Posts mit dem Label ios werden angezeigt. Alle Posts anzeigen
Posts mit dem Label ios werden angezeigt. Alle Posts anzeigen

Donnerstag, 26. November 2009

DE - IOS HTTP Server "hacking" Vorsorge

So nachdem ich heute 4 Firmen angerufen hab und denen mitgeteilt hab das die Konfiguration Murks ist, poste ich die ganze Geschichte auch noch in deutsch.

Vor kurzem bin ich über eine Suchmaschine gestolpert mit der man auch was finden kann. Dabei ging es aber nicht um den Inhalt der Webseite sondern mehr das drum herum. So war es möglich nach dem Webserver und deren Version zu suchen.

Gesagt getan auf meine suche nach Cisco IOS Webservern erhielt ich über 67.000 Treffer. Ouch,. mal ehrlich 67k wieso müssen die Webinterfaces haben und vor allem warum müssen die via Publik IP Verfügbar sein.

Als ich so durch die liste surfte stellt ich fest das einige nicht mit der 401 sondern mit einer 200 als HTTP Statuscode antworteten. Einen von den Routern angeklickt und schon hat sich gezeigt. Prima die Systeme arbeiten ganz ohne Authentifizierung.

Ich hab die Suchkriterien angepasst und von 67.000 Routern brauchen mehr als 1200 Kein Passwort sind also ungeschützt.

Da es über die Weboberfläche möglich ist ein show cdp neigbor abzusetzen zeigte sich das hinter den Routern noch andere Cisco Komponenten hängen. Ich hoffe das die nicht so lausig konfiguriert sind wie der Router.

Um sicher zu sein, gilt daher entweder eine Access Liste auf den Webserver binden:

access-list 1 permit X.X.X.X ! x.x.x.x= your management network
ip http access-class 1

oder noch besser:

no ip http server


cheers
NWG

EN - IOS HTTP Server hacking prevention

OK I need to post this since this is really scary to me.

A few days ago I stumbled upon a quite cool search engine (no I will not post the URL) what was really interesting is that it did not search for the content of the website it was more interested in the server replies like Server Version HTTP status code.

Since Cisco routers and switches offer a web server for configuration I searched for Cisco IOS servers. The result was scary (it gets worse a bit later) more than 67.000 routers and switches operating the HTTP server are public available. Their may be reasons why routers should be available via HTTP from the Internet but 67000 router people you are kidding me.
I checked some of them and most look like real routers/ switches.

But while browsing the list I found a few routers responding with Cisco IOS Server AND HTTP 200 code. (most of the routers respond with 401 authorization required). I tried one of these and great I could log in and have a look at the configuration passwords etc.

I decided to redefine my search and the result was: from those 67.000 routers 1200 are not requiring authorization of any kind, great.

A quick show cdp neigh showed that most of them I've checked are connected to other Cisco devices. I hope that these devices aren't configured that poorly.

To get out of this list just bind an access list to you HTTP Server,


access-list 1 permit X.X.X.X ! x.x.x.x= your management network
ip http access-class 1


or even better do a

no ip http server


hope some of those guys owning these routers fix them (fast)


Cheers
NWG

Montag, 9. November 2009

DE - LAB Update

Ok es ist wieder eine Weile her, dass ich gepostet habe (passiert mir anscheinend öfter). Es gibt mehrere Grunde warum ich nicht gepostet hab. Zum einen habe ich mich seit August mit mehreren Trainings zum Thema CCNA und CCNA Security befasst. Mittlerweile habe ich den CCNA Test bestanden und bald kommt der CCNA Security dran. Danach geht es zum CCSP Training das ich hoffentlich auch irgendwann im Januar 2010 hinter mich gebracht hab.

Der zweite Grund ist, das ich mein Lab überarbeiten musste und zwar von Grund auf. Grund dafür ist das mein Lab bei weitem nicht den Anforderung entsprochen hat, die ich für meine Kunden brauchte und das ich damit keine CCNA Security Labs durchführen konnte.

Deshalb hier ein kurzer Überblick über mein jetziges LAB Setup:



Anbei eine Erklärung der wichtigsten Maschinen und Systeme:

Elysium:
- eine XP64 Arbeitsstation mit GNS3 und VMware Server 1.8
- die meisten kleinen Labs erarbeite ich hier (quick und dirty)
- bei großen Labs dient die Maschine auch als zusätzlicher Hypervisor
- beide Netzwerkkarten sind am Main und Lab Switch angebunden

Core01
- Win2k8 x64 (64 GB RAM 2x4 Core CPUs) – merkt man das ich stolz auf die Box bin
- alle VMs laufen via Hyper V
- beide Netzwerkkarten sind am Main und Lab Switch angebunden

VM Server:
Active Directory Server und AD Child Server
- um sich gegen AD Szenario zu authentifizieren
CA Server
- MS CA Server für PKI Szenarios zwischen den Routern
Nagios
- Nagios überwacht meine Labs und ein paar echte Maschinen
Radius
- Free Radius um Radius auth. zu simulieren
Tacacs
- TACACS+ um Tacacs auth. zu simulieren (noch nicht fertig eingerichtet)
SDM
- Die XP Maschine stellt den SMD für das CCNA Security Labs zur Verfügung
Workstation
- nur eine Testmaschine für VPN Clients et
MAIL
- Sendet Mails von Nagios
Cisco MARS
- eine virtuelle MARS Appliance (auch noch nicht ganz fertig)
Nicht aufgeführte Systeme:
Cisco ACS 4/5 (trial), CUCM 7/ 5

LAB-R001
- virtueller 7200 Router mit IOS 15.0.1.M
- komplett mit FE Anschlüssen ausgerüstet
- jeder FE Anschluss ist an ein LAB angebunden

LAB-SW01/SW02/SW03
- Cisco Lab Switches von Ebay
- Catalyst 2950 12.1.22-EA13

Home-SW02
- Netgear 8 Port Gigabit Switch

Router Labs
Jedes Router Lab läuft in einer eigenen Dynaslax VM die so viele Ressourcen wie nötig zugewiesen bekommen.

Ich würde mich über Anregungen Kommentare und Ideen zu meinem Labaufbau freuen.
Das war's fürs erste.

cheers NWG

EN - Lab update

It has been a while since I made my last post. This was due to several reasons.
First of all I was doing some training for my CCNA and CCNA Sec certification. I've already passed the CCNA stuff and now I'm up to do the CCNA Sec test.
Later on I've planed to do the CCSP tests, hopefully I'll have them finished in January 2010.

The second reason was that I've restructured my lab from the scratch. This was necessary since the old setup did not reflect the environments I've had to face at my customers location and it was not possible to train for the CCNA Sec stuff. :D

So here is a quick overview of my current lab setup


I'll go through the picture and explain the most important machines:

Elysium:
- Is a XP64 workstation running GNS3 and VMWare Server 1.8
- most small labs and tests are done here
- for larger labs this box is used as additional hypervisor
- 2xNICs connected to my main and my lab switch

Core01
- Win2k8 x64 (64 GB RAM 2x4 Core CPUs) – I'm happy with this box :D
- Hyper V is running all VMS
- 2xNICs connected to my main and my lab switch

VM Servers:
Active Directory Server and AD Child Server
- for authentication tests with Active Directory
CA Server
- MS CA Server to do the PKI stuff for router to router authentication
Nagios
- Nagios is monitoring my lab networks and some of my real workstations
Radius
- Free Radius implementation for authentication testing
Tacacs
- TACACS+ for Tacacs testing (still in deployment)
SDM
- Well this XP Machine provides the SDM that is required for CCNA Sec
Workstation
- This is just a testing machine (VPN client and so on)
MAIL
- Reporting from Nagios
Cisco MARS
- a virtual MARS appliance (not really deployed yet)
Machines not listed:
Cisco ACS 4/5 (trial), CUCM 7/ 5

LAB-R001
- virtual 7200 running IOS 15.0.1.M
- stuffed with lots of FE interfaces
- each FE connects to a router lab

LAB-SW01/SW02/SW03
- Cisco lab switches from Ebay
- Catalyst 2950 12.1.22-EA13

Home-SW02
- Netgear 8 Port Gigabit Switch

Router Labs
Each router lab is a own VM running Dynaslax with as much resources allocated as needed

I would be thank full for any comments and other ideas about the lab setup. Even for questions :D

Thats it for now :D
cheers NWG

Montag, 18. Mai 2009

EN/DE - Configuration Registers on Routers

Hey out there,

due to I stubled over some wrong set config registered in last time and had not all settings in mind, I found a nice cisco document revealing the secrets about the crytic hex values:

Use of the Configuration Register on All Cisco Routers

Have fun with it,
Zif

Hallo zusammen,

letztens bin ich bei einem Kunden über falsch gesetzte config registers gestolpert und da ich mir nicht sämtliche Werte merken kann, habe ich ein schickes Cisco-Dokument gefunden, welches die Bedeutung hinter den kryptischen Hex-Zahlen verrät:

Use of the Configuration Register on All Cisco Routers

Habt Spaß damit,
Zif

Dienstag, 24. März 2009

DE – Tools update

In den letzten Wochen hat sich mein Lab doch etwas verändert, daher hier ein kurzes Update.

Tools:
GNS3 Version 0.6

Ich musste feststellen das die 7200 Router ab einer bestimmten Anzahl dazu tendieren einfach so zu crashen. Bei meinem Arbeitsnotebook ist das zwischen 3 und 4 Router. Daher habe ich die Wahl dieser Boxen verworfen. Seit kurzem setze ich daher auf 3725, ich wollte zuerst die 3745er nehmen aber die leiden unter einem Dynamips Bug und so kann man die Konfig nicht reimportieren nachdem man sie gespeichert hat. Die 3725 laufen mit dem IOS 12.4.15T8.

Ach so ich habe eine der 5505 ASAs ausgetauscht gegen eine 5510 aber leider ist die Box im produktiven Umfeld. Daher wird es auf der keinen großen außergewöhnlichen Configs geben.

Bei VMWare bleibt alles beim alten.
Cheers NWG

ENG – Tools update

Well within the last weeks my environment slightly changed.

Just to give you a quick update
Tools:
GNS3 version 0.6

I've noticed that the 7200 routers tend to crash, if you run more than a certain amount of them. On my notebook it is often between 3 or 4 7200 routers, even if the are doing nothing. I dropped them and only use them if I need features of 12.4.22T1.
My main routers are now 3725, I tried the 3745 but due to some kind of dynamips bug the do not re import saved configs. So I keep the 3725s running IOS 12.4.15T8.

I changed one of the ASA 5505 to an ASA 5510 but this equipment is now in productive environment so their is no big chance of using them in tricky configs. Both ASAs are still running v8.0.3

VMWare stays the same
Cheers NWG

Mittwoch, 4. März 2009

DE- Update von IOS v12.4.22T auf 12.4.24T

Servus

nachdem ich gestern ca. 8 Stunden bei einem Kunden mich mit 2 Router herumgeschlagen habe, konnte ich das Problem durch einen Releasewechsel von 12.4.22T auf 12.4.24T beheben. Ich glaube 22T ist keine gute Wahl für Router vor allem wenn man bedenkt das von den aktuell 2015 Bugs 1200 innerhalb der letzten 3 Wochen hinzu kamen. AUA!
Mal sehen wie sich 12.4.24T macht, ich will es mal in GNS3 testen.

Cheers NWG

ENG -Update from IOS 12.4.22T to 12.4.24T

Hi Folks

after about 8 hours fighting with 2 routers on a customer location i solved the problem with switching from 12.4.22T to 12.4.24T, guess 22T is not a good choice for routers. According to the Bugtracking tool from the Cisco website their are 2015 Bugs level 1-3 listed. Approximately 1200 added within the last week. Ouch!
Lets see how 12.4.24T is working. I´ll test this release in GNS3.

Cheers
NWG

Donnerstag, 26. Februar 2009

ENG - Tools and Hardware

To build my labs I use several tools here are some of them including some links

Tools
GNS3 – graphical interface for the router simulator Dynamips
* mainly I use the 7200 routers with 12.4.22T IOS

Pemu – PIX and ASA simulator
* my PIX are running v7.2.4 or v8.0.4
* the ASA is running v8.0.3

VMWare – nothing more to say I guess


Hardware

2x ASA 5505
* both ASAs are running 8.0.4

DE - Tools und Hardware

Um die Labs zu bauen werde verschiedene Tools benutzt hier eine kleine Auflistung mit Links.

Tools
GNS3 – grafische Oberfläche zum Router Simulator Dynamips
* Hauptsächlich arbeite ich mit den 7200 Router und IOS 12.4.22T

Pemu – PIX und ASA Simulator
* die PIXen laufen mit v7.2.4 oder v8.0.4
* die ASA mit v8.0.3

VMWare – Was soll ich hierzu noch sagen

Hardware
2x ASA 5505
* beide ASAs laufen mit 8.0.4