Re: Cisco Smart Install script
"XenoN. w0w" <[email protected]> Thu, 19 Sep 2019 07:09:44 +0000
| Newsgroups | gmane.comp.security.nmap.devel |
|---|---|
| Message-ID | <VI1PR0902MB17896F77F296C8D7CDC94F55FC890@VI1PR0902MB1789.eurprd09.prod.outlook.com> |
--===============4653352368636186790== Content-Language: en-US Content-Type: multipart/alternative; boundary="_000_VI1PR0902MB17896F77F296C8D7CDC94F55FC890VI1PR0902MB1789_" --_000_VI1PR0902MB17896F77F296C8D7CDC94F55FC890VI1PR0902MB1789_ Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable What do you think should i submit PR for it at all? Even though it is featu= re, during pentesting engagements you can find out a lots of information an= d perhaps gain code exec depending on ios version. ________________________________ From: Robin Wood <[email protected]> Sent: Thursday, September 19, 2019 9:06:39 AM To: Fyodor <[email protected]> Cc: XenoN. w0w <[email protected]>; nmap list <[email protected]> Subject: Re: Cisco Smart Install script If it's the same issue I think it is, Nessus reports it as an info. The one= that they report on can also be used to do unauthenticated code exec but i= s a feature not "vulnerability" so not a problem. Robin On Mon, 9 Sep 2019, 18:34 Gordon Fyodor Lyon, <[email protected]<mailto:fyodo= [email protected]>> wrote: On Mon, Aug 26, 2019 at 4:08 AM XenoN. w0w <[email protected]<mailto:e-ne= [email protected]>> wrote: Hello guys, during penetration testing engagements I often come to cisco de= vices which allows me to grab their config over smart install protocol. I would like to make a script and add functionality of testing and getting = config within the script. Here is the link for reference exploit https://github.com/Sab0tag3d/SIET What do you guys think about it? Thanks for the details. And wow, the Cisco advisory[1] really tries to shi= rk all responsibility for this mess by writing: "Cisco does not consider this a vulnerability in Cisco IOS, IOS XE, or the = Smart Install feature itself but a misuse of the Smart Install protocol, wh= ich does not require authentication by design." Well maybe they shouldn't have introduced such a lame "feature" in the firs= t place. And even though it is broken by design, there are lots of ways th= at Cisco could have at least mitigated the problem. Apparently they only r= ecently added a command to turn this crap off. Anyway, yeah, we'd like to see an NSE script or other Nmap features related= to this. For example, does Nmap version detection (-sV) detect this prope= rly? Are there good ways to detect the vulnerability (beyond just port 4786= being open) without reconfiguring the device or otherwise being too intrus= ive? I mean an exploitation feature is nice too, but often Nmap users just= want to learn as much as possible about the device and vulnerability witho= ut doing anything too intrusive. Cheers, Fyodor [1] https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/c= isco-sa-20170214-smi _______________________________________________ Sent through the dev mailing list https://nmap.org/mailman/listinfo/dev Archived at http://seclists.org/nmap-dev/ --_000_VI1PR0902MB17896F77F296C8D7CDC94F55FC890VI1PR0902MB1789_ Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable <html> <head> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"= > </head> <body> <style id=3D"ms-outlook-ios-style" type=3D"text/css">html { background-color: transparent !important; } body { background-color: transparent !important; color: #333; line-height: 150%; font-family: "-apple-system", "HelveticaNeue"; margin: 0; } .ms-outlook-ios-reference-expand { display: block; color: #999; padding: 20px 0px; text-decoration: none; } .ms-outlook-ios-availability-container { max-width: 500px; margin: auto; padding: 12px 15px 15px 15px; border: 1px solid #C7E0F4; border-radius: 4px; } .ms-outlook-ios-availability-container > .ms-outlook-ios-availability-delet= e-button { width: 25px; height: 25px; right: -12px; top: -12px; background-image: url("data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAEgAAA= BICAYAAABV7bNHAAAAAXNSR0IArs4c6QAACeVJREFUeAHtnMuPHcUVxmveY/CMX7IxDoo8RjAIg= YhNVpFlEKCgbOMkigRCAoHEBhaIBfAHGBagSLBBAhEJsUBJzDZyBCiMElYByyGLmCiMEyFjbAbb= MwbmPXy/dp+eunfqdlf3fcxg3086U7erq0+d+u6p09Vd506P6yBWVlZ61d1+yR2S8VTGVI5KRlJ= R4WZSmVY5KTmZygmVx3t6epZVdgQ97e5FpOxRH4cl90rukmyVNIMLuvgDyXuSoyLrdDPK1uVakT= IseUByTLIkaRfQTR/0Nbwugy3TqYzcLHla8oWk06BP+t5cxuaOtJVR/ZKnJF9J1hvYgC39HRl8U= Scy5KDkn5KNBmw6WGR/286r80HJy5JlyUYFtmHjYFUiKt3F1OE+dfgHyZ1VO+7wdR+pv9/ojvdZ= 2X5LEyRy7lEn70i2lO1sndtfVP+/FEnvl7GjFEEi59dS/pakssti3HcLK256dsl9u7DsZiVzSyt= uaRnhrHN9Wk729fa4ob4eNzzQ666RjA73uU0Dpcy9rKz277wOHxRJf6ytbnwU3aPIeUxqXpWwGi= 6Nmblld+7Sojv/3aJbECFVMCDCtm3qdzs397uRoUpm0C1fw+Mi6bUYG6IISj3nbSksbdXUt0vu8= wvz8prUPWKsimizSV51w9ZBt+OavojWa5pgzG9jPKmQoDTm/FkKS02raXnM/8/Pu0tzS2us69X0= 2aopY9NmuL83mVJMLcBUY8rNLi5n0/GCpuSy6uqxeajP/XjboBst71FMt18UxaRcgkTOPin5WBI= dkOcWV9ypr+eTqeQPpl/TY7umxzZ941tEjjgqBbi5KJLOyyO/1jRdrJumTL292wfdUH8pxQTuAy= Lps0bGNNQmcvCYDyXRt3K85j/nZmtiDMH2+tEBt0dSlpRGRkPW6ekF94UETzMQo27aOVzWm1gC/= Ewk4VFrkEfQy2r9xJorGlScVQDGc7QyS1qoQ7dLwfSGLQMOw9sBgv3nFxccfesLTbroVb94En2X= wCuy98lQ+6Dl6owl+oQkeL5e0SnFmjP6Ng2DiinjO4fctYOlY7qpKFV+M7/sTp6bc/OKWYbd8ti= 9ik2RgN1DIulv9e3XECByoJ64c3t949BxPTkjCpo3i5x2eU3IBurwpk9F0ox3UyhJ0idSQzxa9P= sIfcW4WhQ5uLbvOaxPbt093HFyGBBfCH1jgwHbsDESjHnNNKvxIHkP71L+J9lepJSA/O8vZ7OYg= 2E37hgquqwj5/87NZcsSumMmHTLddGBe0qX7JUXXTJD6z3ocZ0oJIdbOXcrC8hMq30bhBwGhi3Y= BLARW7E5AjvUBg4yZB4k7+GV5aRkd3a2wYeTZ+eydQ4B+fZ1mlYNzEuqiUmfnJnNAjfrpPFdUR5= +RgrG5EWzKPI96LCOC8lhavE8BaQkuVt1OiAnnRf8wSbupNgIsBnbIwAHcJHAJ+ghq8wreXwwsN= bo1K3c+ixTYpu/HvJtL9CTcZEQpOm1RxfcV3CR48HTnq1YIbMILMLv/j7lfvT8p+7ZY2ddVBQoU= IgOdKET3UXARmwF2M4YInBfykk2xX6li3xvCurgqdzA40PM1HpxYip5LHjhr+fco0dPN0US5KAD= XTxqoLsI2IitBn8MVhco4SKZZkYKm3q54H2OvbLgwZNnqxg8dGB1n/CNf5yvTJKRgw6Dr9vqQiU= EYTNgDIwlAgknvXIlSDpUdAEvuww8lcc+eB65f5d75Kfb7FJXhaQQOehEdwzgBpsN/lisLlDeBT= eQs1+y+jUHWlJldy4+88oiFnxvrx/eU5mkRuSg87JPxFni2+yPJedqONkPQSQS5IJ3yPaalJddv= M8pg6oktYocbE3eQaVuz1gYUwTugCCyLHLBC3YDbwJjp5ddQ1mWpFaSQ//YjO0Gf0xWFyjHowhi= 98HAa9KqiCWp1eSYvb7t/pjsfKAcJ3KNBU7UVLE1Y2h268VIQp/dkawkrgBu5VbHMQG5bMzhunr= 4tvtjqm/nHY9B0KhXEfzoP+jxgr1ZNCLJosLvvVt5q8jBZt92f0w54xmFoJGcBskpJeFkTWxVml= VU/BAiyScGta0kB32+7f6YONcAI7hDMUGrM0ydNFBVodpIethbJ5ka6loxrUwfpW+77eL65wOfE= 4IC9d0qYwB/mLGDRmUF5hupqqm3u1X91KIRdc0+u9V0pgPfa/wx1bfzjmfiCErfqXChvw/lKSr9= 0cjx71ZMK3+6ca6VJPm2+/Eox/gZgjSptrlgt3I2fRRjO3iov/paiI5C5FhA5jyxyYizshXxCNs= NZI5EYBoPmixqSAqKIXKJbs3XlHnkYLIFbggztMqTfNv9MVk/gXKSkZOknQvycwyRS3RrXlMWkW= ON20WSb7s/Jus3UJ6MIshfoidZFoy0JGLJMbWtJoktfGw3+GOyukCZEHQicKKmiiW6vT0kBYUsi= zIoS47pbiVJ2GzpM4zFf+yw/gLlCTzouIT0/lywbWIgBSUWVckx/a0iybfZH4v1Eyjh5Lg2HpMf= hkwEGtRU+Vu65Od4WSc17eoPntMLdrsTcc7uVgw8Fo1IQncMsBWbDf5YrC5QfgA3Fn3fCzSoqSI= nkLQ3QPISL81j8ObHq85ZhRzrI0SSr9vahUpstYQrxhCZ35hwYgT9SYpXFwmhXlRHTqCB5CV7y2= h1ofLpQzuSF/zP3L2z6WcrIwldbBqguwjYiK0GfwxWFyjh4ij1mafrBfUxHf+cyjz8S9u5tjd23= ciAG1Oy0kbGpJK6vpy5TBD5jLdpmzwCf9H0up925kF8fpM/RSBh0kBqCclLGxXY5qe/+LYX2Jxx= 4ROES7FxnwuySe0uIK9LMrtiplqu0jacxCayzrARYHNkJiwcJNOL6zKC5FJkM7xEZRHIAbR1EWl= vZHZdNqPoys6cxxZsspQ8bMXmSLyUcpE0z2IQR2KbBKpTksLod1UmUIk5MquOSAqBu/rfCruVZH= atpyfRt59dxiCwMXJq0fxIygGfE9R4EDXyIpbM3STOhB7vNp8eJ4VIOqgPE5I1BPrt7HN9pusVn= QZsgxZJ3UTyPA8RQYT9DyV3GmlFJYH7qvkpAmSIpH0qiEfdH7NASAgi6R7Vd38OFSLH6kQSP8V8= W5ItLO1cUXnF/6DOCBBJ3Z9kGhmNytST3tL56HV7SBe7C7xAz37Uqyx49sptY49NPfatflA/6rW= BpjHpHR1HB267dp3Li+q/9M/CS8cULcXfV0cHJB+t84DLdI+t/NQJ2zsDedJV8a8pmmZTRHX/uU= kRiyKp++9xikjivIjq/oOlSKKumH/RFfU6I4aURm3kVaSu8mOZeyWHJGSwNwM22iYk70ra/k/e2= k6Qz4TIIrHoJxKy+0lgR8YkZNqOpKJi4/ybwO8BdPFbSx34AtIAAAAASUVORK5CYII=3D"); background-size: 25px 25px; background-position: center; } #ms-outlook-ios-main-container { margin: 0 0 0 0; margin-top: 120; padding: 8; } #ms-outlook-ios-content-container { padding: 0; padding-top: 12; padding-bottom: 20; } .ms-outlook-ios-mention { color: #333; background-color: #f1f1f1; border-radius: 4px; padding: 0 2px 0 2px; pointer-events: none; text-decoration: none; } .ms-outlook-ios-mention-external { color: #ba8f0d; background-color: #fdf7e7; } .ms-outlook-ios-mention-external-clear-design { color: #ba8f0d; background-color: #f1f1f1; }</style><style id=3D"ms-outlook-ios-dark-mode-style" type=3D"text/css">.ms= -outlook-ios-dark-mode { color: #E1E1E1 !important; } .ms-outlook-ios-dark-mode .ms-outlook-ios-reference-expand { color: #777777 !important; } .ms-outlook-ios-dark-mode a:not([class]) { color: #0086F0; } .ms-outlook-ios-dark-mode font[color=3D"#000000"] { color: #E1E1E1 !important; } .ms-outlook-ios-dark-mode .ms-outlook-ios-availability-container { border-color: #303030 !important; } .ms-outlook-ios-dark-mode .ms-outlook-ios-availability-container > table > = tbody > tr > td:nth-child(1) > table:nth-child(1) > tbody > tr:nth-child(1)= > td:nth-child(2) { color: #0086F0; } .ms-outlook-ios-dark-mode .ms-outlook-ios-availability-container .ms-outloo= k-ios-availability-timeslot-container { background-color: #0086F0 !important; color: #000000 !important; } .ms-outlook-ios-dark-mode .ms-outlook-ios-availability-container .ms-outloo= k-ios-availability-border { border-top: 1px solid #0086F0 !important; } .ms-outlook-ios-dark-mode .ms-outlook-ios-availability-container > .ms-outl= ook-ios-availability-delete-button { background-image: url("data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAEgAAA= BICAYAAABV7bNHAAAAAXNSR0IArs4c6QAAC/FJREFUeAHtnF2MVVcVxw9z+RhgZhgY6GgTzIwvm= IBRWoMJNpRIg1Yf6kdH+6BNNDYQQ4yG+NAHE+KLD4Y0sQQx+lRJbDTURBNMm1JoQ1pFUZuCCQ9W= LInlm2EGGBiYGf+/M3fdu++Zfc7Z59x7h6FhJWf22V9rr/0/a6299r7nzLxoFmnXrl0de/bsWT9= v3rxPTE1NrdHQa3Q/qLRHV7fKuhFHZaNKuEZU9h+lp1R2Svdv79ix4x/iM6myWaF57R5l9erVD9= 68efOrmtwWjfWort4mxxxW/9cF2KHOzs4DZ86c+V+T/DK7twWggYGBzhs3bgDK07oekwQdmVKUr= 5wUUK/qemHJkiUHTp8+fbM8K3/PlgK0atWqLgm7XaDs1PUh/5DtKdW4Z3Xt1rj7Lly4cK1Vo1Ra= wWjz5s3zr1279n0JeEACPiGeXa3gW5BHl8beKhm2SZvubNiw4a/SqKZ9VdMaJK15RBPZK+E+XnB= CbW0uoN7RAN+VNh1tZqDSGrR27dqFGvg5AfNzpf3NCNGmvsj0raVLl/YNDg4eElATZcYppUH9/f= 0fnZiY+K0GfLjMoHehz/FKpfK1c+fOvVt07MIACZzPCpyXNNCyooPd5fZXBdJXBNJrReQoBJD8z= ZBMar8GwLxK04IFC6JFixZFpPPnz48keNTR0UGAGPPUGNHk5GSkBxHduXMnun37dnTr1q04LT3o= dMdxjfENmdvvQvkEA7Ry5cpnxHSfrlIxDYBodYkWL14cgxEqoNsO0MbGxiLFWDFgbl2Be1a27Rc= vXvxlSJ8ggKqa86IYFgYHUHp6emJNCREotA2aNTIyEoMV2sdpR4D5VIgm5QJU9Tl/EvNCZoXG9P= b2xmbkCBbfYkKYjJkNk0U7KIcwNUwO8zNzhJ+ZYNyo+gfzGx4eLqNR4zLtx/N8UiZA1dXq75Il2= CEzKYDRPsmdRwwA5qF9WXwZGA2NMjKAA08un5nCF6AAuwDhuB/KWt1SASLOUcc3NVjwUs5T7uvr= a/AxADE6OhpfRUFJmyhgdXd3x5erVWjhpUuXimrTcSnCxpMnT477xssKFJ9Thy/5OvnKFJDF4Lg= CX79+PRaYp9tqwjxx1pjiwoXT1s/YyMHqh+kF0oPi06sLNzKDvBrE9kFP+w219tYnuWBSXV317R= cCapUoImSSZaE8fkqrbBwuWEftDWOTs3xOOiVwN/m2JTNWJTaeYrZXVylwxsfHo/Pnz88aOEwcb= WFMxjbigfHgAom57q3OvaHLDBNjV64W32xolZJBnZctq/tvVB4fgC+YbcK/Mb6tfIyP6RUwt36B= fFU83nJlb9ASmRZHBv9VgxVuI989Dlnta1UId/ny5Vr+bt6sWLEiDkpNBplOkOOWmV1SnwG1r50= nNZiYGmxXg1xweEqsVkao9pUrVyx711Nkcc0NWZE5j6QcfVUMak1rAA3omFQNdtZqMm6wbVYPCB= XGrFDxuULIgkzIBiFrqD8CA7CwudQAkolwhpx7TIppuUEgq5UJYkznQopMyGaEzMieR2AAFtauB= pAqnrbCrNR9EsQ5BeKNLLZtqUM2ZDRyZbcyX+piEQPETzMqfMzX2C1j40nMAal9vFl06333Yw9/= O7q87c3o+iM/jFphhPCAFzzhnUdsaJEVQnbmkEdgASa0iwFSpPuk3Wd1ZlduxPYhxLTGPvWdaHL= pA9HYhm3Rta0/aQokpgkPeMU8xTuPkBFZjdw5WJkn7RAmsZnFAAmxLZ5GDUXYr60ExDnuoA0NE5= lFJ39fK7m1bqg0SAYOPIxc3lbmS5HVYjPmEOiLYkw6dunnYDHd5GPslrmqya7c1NZt47tfcvSn0= aIT9QO8MiB5wRFPeIcQsiKzkTsXK/Okj4JN5cSJEw+p8nueBg1FBF+KEeIynkjosQI9Fv77UDTZ= /eFo4oG1cX9S8pQ3RKoNI05n0sDpeuXZ3L4uO2Q3YNCiAAvoPHbs2B8r2i48LkZPuMyS9zg3jhc= gnkbRoLAsSK0CB7nxRcwBoLjQKDM76n2kdn+pCNWnVPkZXwMrA3mLfeyYwepC06IgtRIck9H1o1= iAG21bm0R6CoB2qPBjiYqGLJtSO3Mhrghg3NDfMqEgtQMcZODXE3vQaFTAOdVFTOxZ9eVXyFRCN= W0F45wl1P/4GOaBRB+W8obVSg65qM/xjc2Ww/wQroINdhbJxMbZwdWDm5TWIG/UDDjGA5CYMGRA= kKI51FkZ9ayArQAHXq7s7pyoS6EeAJr2viktKLaNKfd5jo02IeQDadyJceDRSnDg58ruzom6FOr= ukKrlAoTXN0I1W0UG0kInTjLerQYHvq7s7pxszGQKNnEknayY7Xwd/vrIrXsMdZ5l7jqEZH2jks= KhKPIpbGYU+1Yra4S5Nbt3M16WulrjzsnqkynYoEG5AJWw3eRYM/I+cDAr19xw1q0EyfU77pxmC= FcvGMVJj9Tz/jtiBlvmSd3VwN8juzQNHFvZOBC2lczSVqxkNgekY04BNEKg+Hk1zAwUiUAtUOQQ= qmygiEBZ4OCLuJrZuzFGGvGTtQWK7AgCAsU/A9B6MczcaoC8MWbwvAArTcA8cKxfu0By3zJhDgE= P+g846VMmWFoK2kZok+vsrDwvDQXH+AASZoVfMmrGJyGzew7kzsn4J1OwIQ56O1mRzGNW5tQYyN= WmZFtfvig4xqOVICGzPVjmEnKWDjYdfPsggXi9P5PcA6ciAJUFx4RpFUiuzO5cbBxPOgw2lSNHj= kzJD21UAz4uSSXiBnb1ED6JTWsI3dAB+8319R9MykTIaT4pqmjxeI83dLIJzVm+fHlNg65evRqy= ir188ODB38SRtBgcyh5Cy678kC3vxBN2gJbbb+2Xa03KgGOdvZrk8LZ2vhRZLQZiDoH+J8Yk3qb= rp9kz6vgDMUeOVMJ2WSohln1WgvyIdCqaWLUm6vzn/mjp4R9nD5A68nSFaRKaM9n7kWjx334VLX= gfD5FO7Nr56dn8D2+hBfifSc3zGf1kNFoDRC8ivKzJbk0farpGb2PVfhvj8Kzo8Wse/1bXY1rmG= gBGb83lDiEwX9ELDJ+jYW2zqsIXcnuqAU/AiIHth0Qrm0spshk4yOXKniWni0UNIDnqA6o4m9WR= OuzXjUCTb3bl9Z+tekwL2YyQOdD3nAUL61cD6LQ+RhNAu60iK+VJWFyUtPGsfrNVp3nEfsdODZG= 1gPbsBguTtQYQBfJB+8T8klWmpawEvF5ihMPG1ucKIYvtHZEJWW0FzpKRuYOB26Z+2KxSrUrjUi= 9eNI4dlNswec9umMtWNeyd+Mg1v2SfdufRnOTbZSwigYEh4v1Ir8y87srZoEFUrFu37mca6B23U= do9q5gbMArc+LU8U+20fu0oZ0xeCUQGI2RzX3+xcl/KnJl7sq62zLsVGuj+a8BVQBpMzECSqb2n= 5bFP+U9bWVaKWbnmRtTKa7g8VWKP/GAyi3t6Hfx5KQqfY5EyrTGrgN/ea4ylPXsU9/yiVuDceAG= iflCfMUo9v6Db+EUip4/3FiBYRvFJ+AIIRwlQ5APOXrx8fYXw42yHCNl1xqxWvHZXwOfAnk8Rvi= 6AvEeMXhMzoe5/zJKz9wIogcQnmHzHMP1BhKGXk3I4hfr7Im1MDm3jQvNYgnn6ZopoCCbDqkh/e= KUd1NGfGCckCEyI3PznUMZQTptPMV9UfsaqZ23SUlYV96gzrV3RckCdjQ/qUn2QK7Cc9r800fdV= 9kVdmWbp9uOeJ8xya08YrTAflWybl0fLOEHgPIcL3iWI7yT4JPPXIX0LTbaqSfvFuJC5JQUxs7H= gktUIkzLgMDXAYGVEUwDCzDHJq2C+fR/1miBVn/SS8sus7B5JS30WXtin8I2nnjjvNR6/R4BBTP= 6xAJ9evlZU5sIAMYAGeleatFEm8byynMvPVeJDueeRFZnLCFnIB/kGYFui8g/sPzcppUEuUIpAj= +oDYExup55W/QzEbTSL91UZdiITsjU7dNMa5AogbfrA/YOllgJkYA3oeyvFK/f/RZcBkpVW/8nb= k4pttqjdJl3BX9qm8OVXgzdkSq/q19J785+8pUwsGhoaqhw+fPiTmtw9828C/w/K8jZzsc+GngA= AAABJRU5ErkJggg=3D=3D") !important; } .ms-outlook-ios-dark-mode .ms-outlook-ios-availability-container > table > = tbody > tr > td:nth-child(1) > table:nth-child(4) > tbody > tr:nth-child(2)= > td > a { color: #0086F0 !important; } .ms-outlook-ios-dark-mode .ms-outlook-ios-mention { color: #ACACAC !important; background-color: #292929 !important; }</style> <meta name=3D"viewport" content=3D"width=3Ddevice-width, user-scalable=3Dno= , initial-scale=3D1.0, minimum-scale=3D1.0, maximum-scale=3D1.0"> <div style=3D"direction: ltr;"> <div>What do you think should i submit PR for it at all? Even though it is = feature, during pentesting engagements you can find out a lots of informati= on and perhaps gain code exec depending on ios version. </div> </div> <hr style=3D"display:inline-block;width:98%" tabindex=3D"-1"> <div id=3D"divRplyFwdMsg" dir=3D"ltr"><font face=3D"Calibri, sans-serif" st= yle=3D"font-size:11pt" color=3D"#000000"><b>From:</b> Robin Wood <robin@= digininja.org><br> <b>Sent:</b> Thursday, September 19, 2019 9:06:39 AM<br> <b>To:</b> Fyodor <[email protected]><br> <b>Cc:</b> XenoN. w0w <[email protected]>; nmap list <[email protected]= rg><br> <b>Subject:</b> Re: Cisco Smart Install script</font> <div> </div> </div> <div> <div dir=3D"auto">If it's the same issue I think it is, Nessus reports it a= s an info. The one that they report on can also be used to do unauthenticat= ed code exec but is a feature not "vulnerability" so not a proble= m. <div dir=3D"auto"><br> </div> <div dir=3D"auto">Robin</div> </div> <br> <div class=3D"gmail_quote"> <div dir=3D"ltr" class=3D"gmail_attr">On Mon, 9 Sep 2019, 18:34 Gordon Fyod= or Lyon, <<a href=3D"mailto:[email protected]">[email protected]</a>> wro= te:<br> </div> <blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p= x #ccc solid;padding-left:1ex"> <div dir=3D"ltr"> <div dir=3D"ltr"><br> </div> <br> <div class=3D"gmail_quote"> <div dir=3D"ltr" class=3D"gmail_attr">On Mon, Aug 26, 2019 at 4:08 AM XenoN= . w0w <<a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D"n= oreferrer">[email protected]</a>> wrote:<br> </div> <blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-= left:1px solid rgb(204,204,204);padding-left:1ex"> <div lang=3D"EN-US"> <div class=3D"m_1723389174890974703gmail-m_-2586403025385974687WordSection1= "> <p class=3D"MsoNormal"><span style=3D"font-size:11pt">Hello guys, during pe= netration testing engagements I often come to cisco devices which allows me= to grab their config over smart install protocol. <u></u><u></u></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:11pt">I would like to make = a script and add functionality of testing and getting config within the scr= ipt.<u></u><u></u></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:11pt">Here is the link for = reference exploit <a href=3D"https://github.com/Sab0tag3d/SIET" target=3D"_blank" rel=3D"nore= ferrer">https://github.com/Sab0tag3d/SIET</a><u></u><u></u></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:11pt"><u></u> <u></u><= /span></p> <p class=3D"MsoNormal"><span style=3D"font-size:11pt">What do you guys thin= k about it?</span></p> </div> </div> </blockquote> <div><br> </div> <div>Thanks for the details. And wow, the Cisco advisory[1] really tr= ies to shirk all responsibility for this mess by writing:</div> <div><br> </div> <div>"Cisco does not consider this a vulnerability in Cisco IOS, IOS X= E, or the Smart Install feature itself but a misuse of the Smart Install pr= otocol, which does not require authentication by design."</div> </div> <div class=3D"gmail_quote"><br> </div> <div class=3D"gmail_quote">Well maybe they shouldn't have introduced such a= lame "feature" in the first place. And even though it is b= roken by design, there are lots of ways that Cisco could have at least miti= gated the problem. Apparently they only recently added a command to turn this crap off.</div> <div class=3D"gmail_quote"><br> </div> <div class=3D"gmail_quote">Anyway, yeah, we'd like to see an NSE script or = other Nmap features related to this. For example, does Nmap version d= etection (-sV) detect this properly? Are there good ways to detect the vuln= erability (beyond just port 4786 being open) without reconfiguring the device or otherwise being too intrusive?&n= bsp; I mean an exploitation feature is nice too, but often Nmap users just = want to learn as much as possible about the device and vulnerability withou= t doing anything too intrusive.</div> <div class=3D"gmail_quote"><br> </div> <div class=3D"gmail_quote">Cheers,</div> <div class=3D"gmail_quote">Fyodor</div> <div class=3D"gmail_quote"><br> </div> <div class=3D"gmail_quote"><br> </div> <div class=3D"gmail_quote">[1] <a href=3D"https://tools.cisco.com/secu= rity/center/content/CiscoSecurityAdvisory/cisco-sa-20170214-smi" target=3D"= _blank" rel=3D"noreferrer">https://tools.cisco.com/security/center/content/= CiscoSecurityAdvisory/cisco-sa-20170214-smi</a><br> <div><br> </div> <div> <br> </div> </div> </div> _______________________________________________<br> Sent through the dev mailing list<br> <a href=3D"https://nmap.org/mailman/listinfo/dev" rel=3D"noreferrer norefer= rer" target=3D"_blank">https://nmap.org/mailman/listinfo/dev</a><br> Archived at <a href=3D"http://seclists.org/nmap-dev/" rel=3D"noreferrer nor= eferrer" target=3D"_blank"> http://seclists.org/nmap-dev/</a></blockquote> </div> </div> </body> </html> --_000_VI1PR0902MB17896F77F296C8D7CDC94F55FC890VI1PR0902MB1789_-- --===============4653352368636186790== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Sent through the dev mailing list https://nmap.org/mailman/listinfo/dev Archived at http://seclists.org/nmap-dev/ --===============4653352368636186790==--