PDA

View Full Version : Cisco IOS vulnerability exploit?


-~operator~-
06-04-2007, 01:13 PM
Hey all,

i am actually checking a cisco ios router and tried to exploit the http authorization vulnerability ( http://www.cisco.com/warp/public/707/cisco-sa-20010627-ios-http-level.shtml ). The problem is that i don't get any response. i tried to simply do commands in the browser, so just start

http://10.11.12.xxx/level/17/exec/something

and also tried two more xploit codes listed here:

http://www.securiteam.com/exploits/5UP031F4UQ.html

but it didn't work. The "cisco global exploiter" says it is vulnerable on number 17. The router is just "swallowing" everything i send. i get no feedback, no error message, nothing. wireshark shows the input from my side, no output from the router (just quitting with ACK'S). The logs on the router don't show anything, even if i set the alert level higher.

Google says nothing (at least i think i used the right keywords;-) , the forum says nothing. so any suggestions, help, whatsoever would be appreciated. Perhaps someone experienced the same issue.

Greetings
operator

thorin
06-26-2007, 07:27 PM
Is web management of the device even enabled? Do you get a web page when you visit: http://10.11.12.xxx ?

The code you linked was from 2001 are you sure the device is actually vulnerable?

Did you actually do any recon and check the IOS version #s?