Page 2 of 2 FirstFirst 12
Results 11 to 13 of 13

Thread: Cisco Switch

  1. #11
    Just Another Geek
    Join Date
    Jul 2002
    Location
    Rotterdam, Netherlands
    Posts
    3,401
    Originally posted here by nebulus200
    Bah! Don't do that! CLI and 'no ip http server', all the way... you know some of those switches are using IIS on the backend, right?
    IIS? No ****?!? Are you sure?? Never saw one before and I've seen alot of switches.

    But I do suggest checking if your IOS isn't vulnerable.
    Check if you can see the config (without authentication) with the following URL:
    http://myswitch/level/16/exec/show/config

    If you get to see the config I suggest turning the http interface off as soon as possible. Anyone can change your config if this works.

    Also see if you can run the Cisco Global Exploiter to make sure it's not vulnerable to some more tricks.
    Oliver's Law:
    Experience is something you don't get until just after you need it.

  2. #12
    Jaded Network Admin nebulus200's Avatar
    Join Date
    Jun 2002
    Posts
    1,356
    Originally posted here by SirDice
    IIS? No ****?!? Are you sure?? Never saw one before and I've seen alot of switches.

    But I do suggest checking if your IOS isn't vulnerable.
    Check if you can see the config (without authentication) with the following URL:
    http://myswitch/level/16/exec/show/config

    If you get to see the config I suggest turning the http interface off as soon as possible. Anyone can change your config if this works.

    Also see if you can run the Cisco Global Exploiter to make sure it's not vulnerable to some more tricks.

    Hmmm...now that I am actually trying to find it, I can only find stuff related to their call center, unity server, and other similar products. I could have sworn that their earlier switches/routers had some kind of hacked up version of IIS...of course it wouldn't be the first time I was wrong.

    /nebulus
    There is only one constant, one universal, it is the only real truth: causality. Action. Reaction. Cause and effect...There is no escape from it, we are forever slaves to it. Our only hope, our only peace is to understand it, to understand the 'why'. 'Why' is what separates us from them, you from me. 'Why' is the only real social power, without it you are powerless.

    (Merovingian - Matrix Reloaded)

  3. #13
    Senior Member
    Join Date
    Feb 2003
    Location
    Memphis, TN
    Posts
    3,747
    Thanks for all your help guys, I think I got it figured out.

    As far as a vulnerability, we're putting a firewall in front of ASAP.
    =

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •