Re: Cisco IOS vulnerability

From: Jeff Kell (jeff-kell_at_utc.edu)
Date: 07/20/03

  • Next message: Andrew Bates: "Re: Cisco 0-day? [Was: strange protocol scans (and MOBP plug)]"
    Date: Sat, 19 Jul 2003 23:56:29 -0400
    To: jlewis@lewis.org
    
    

    jlewis@lewis.org wrote:

    > That's a different issue. undefined access list = you referenced an
    > access-list that does not exist. In that case, it's as if you didn't
    > reference the access-list.
    >
    > I think this is a common pitfal for beginers with IOS. You need to modify
    > an access-list, so you telnet into the router, conf t, no access-list
    > blah, then start typing in the new version of the access-list. Hopefully,
    > your first line is permit tcp any any est, because once you start
    > reentering the access-list, there's the implicit deny all all at the
    > end...so if you're getting to the router through the interface using the
    > access-list you're modifying, you may block yourself out.
    >
    > For that reason, it's generally best to create a new access-list, then
    > modify the interface config to use that new access-list.

    Even better, show config to get the ACL, cut and paste it into an
    editor. Add "interface foo" and "no ip access-group this-acl in" and
    "no ip access-list extended this-acl" at the beginning, and an
    "interface foo" and "ip access-group this-acl in" at the end. Then you
    can cut-and-paste the config without any side effects (or you can store
    it on a tftp server and config net from there).

    Jeff

    ----------------------------------------------------------------------------
    Attend the Black Hat Briefings & Training, July 28 - 31 in Las Vegas, the
    world's premier technical IT security event! 10 tracks, 15 training sessions,
    1,800 delegates from 30 nations including all of the top experts, from CSO's to
    "underground" security specialists. See for yourself what the buzz is about!
    Early-bird registration ends July 3. This event will sell out. www.blackhat.com
    ----------------------------------------------------------------------------


  • Next message: Andrew Bates: "Re: Cisco 0-day? [Was: strange protocol scans (and MOBP plug)]"

    Relevant Pages

    • [fw-wiz] Noob stuck becomes PIX admin overnight!
      ... I need to allow a device on the DMZ interface to ... I have the skills to modify my current config using the terminal, ...
      (Firewall-Wizards)
    • Re: [Fwd: Config Network Setting]
      ... After modify the config files, I can't restart the network controll by ... Config Network Setting ...
      (Fedora)
    • Re: HTTPWebrequest HTTP1.1 100 Continue
      ... What you need to do in modify the .config ... file for your program, which resides in the same folder as your executable, ... > I don't see how to modify the useUnsafeHeaderParsing propery in my VB.Net ... >> Except that article doesn't apply, the response here is perfectly valid ...
      (microsoft.public.dotnet.framework)
    • Looking for automatic .config file modifier
      ... modify a certain config value in many .config (web.config and ... web applications with different paths. ... the xml file path and the config value's xpath for every entry. ... values and push a button to modify all the values. ...
      (microsoft.public.dotnet.framework.aspnet)
    • Re: [SLE] KWiFimanager NFG again!!!
      ... > interface config. ... This allows users to make changes to the network ... the root password is required to do the ...
      (SuSE)