expand {
color: #777777 !important;
}

.ms-outlook-ios-dark-mode a:not([class]) {
color: #0086F0;
}

.ms-outlook-ios-dark-mode font[color=3D"#000000"] {
color: #E1E1E1 !important;
}

.ms-outlook-ios-dark-mode .ms-outlook-ios-availability-container {
border-color: #303030 !important;
}

.ms-outlook-ios-dark-mode .ms-outlook-ios-availability-container > table > =
tbody > tr > td:nth-child(1) > table:nth-child(1) > tbody > tr:nth-child(1)=
 > td:nth-child(2) {
color: #0086F0;
}

.ms-outlook-ios-dark-mode .ms-outlook-ios-availability-container .ms-outloo=
k-ios-availability-timeslot-container {
background-color: #0086F0 !important;
color: #000000 !important;
}

.ms-outlook-ios-dark-mode .ms-outlook-ios-availability-container .ms-outloo=
k-ios-availability-border {
border-top: 1px solid #0086F0 !important;
}

.ms-outlook-ios-dark-mode .ms-outlook-ios-availability-container > .ms-outl=
ook-ios-availability-delete-button {
background-image: url("data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAEgAAA=
BICAYAAABV7bNHAAAAAXNSR0IArs4c6QAAC/FJREFUeAHtnF2MVVcVxw9z+RhgZhgY6GgTzIwvm=
IBRWoMJNpRIg1Yf6kdH+6BNNDYQQ4yG+NAHE+KLD4Y0sQQx+lRJbDTURBNMm1JoQ1pFUZuCCQ9W=
LInlm2EGGBiYGf+/M3fdu++Zfc7Z59x7h6FhJWf22V9rr/0/a6299r7nzLxoFmnXrl0de/bsWT9=
v3rxPTE1NrdHQa3Q/qLRHV7fKuhFHZaNKuEZU9h+lp1R2Svdv79ix4x/iM6myWaF57R5l9erVD9=
68efOrmtwWjfWort4mxxxW/9cF2KHOzs4DZ86c+V+T/DK7twWggYGBzhs3bgDK07oekwQdmVKUr=
5wUUK/qemHJkiUHTp8+fbM8K3/PlgK0atWqLgm7XaDs1PUh/5DtKdW4Z3Xt1rj7Lly4cK1Vo1Ra=
wWjz5s3zr1279n0JeEACPiGeXa3gW5BHl8beKhm2SZvubNiw4a/SqKZ9VdMaJK15RBPZK+E+XnB=
CbW0uoN7RAN+VNh1tZqDSGrR27dqFGvg5AfNzpf3NCNGmvsj0raVLl/YNDg4eElATZcYppUH9/f=
0fnZiY+K0GfLjMoHehz/FKpfK1c+fOvVt07MIACZzPCpyXNNCyooPd5fZXBdJXBNJrReQoBJD8z=
ZBMar8GwLxK04IFC6JFixZFpPPnz48keNTR0UGAGPPUGNHk5GSkBxHduXMnun37dnTr1q04LT3o=
dMdxjfENmdvvQvkEA7Ry5cpnxHSfrlIxDYBodYkWL14cgxEqoNsO0MbGxiLFWDFgbl2Be1a27Rc=
vXvxlSJ8ggKqa86IYFgYHUHp6emJNCREotA2aNTIyEoMV2sdpR4D5VIgm5QJU9Tl/EvNCZoXG9P=
b2xmbkCBbfYkKYjJkNk0U7KIcwNUwO8zNzhJ+ZYNyo+gfzGx4eLqNR4zLtx/N8UiZA1dXq75Il2=
CEzKYDRPsmdRwwA5qF9WXwZGA2NMjKAA08un5nCF6AAuwDhuB/KWt1SASLOUcc3NVjwUs5T7uvr=
a/AxADE6OhpfRUFJmyhgdXd3x5erVWjhpUuXimrTcSnCxpMnT477xssKFJ9Thy/5OvnKFJDF4Lg=
CX79+PRaYp9tqwjxx1pjiwoXT1s/YyMHqh+kF0oPi06sLNzKDvBrE9kFP+w219tYnuWBSXV317R=
cCapUoImSSZaE8fkqrbBwuWEftDWOTs3xOOiVwN/m2JTNWJTaeYrZXVylwxsfHo/Pnz88aOEwcb=
WFMxjbigfHgAom57q3OvaHLDBNjV64W32xolZJBnZctq/tvVB4fgC+YbcK/Mb6tfIyP6RUwt36B=
fFU83nJlb9ASmRZHBv9VgxVuI989Dlnta1UId/ny5Vr+bt6sWLEiDkpNBplOkOOWmV1SnwG1r50=
nNZiYGmxXg1xweEqsVkao9pUrVyx711Nkcc0NWZE5j6QcfVUMak1rAA3omFQNdtZqMm6wbVYPCB=
XGrFDxuULIgkzIBiFrqD8CA7CwudQAkolwhpx7TIppuUEgq5UJYkznQopMyGaEzMieR2AAFtauB=
pAqnrbCrNR9EsQ5BeKNLLZtqUM2ZDRyZbcyX+piEQPETzMqfMzX2C1j40nMAal9vFl06333Yw9/=
O7q87c3o+iM/jFphhPCAFzzhnUdsaJEVQnbmkEdgASa0iwFSpPuk3Wd1ZlduxPYhxLTGPvWdaHL=
pA9HYhm3Rta0/aQokpgkPeMU8xTuPkBFZjdw5WJkn7RAmsZnFAAmxLZ5GDUXYr60ExDnuoA0NE5=
lFJ39fK7m1bqg0SAYOPIxc3lbmS5HVYjPmEOiLYkw6dunnYDHd5GPslrmqya7c1NZt47tfcvSn0=
aIT9QO8MiB5wRFPeIcQsiKzkTsXK/Okj4JN5cSJEw+p8nueBg1FBF+KEeIynkjosQI9Fv77UDTZ=
/eFo4oG1cX9S8pQ3RKoNI05n0sDpeuXZ3L4uO2Q3YNCiAAvoPHbs2B8r2i48LkZPuMyS9zg3jhc=
gnkbRoLAsSK0CB7nxRcwBoLjQKDM76n2kdn+pCNWnVPkZXwMrA3mLfeyYwepC06IgtRIck9H1o1=
iAG21bm0R6CoB2qPBjiYqGLJtSO3Mhrghg3NDfMqEgtQMcZODXE3vQaFTAOdVFTOxZ9eVXyFRCN=
W0F45wl1P/4GOaBRB+W8obVSg65qM/xjc2Ww/wQroINdhbJxMbZwdWDm5TWIG/UDDjGA5CYMGRA=
kKI51FkZ9ayArQAHXq7s7pyoS6EeAJr2viktKLaNKfd5jo02IeQDadyJceDRSnDg58ruzom6FOr=
ukKrlAoTXN0I1W0UG0kInTjLerQYHvq7s7pxszGQKNnEknayY7Xwd/vrIrXsMdZ5l7jqEZH2jks=
KhKPIpbGYU+1Yra4S5Nbt3M16WulrjzsnqkynYoEG5AJWw3eRYM/I+cDAr19xw1q0EyfU77pxmC=
FcvGMVJj9Tz/jtiBlvmSd3VwN8juzQNHFvZOBC2lczSVqxkNgekY04BNEKg+Hk1zAwUiUAtUOQQ=
qmygiEBZ4OCLuJrZuzFGGvGTtQWK7AgCAsU/A9B6MczcaoC8MWbwvAArTcA8cKxfu0By3zJhDgE=
P+g846VMmWFoK2kZok+vsrDwvDQXH+AASZoVfMmrGJyGzew7kzsn4J1OwIQ56O1mRzGNW5tQYyN=
WmZFtfvig4xqOVICGzPVjmEnKWDjYdfPsggXi9P5PcA6ciAJUFx4RpFUiuzO5cbBxPOgw2lSNHj=
kzJD21UAz4uSSXiBnb1ED6JTWsI3dAB+8319R9MykTIaT4pqmjxeI83dLIJzVm+fHlNg65evRqy=
ir188ODB38SRtBgcyh5Cy678kC3vxBN2gJbbb+2Xa03KgGOdvZrk8LZ2vhRZLQZiDoH+J8Yk3qb=
rp9kz6vgDMUeOVMJ2WSohln1WgvyIdCqaWLUm6vzn/mjp4R9nD5A68nSFaRKaM9n7kWjx334VLX=
gfD5FO7Nr56dn8D2+hBfifSc3zGf1kNFoDRC8ivKzJbk0farpGb2PVfhvj8Kzo8Wse/1bXY1rmG=
gBGb83lDiEwX9ELDJ+jYW2zqsIXcnuqAU/AiIHth0Qrm0spshk4yOXKniWni0UNIDnqA6o4m9WR=
OuzXjUCTb3bl9Z+tekwL2YyQOdD3nAUL61cD6LQ+RhNAu60iK+VJWFyUtPGsfrNVp3nEfsdODZG=
1gPbsBguTtQYQBfJB+8T8klWmpawEvF5ihMPG1ucKIYvtHZEJWW0FzpKRuYOB26Z+2KxSrUrjUi=
9eNI4dlNswec9umMtWNeyd+Mg1v2SfdufRnOTbZSwigYEh4v1Ir8y87srZoEFUrFu37mca6B23U=
do9q5gbMArc+LU8U+20fu0oZ0xeCUQGI2RzX3+xcl/KnJl7sq62zLsVGuj+a8BVQBpMzECSqb2n=
5bFP+U9bWVaKWbnmRtTKa7g8VWKP/GAyi3t6Hfx5KQqfY5EyrTGrgN/ea4ylPXsU9/yiVuDceAG=
iflCfMUo9v6Db+EUip4/3FiBYRvFJ+AIIRwlQ5APOXrx8fYXw42yHCNl1xqxWvHZXwOfAnk8Rvi=
6AvEeMXhMzoe5/zJKz9wIogcQnmHzHMP1BhKGXk3I4hfr7Im1MDm3jQvNYgnn6ZopoCCbDqkh/e=
KUd1NGfGCckCEyI3PznUMZQTptPMV9UfsaqZ23SUlYV96gzrV3RckCdjQ/qUn2QK7Cc9r800fdV=
9kVdmWbp9uOeJ8xya08YrTAflWybl0fLOEHgPIcL3iWI7yT4JPPXIX0LTbaqSfvFuJC5JQUxs7H=
gktUIkzLgMDXAYGVEUwDCzDHJq2C+fR/1miBVn/SS8sus7B5JS30WXtin8I2nnjjvNR6/R4BBTP=
6xAJ9evlZU5sIAMYAGeleatFEm8byynMvPVeJDueeRFZnLCFnIB/kGYFui8g/sPzcppUEuUIpAj=
+oDYExup55W/QzEbTSL91UZdiITsjU7dNMa5AogbfrA/YOllgJkYA3oeyvFK/f/RZcBkpVW/8nb=
k4pttqjdJl3BX9qm8OVXgzdkSq/q19J785+8pUwsGhoaqhw+fPiTmtw9828C/w/K8jZzsc+GngA=
AAABJRU5ErkJggg=3D=3D") !important;
}

.ms-outlook-ios-dark-mode .ms-outlook-ios-availability-container > table > =
tbody > tr > td:nth-child(1) > table:nth-child(4) > tbody > tr:nth-child(2)=
 > td > a {
color: #0086F0 !important;
}

.ms-outlook-ios-dark-mode .ms-outlook-ios-mention {
color: #ACACAC !important;
background-color: #292929 !important;
}</style>
<meta name=3D"viewport" content=3D"width=3Ddevice-width, user-scalable=3Dno=
, initial-scale=3D1.0, minimum-scale=3D1.0, maximum-scale=3D1.0">
<div style=3D"direction: ltr;">
<div>What do you think should i submit PR for it at all? Even though it is =
feature, during pentesting engagements you can find out a lots of informati=
on and perhaps gain code exec depending on ios version.&nbsp;</div>
</div>
<hr style=3D"display:inline-block;width:98%" tabindex=3D"-1">
<div id=3D"divRplyFwdMsg" dir=3D"ltr"><font face=3D"Calibri, sans-serif" st=
yle=3D"font-size:11pt" color=3D"#000000"><b>From:</b> Robin Wood &lt;robin@=
digininja.org&gt;<br>
<b>Sent:</b> Thursday, September 19, 2019 9:06:39 AM<br>
<b>To:</b> Fyodor &lt;[email protected]&gt;<br>
<b>Cc:</b> XenoN. w0w &lt;[email protected]&gt;; nmap list &lt;[email protected]=
rg&gt;<br>
<b>Subject:</b> Re: Cisco Smart Install script</font>
<div>&nbsp;</div>
</div>
<div>
<div dir=3D"auto">If it's the same issue I think it is, Nessus reports it a=
s an info. The one that they report on can also be used to do unauthenticat=
ed code exec but is a feature not &quot;vulnerability&quot; so not a proble=
m.
<div dir=3D"auto"><br>
</div>
<div dir=3D"auto">Robin</div>
</div>
<br>
<div class=3D"gmail_quote">
<div dir=3D"ltr" class=3D"gmail_attr">On Mon, 9 Sep 2019, 18:34 Gordon Fyod=
or Lyon, &lt;<a href=3D"mailto:[email protected]">[email protected]</a>&gt; wro=
te:<br>
</div>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">
<div dir=3D"ltr">
<div dir=3D"ltr"><br>
</div>
<br>
<div class=3D"gmail_quote">
<div dir=3D"ltr" class=3D"gmail_attr">On Mon, Aug 26, 2019 at 4:08 AM XenoN=
. w0w &lt;<a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D"n=
oreferrer">[email protected]</a>&gt; wrote:<br>
</div>
<blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-=
left:1px solid rgb(204,204,204);padding-left:1ex">
<div lang=3D"EN-US">
<div class=3D"m_1723389174890974703gmail-m_-2586403025385974687WordSection1=
">
<p class=3D"MsoNormal"><span style=3D"font-size:11pt">Hello guys, during pe=
netration testing engagements I often come to cisco devices which allows me=
 to grab their config over smart install protocol.
<u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11pt">I would like to make =
a script and add functionality of testing and getting config within the scr=
ipt.<u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11pt">Here is the link for =
reference exploit
<a href=3D"https://github.com/Sab0tag3d/SIET" target=3D"_blank" rel=3D"nore=
ferrer">https://github.com/Sab0tag3d/SIET</a><u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11pt"><u></u>&nbsp;<u></u><=
/span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11pt">What do you guys thin=
k about it?</span></p>
</div>
</div>
</blockquote>
<div><br>
</div>
<div>Thanks for the details.&nbsp; And wow, the Cisco advisory[1] really tr=
ies to shirk all responsibility for this mess by writing:</div>
<div><br>
</div>
<div>&quot;Cisco does not consider this a vulnerability in Cisco IOS, IOS X=
E, or the Smart Install feature itself but a misuse of the Smart Install pr=
otocol, which does not require authentication by design.&quot;</div>
</div>
<div class=3D"gmail_quote"><br>
</div>
<div class=3D"gmail_quote">Well maybe they shouldn't have introduced such a=
 lame &quot;feature&quot; in the first place.&nbsp; And even though it is b=
roken by design, there are lots of ways that Cisco could have at least miti=
gated the problem.&nbsp; Apparently they only recently
 added a command to turn this crap off.</div>
<div class=3D"gmail_quote"><br>
</div>
<div class=3D"gmail_quote">Anyway, yeah, we'd like to see an NSE script or =
other Nmap features related to this.&nbsp; For example, does Nmap version d=
etection (-sV) detect this properly? Are there good ways to detect the vuln=
erability (beyond just port 4786 being
 open) without reconfiguring the device or otherwise being too intrusive?&n=
bsp; I mean an exploitation feature is nice too, but often Nmap users just =
want to learn as much as possible about the device and vulnerability withou=
t doing anything too intrusive.</div>
<div class=3D"gmail_quote"><br>
</div>
<div class=3D"gmail_quote">Cheers,</div>
<div class=3D"gmail_quote">Fyodor</div>
<div class=3D"gmail_quote"><br>
</div>
<div class=3D"gmail_quote"><br>
</div>
<div class=3D"gmail_quote">[1]&nbsp;<a href=3D"https://tools.cisco.com/secu=
rity/center/content/CiscoSecurityAdvisory/cisco-sa-20170214-smi" target=3D"=
_blank" rel=3D"noreferrer">https://tools.cisco.com/security/center/content/=
CiscoSecurityAdvisory/cisco-sa-20170214-smi</a><br>
<div><br>
</div>
<div>&nbsp;<br>
</div>
</div>
</div>
_______________________________________________<br>
Sent through the dev mailing list<br>
<a href=3D"https://nmap.org/mailman/listinfo/dev" rel=3D"noreferrer norefer=
rer" target=3D"_blank">https://nmap.org/mailman/listinfo/dev</a><br>
Archived at <a href=3D"http://seclists.org/nmap-dev/" rel=3D"noreferrer nor=
eferrer" target=3D"_blank">
http://seclists.org/nmap-dev/</a></blockquote>
</div>
</div>
</body>
</html>

--_000_VI1PR0902MB17896F77F296C8D7CDC94F55FC890VI1PR0902MB1789_--

--===============4653352368636186790==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Sent through the dev mailing list
https://nmap.org/mailman/listinfo/dev
Archived at http://seclists.org/nmap-dev/
--===============4653352368636186790==--