Re: Sniffing packets on the wire

From: Robert Moir (bofh_at_mvps.org)
Date: 06/06/04


Date: Sun, 6 Jun 2004 10:04:07 +0100

S. Pidgorny <MVP> wrote:
> Just to add to that: some time ago Cisco had a vulnerability in the
> Web management interface of their switches, allowing to configure the
> switch without proper authorisation. I observe switches that have
> this problem still in wide use. That vulnerability allows anybody
> physically connected to the same switch, sniff traffic to any/all of
> the systems, then use software packages like Cain and Abel to extract
> all sorts of logon credentials.

Thats pretty bad....



Relevant Pages

  • Re: Cisco 6509 switch telnet vulnerability
    ... The> vulnerability was found to work on 2 different Cisco 6509 switches> running CATOS 5.4and 5.5. ... The vulnerability can lead to> information and commands being exectued on the remote switch from the> login prompt. ...
    (Bugtraq)
  • [NEWS] Cisco CatOS Telnet Buffer Vulnerability
    ... Some Cisco Catalyst switches, running CatOS based software releases, have ... a vulnerability wherein a buffer overflow in the telnet option handling ... This vulnerability is documented as Cisco bug ID CSCdw19195. ...
    (Securiteam)
  • Re: Duplex/Speed Hardcoding
    ... fully cisco managed switch network. ... series switches and 29xx series switches. ... is set to half duplex and the other to auto). ... managed switch network" that shouldn't be difficult, ...
    (comp.dcom.sys.cisco)
  • Re: multiple uplinks from ISP
    ... I am using cisco 29xx and 3xxx switches. ... Subject: multiple uplinks from ISP ...
    (freebsd-net)
  • Re: Cisco 6513
    ... I am in the process of designing a high availabilty data center, ... have chose the cisco 6513; i have used cisco configurator, ... MEM-C6K-CPTFL1GB Catalyst 6500 Compact Flash Memory ... pair of switches for Firewalls (if not true firewall themselves, ...
    (comp.dcom.sys.cisco)