Penetration Testing mailing list archives

Re: Cisco UBR920 cable router - SNMP to change telnet passwords?


From: Mathias Wegner <mwegner () cs oberlin edu>
Date: Tue, 26 Nov 2002 23:05:56 -0500

  ... does anyone know how to exploit SNMP read-write access to change or
retrieve the usernames/passwords protecting the telnet access?  I have SNMP
read-write access on the Cisco UBR920 cable router, so I could DoS it, but
I'm looking for further access.

download the MIBs from cisco, then read man snmpset?

It depends on the device whether or not the passwords are settable via SNMP.
In the case of the Cisco MIBs that I have for reference (mostly IOS 11-13
for 7xxx series hardware), I don't see it, but it's not a complete set of
MIBs and I haven't looked carefully.

mathias

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/


Current thread: