FailSecurityBR

Exploitation of Cisco Security | #FailSecBR

Sep 11th, 2012
548
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.28 KB | None | 0 0
  1. $$$$$$$$\ $$\ $$\ $$$$$$\ $$$$$$$\ $$$$$$$\
  2. $$ _____| \__|$$ |$$ __$$\ $$ __$$\ $$ __$$\
  3. $$ | $$$$$$\ $$\ $$ |$$ / \__| $$$$$$\ $$$$$$$\ $$ | $$ |$$ | $$ |
  4. $$$$$\ \____$$\ $$ |$$ |\$$$$$$\ $$ __$$\ $$ _____|$$$$$$$\ |$$$$$$$ |
  5. $$ __|$$$$$$$ |$$ |$$ | \____$$\ $$$$$$$$ |$$ / $$ __$$\ $$ __$$<
  6. $$ | $$ __$$ |$$ |$$ |$$\ $$ |$$ ____|$$ | $$ | $$ |$$ | $$ |
  7. $$ | \$$$$$$$ |$$ |$$ |\$$$$$$ |\$$$$$$$\ \$$$$$$$\ $$$$$$$ |$$ | $$ |
  8. \__| \_______|\__|\__| \______/ \_______| \_______|\_______/ \__| \__|
  9.  
  10. =================================================================================================================================
  11. CISCO Security ... are you really sec ?
  12. Site: www.cisco.com
  13. Members Login: https://sso.cisco.com/autho/forms/CDClogin.htm (Não loga com os dados postados)
  14. Payloaded: Category_Id=1 and App_Id=106
  15. Falha: Jive Servlet Exploitation
  16. Table: User_Info
  17. Jive version: Jive SBS | E-mail:4.5.4.0
  18. =================================================================================================================================
  19.  
  20. Dumps →
  21.  
  22. Create tables: Function | TBL_BY_FUNC
  23.  
  24. INSERT INTO FUNCTION(Function_Id, Function_Name)
  25. VALUES(302,'Cisco:CW2000:Config Editor');
  26. INSERT INTO TBL_BY_FUNC(Table_Id,Table_Name,Function_Id)
  27. VALUES(349, 'CALL_MANAGERS', 2);
  28. INSERT INTO TBL_BY_FUNC(Table_Id,Table_Name,Function_Id)
  29. VALUES(350, 'CALL_MANAGER_GROUPS', 2);
  30. INSERT INTO TBL_BY_FUNC (Table_Id,Table_Name,Function_Id)
  31. VALUES (512, 'IGXBPXMGX_SW', 103);
  32. INSERT INTO TBL_BY_FUNC (Table_Id,Table_Name,Function_Id)
  33. VALUES (1000, 'CFGEDIT_MRU_FILES', 302);
  34. INSERT INTO TBL_BY_FUNC (Table_Id,Table_Name,Function_Id)
  35. VALUES (1001, 'CFG_JOBS', 302);
  36. INSERT INTO TBL_BY_FUNC (Table_Id,Table_Name,Function_Id)
  37. VALUES (802, 'RTT_MON_SUP',2);
  38.  
  39. Create tables: USER_VIEW_PERMISSION | USER_GROUP_DEF | USER_GROUP_MEMBERSHIP
  40.  
  41. Insert into TBL_BY_FUNC (Table_Id,Table_Name,Function_Id) VALUES
  42. (1009,'NSHOW_REPORT',106);
  43. Insert into TBL_BY_FUNC (Table_Id,Table_Name,Function_Id) VALUES
  44. (1010,'REPORTID_TO_DEVICEID',106);
  45. Insert into TBL_BY_FUNC (Table_Id,Table_Name,Function_Id) VALUES
  46. (1011,'REPORTID_TO_CMDSETID',106);
  47. Insert into TBL_BY_FUNC (Table_Id,Table_Name,Function_Id) VALUES
  48. (1012,'REPORTID_TO_CMD',106);
  49. Insert into TBL_BY_FUNC (Table_Id,Table_Name,Function_Id) VALUES
  50. (1013,'USER_VIEW_PERMISSION',106);
  51. Insert into TBL_BY_FUNC (Table_Id,Table_Name,Function_Id) VALUES
  52. (1014,'USER_GROUP_DEF',106);
  53. Insert into TBL_BY_FUNC (Table_Id,Table_Name,Function_Id) VALUES
  54. (1015,'USER_GROUP_MEMBERSHIP',106);
  55.  
  56. =================================================================================================================================
  57. Login: CSCadmin
  58. Password: Not Found !
  59.  
  60. Whois Information:
  61. Domain Name.......... cisco.com
  62. Creation Date........ 1987-05-14
  63. Registration Date.... 2011-04-06
  64. Expiry Date.......... 2013-05-16
  65. Organisation Name.... Cisco Technology, Inc.
  66. Organisation Address. 170 W. Tasman Drive
  67. Organisation Address.
  68. Organisation Address.
  69. Organisation Address. San Jose
  70. Organisation Address. 95134
  71. Organisation Address. CA
  72. Organisation Address. UNITED STATES
  73.  
  74. Admin Name........... Info Sec
  75. Admin Address........ 170 West Tasman Drive
  76. Admin Address........
  77. Admin Address........
  78. Admin Address. San Jose
  79. Admin Address........ 95134
  80. Admin Address........ CA
  81. Admin Address........ UNITED STATES
  82. Admin Email.......... [email protected]
  83. Admin Phone.......... +1.4085273842
  84. Admin Fax............ +1.4085264575
  85.  
  86. Tech Name............ Network Services
  87. Tech Address......... 170 W. Tasman Drive
  88. Tech Address.........
  89. Tech Address.........
  90. Tech Address......... San Jose
  91. Tech Address......... 95134
  92. Tech Address......... CA
  93. Tech Address......... UNITED STATES
  94. Tech Email........... [email protected]
  95. Tech Phone........... +1.4085279223
  96. Tech Fax............. +1.4085267373
  97. Name Server.......... NS1.CISCO.COM
  98. Name Server.......... NS2.CISCO.COM
Advertisement
Add Comment
Please, Sign In to add comment