Showing posts with label Cisco. Show all posts
Showing posts with label Cisco. Show all posts

Metasploit's HD Moore releases 'war dialing' tools

HD Moore wants to simplify pen-testing and simulated hacking attacks against telephone systems.

The Metasploit founder has released WarVOX as a free suite of tools to explore, classify and audit a range of telephone systems, including modems, faxes, voicemail boxes, PBXs, loops, dial tones, IVRs and forwarders.

Moore explains:

  • WarVOX requires no telephony hardware and is massively scalable by leveraging Internet-based VoIP providers. A single instance of WarVOX on a residential broadband connection, with a typical VoIP account, can scan over 1,000 numbers per hour. The speed of WarVOX is limited only by downstream bandwidth and the limitations of the VoIP service. Using two providers with over 40 concurrent lines we have been able to scan entire 10,000 number prefixes within 3 hours.
  • The resulting call audio can be used to extract a list of modems that can be fed into a standard modem-based wardialing application for fingerprinting and banner collection. One of the great things about the WarVOX model is that once the data has been gathered, it is archived and available for re-analysis as new signatures, plugins, and tools are developed. The current release of WarVOX (1.0.0) is able to automatically detect modems, faxes, silence, voice mail boxes, dial tones, and voices.

Moore hopes WarVOX can replace the “slow and inefficient” systems currently in place to identify security holes in phone systems.

This presentation (.pdf) covers the motivation behind the tools and the implementation details.

[Source: zdnet]

Cisco warning: Serious flaws in Wireless LAN controllers

Routing and switching giant Cisco has released an alert to warn of multiple security flaws in some of its Wireless LAN controllers.

The company documented at least four vulnerabilities that could lead to denial-of-service or privilege escalation attacks. Affected product lines include Cisco Wireless LAN Controllers (WLCs), Cisco Catalyst 6500 Wireless Services Modules (WiSMs), and Cisco Catalyst 3750 Integrated Wireless LAN Controllers.

The skinny:

  • CVE-2009-0058: Web authentication is a Layer 3 security feature that causes the
    controller to drop IP traffic (except DHCP and DNS related packets) from a
    particular client until that client has correctly supplied a valid username and
    password.
  • CVE-2009-0059: An attacker may cause a device reload when sending a malformed post
    to the web authentication “login.html” page.
  • CVE-2009-0061: Affected Cisco WLC, WiSM and Catalyst 3750 Wireless LAN Controller
    models are vulnerable to a DoS condition that is triggered by the receipt of
    certain IP packets. Upon receiving these IP packets, the affected device may
    become unresponsive and require a reboot to recover.
  • CVE-2009-0062: A privilege escalation vulnerability exists only in WLC software
    version 4.2.173.0, and could allow a restricted user (i.e., Lobby Admin) to
    gain full administrative rights on the affected system.

One of these flaws carry a CVSS Base Score of 9.0, meaning it should be treated as a “high priority” update.

[Source: zdnet]

Lead, melamine, and backdoored routers

It seems that not a day goes by without a new media alert regarding bad things in the chinese supply chain. First it was lead in our toys, then it was melamine in our milk, and now it also may be backdoors in our counterfeit Cisco hardware.

A recent BusinessWeek article discusses a criminal prosecution from late 2007 that raised the possibility that counterfeit Cisco routers have made their way into the western supply chain. Purchasers apparently include several government agencies and contractors, including branches of the military.

While counterfeit products may be a major economic concern, they also present a vector for foreign concerns to inject backdoors into critical infrastructure. This scenario is rather unlikely, as it would be far more cost effective for an attacker to compromise desktop systems using social engineering and trojans than it would be to create a trojaned router. Nevertheless, the possibility pushed the FBI to launch Operation Cisco (Cylon?) Raider in an effort to clamp down on the sale of counterfeit routers.

Unlike toys and food, performing a in-depth analysis of what goes into these routers would be expensive and possibly imperfect. Much like the apocryphal story of the CIA-initiated Soviet oil pipeline sabotage, we may never know if these mongrel devices were either pure clones or something more sinister.

[Source: zdnet]

Cisco mega patch plugs serious IOS vulnerabilities

Serious IOS vulnerabilitiesToday is a very busy patch day for network administrations managing Cisco gear.

The networking giant released a whopping 12 bulletins with fixes for a wide range of security vulnerabilities in IOS, the underlying software that powers routers and network switches.

Some of the flaws could allow a malicious hacker to take complete control of vulnerable devices while others put Cisco customers at risk of denial-of-service attacks.

The most serious issue in this patch batch carries a maximum CVSS base score of 10.0 and affects the Cisco uBR10012 series devices:

Cisco uBR10012 series devices need to communicate with an RF Switch when configured for linecard redundancy. This communication is based on SNMP (Simple Network Management Protocol). When linecard redundancy is enabled on a Cisco uBR10012 series device, SNMP is also automatically enabled with a default community string of private that has read/write privileges. Since there are no access restrictions on this community string, it may be exploited by an attacker to gain complete control of the device. Changing the default community string, adding access restrictions on SNMP or doing both will mitigate this vulnerability. The recommended mitigation is to do both.Blogger: 4 X Security Team - Create Post

Network administrators managing Cisco gear (with IOS) and strongly urged to review all the September 24 patches listed here and prioritize fixes according to severity rating scores. In cases where mitigations are offered, those should be applied where necessary.

[Source: zdnet]

Cisco IP Phone Overflow and DoS Vulnerabilities

ciscophone.png

There comes word today of some rather nasty vulnerabilities that effect Cisco IP phones. Some of the affected Cisco (CSCO) devices are:

The following Cisco Unified IP Phone devices running Skinny Client Control Protocol (SCCP) firmware:

7906G, 7911G, 7935, 7936, 7940, 7940G, 7941G, 7960, 7960G, 7961G, 7970G, 7971G

The following Cisco Unified IP Phone devices running Session Initiation Protocol (SIP) firmware:

7940, 7940G, 7960, 7960G

The version of firmware running on an IP Phone can be determined via the Settings menu on the phone or via the phone HTTP interface.

There are numerous vulnerabilities involved here. I have listed the lot after the jump.


More after the jump »

[Source: Liquidmatrix]

Cisco IOS Multiple Vulnerabilities

Out today are multiple vulnerabilities from Cisco. There are patches available from Cisco to tackle data manipulation and denial of service issues in their IOS.

From Secunia:

Description:
Some vulnerabilities have been reported in Cisco IOS, which can be exploited by malicious people to disclose sensitive information, manipulate certain data, or to cause a DoS (Denial of Service).

1) A memory leak exists in the handling of completed PPTP sessions, which can be exploited to exhaust memory on an affected system.

2) An error exists in the handling of PPTP sessions when virtual access interfaces are not removed from the interface descriptor block (IDB) and are not reused. This can result in an exhaustion of the interface descriptor block (IDB) limit.

Vulnerabilities #1 and #2 are reported in Cisco IOS versions prior to 12.3 with VPDN enabled.

3) Some errors exist in the Data-Link-Switching (DLSw) feature when processing UDP and IP protocol 91 packets. This can be exploited to cause a reload of the system or a memory leak.

4) An error exists in the processing of IPv6 packets, which can be exploited to prevent the interface from receiving additional traffic or to cause the device to crash (if RSVP service is configured on the interface) by sending a specially crafted IPv6 packet to the device.

Successful exploitation of this vulnerability requires that IPv6 and certain IPv4 UDP services are enabled.

5) An error exists in the implementation of Multicast Virtual Private Networks (MVPN), which can be exploited to create extra multicast states on the core routers via specially crafted Multicast Distribution Tree (MDT) Data Join messages. This can also be exploited to receive multicast traffic from VPNs that are not connected to the same Provider Edge (PE).

Successful exploitation of the multicast traffic leak requires that the attacker knows or guesses the Border Gateway Protocol (BGP) peering IP address of a remote PE router and the address of the multicast group that is used in other MPLS VPNs.

Ger yer patch on.


Article Link

[Source: Liquidmatrix]

Cisco IPS Jumbo Frame DoS

For a networking company, that’s gotta hurt.

From Cisco:

Cisco Intrusion Prevention System (IPS) platforms that have gigabit network interfaces installed and are deployed in inline mode contain a denial of service vulnerability in the handling of jumbo Ethernet frames. This vulnerability may lead to a kernel panic that requires a power cycle to recover platform operation. Platforms deployed in promiscuous mode only or that do not contain gigabit network interfaces are not vulnerable.

Cisco has released free software updates that address this vulnerability. There is a workaround for this vulnerability.

Update or workaround? Which is it then? At the very least get your patch on.

[Source: Liquidmatrix]

Cisco confirms possibility of IOS rootkits

Cisco confirms possibility of IOS rootkitsOn the heels of an EUSecWest conference presentation on malicious rootkits for Cisco IOS (see background), Cisco’s security response team has published a must-read document confirming that stealthy malware can be loaded on the software used on the vast majority of its routers and network switches.

Cisco warns:

It is possible that an attacker could insert malicious code into a Cisco IOS software image and load it onto a Cisco device that supports that image. This attack scenario could occur on any device that uses a form of software, given a proper set of circumstances.

The company’s confirmation follows a technical discussion by Core Security researcher Sebastian Muniz of “Da IOS Rootkit,” which is basically a binary modification to the IOS image downloaded from the device.

In this Q&A, Muniz explains his creation:

The main feature of Da IOS Rootkit is the universal password. Every call to the different password validation routines grant access to the user if the unique rootkit password is specified. This is what will be in the public release. Other features such as hiding files, processes and connections will not be included. The core of the rootkit code is written in plain C instead of assembly. It doesn’t persist through upgrades yet but future versions probably will.

I haven’t tested on Catalyst switches because they run CatOS which a different than IOS. The rootkit code is rather generic so it should work with some modifications. As a matter of fact, some parts of the code are so generic that they will work on any other class of devices (not even CISCO devices).

Cisco, in response, published a list of security best practices  to improve the security posture of a routing and switching network.  “These practices are particularly relevant to ensure that Cisco IOS devices only use authorized and unaltered Cisco IOS software images,” the company said.

[Source: Zdnet]