Advertisement
FailSecurityBR

Exploitation of Cisco Security | #FailSecBR

Sep 11th, 2012
478
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.28 KB | None | 0 0
  1. $$$$$$$$\ $$\ $$\ $$$$$$\ $$$$$$$\ $$$$$$$\
  2. $$ _____| \__|$$ |$$ __$$\ $$ __$$\ $$ __$$\
  3. $$ | $$$$$$\ $$\ $$ |$$ / \__| $$$$$$\ $$$$$$$\ $$ | $$ |$$ | $$ |
  4. $$$$$\ \____$$\ $$ |$$ |\$$$$$$\ $$ __$$\ $$ _____|$$$$$$$\ |$$$$$$$ |
  5. $$ __|$$$$$$$ |$$ |$$ | \____$$\ $$$$$$$$ |$$ / $$ __$$\ $$ __$$<
  6. $$ | $$ __$$ |$$ |$$ |$$\ $$ |$$ ____|$$ | $$ | $$ |$$ | $$ |
  7. $$ | \$$$$$$$ |$$ |$$ |\$$$$$$ |\$$$$$$$\ \$$$$$$$\ $$$$$$$ |$$ | $$ |
  8. \__| \_______|\__|\__| \______/ \_______| \_______|\_______/ \__| \__|
  9.  
  10. =================================================================================================================================
  11. CISCO Security ... are you really sec ?
  12. Site: www.cisco.com
  13. Members Login: https://sso.cisco.com/autho/forms/CDClogin.htm (Não loga com os dados postados)
  14. Payloaded: Category_Id=1 and App_Id=106
  15. Falha: Jive Servlet Exploitation
  16. Table: User_Info
  17. Jive version: Jive SBS | E-mail:4.5.4.0
  18. =================================================================================================================================
  19.  
  20. Dumps →
  21.  
  22. Create tables: Function | TBL_BY_FUNC
  23.  
  24. INSERT INTO FUNCTION(Function_Id, Function_Name)
  25. VALUES(302,'Cisco:CW2000:Config Editor');
  26. INSERT INTO TBL_BY_FUNC(Table_Id,Table_Name,Function_Id)
  27. VALUES(349, 'CALL_MANAGERS', 2);
  28. INSERT INTO TBL_BY_FUNC(Table_Id,Table_Name,Function_Id)
  29. VALUES(350, 'CALL_MANAGER_GROUPS', 2);
  30. INSERT INTO TBL_BY_FUNC (Table_Id,Table_Name,Function_Id)
  31. VALUES (512, 'IGXBPXMGX_SW', 103);
  32. INSERT INTO TBL_BY_FUNC (Table_Id,Table_Name,Function_Id)
  33. VALUES (1000, 'CFGEDIT_MRU_FILES', 302);
  34. INSERT INTO TBL_BY_FUNC (Table_Id,Table_Name,Function_Id)
  35. VALUES (1001, 'CFG_JOBS', 302);
  36. INSERT INTO TBL_BY_FUNC (Table_Id,Table_Name,Function_Id)
  37. VALUES (802, 'RTT_MON_SUP',2);
  38.  
  39. Create tables: USER_VIEW_PERMISSION | USER_GROUP_DEF | USER_GROUP_MEMBERSHIP
  40.  
  41. Insert into TBL_BY_FUNC (Table_Id,Table_Name,Function_Id) VALUES
  42. (1009,'NSHOW_REPORT',106);
  43. Insert into TBL_BY_FUNC (Table_Id,Table_Name,Function_Id) VALUES
  44. (1010,'REPORTID_TO_DEVICEID',106);
  45. Insert into TBL_BY_FUNC (Table_Id,Table_Name,Function_Id) VALUES
  46. (1011,'REPORTID_TO_CMDSETID',106);
  47. Insert into TBL_BY_FUNC (Table_Id,Table_Name,Function_Id) VALUES
  48. (1012,'REPORTID_TO_CMD',106);
  49. Insert into TBL_BY_FUNC (Table_Id,Table_Name,Function_Id) VALUES
  50. (1013,'USER_VIEW_PERMISSION',106);
  51. Insert into TBL_BY_FUNC (Table_Id,Table_Name,Function_Id) VALUES
  52. (1014,'USER_GROUP_DEF',106);
  53. Insert into TBL_BY_FUNC (Table_Id,Table_Name,Function_Id) VALUES
  54. (1015,'USER_GROUP_MEMBERSHIP',106);
  55.  
  56. =================================================================================================================================
  57. Login: CSCadmin
  58. Password: Not Found !
  59. E-Mail: infosec@cisco.com
  60.  
  61. Whois Information:
  62. Domain Name.......... cisco.com
  63. Creation Date........ 1987-05-14
  64. Registration Date.... 2011-04-06
  65. Expiry Date.......... 2013-05-16
  66. Organisation Name.... Cisco Technology, Inc.
  67. Organisation Address. 170 W. Tasman Drive
  68. Organisation Address.
  69. Organisation Address.
  70. Organisation Address. San Jose
  71. Organisation Address. 95134
  72. Organisation Address. CA
  73. Organisation Address. UNITED STATES
  74.  
  75. Admin Name........... Info Sec
  76. Admin Address........ 170 West Tasman Drive
  77. Admin Address........
  78. Admin Address........
  79. Admin Address. San Jose
  80. Admin Address........ 95134
  81. Admin Address........ CA
  82. Admin Address........ UNITED STATES
  83. Admin Email.......... infosec@cisco.com
  84. Admin Phone.......... +1.4085273842
  85. Admin Fax............ +1.4085264575
  86.  
  87. Tech Name............ Network Services
  88. Tech Address......... 170 W. Tasman Drive
  89. Tech Address.........
  90. Tech Address.........
  91. Tech Address......... San Jose
  92. Tech Address......... 95134
  93. Tech Address......... CA
  94. Tech Address......... UNITED STATES
  95. Tech Email........... dns-info@cisco.com
  96. Tech Phone........... +1.4085279223
  97. Tech Fax............. +1.4085267373
  98. Name Server.......... NS1.CISCO.COM
  99. Name Server.......... NS2.CISCO.COM
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement