Penetration Testing mailing list archives

Re: Pentesting Cisco 3640 devices via dialup ?


From: Evrim ULU <evrim () envy com tr>
Date: Fri, 02 Aug 2002 15:50:33 +0300

r00t () online ie wrote:
From what I know so far, by default Cisco devices will disconnect a user from a
dialup session after 3 unsucessfull authentication attempts, which means I need to manually re-iniate the dialup connection every 50-60 seconds. I feel this will be infeasable due to the time required to crack a single password.


Could anyone suggest a way to automate this. Or could anyone who has pen-tested RAS servers over dialup specify an alternative method.

You may simply use wvdial or a chat script to automate this. Write a simply c code and bind it with chat then read your wordlist and write results to a file by redirecting the output. Heh simple?

Regards,
--
Evrim ULU
evrim () envy com tr / evrim () core gen tr
sysadm
http://www.core.gen.tr


----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/


Current thread: