Last year, at HAR2009, there was a presentation about reverse engineering switch firmware. The researchers had found there is a backdoor password in some Accton-based switches (which are sold by several manufacturers, such as 3Com). It was a very nice piece of reverse engineering.
After the presentation I occasionally checked the manufacturer website to see when a patch would show up, but it never did. In fact the vulnerability was never picked up by the security community. I have a vulnerable device (a 3com 3812 gigabit switch) and started to complain. So here it is, more than a year later, a >365-day exploit.
It's hard to say which switches are vulnerable and which are not. It certainly doesn't mean that if you have a 3Com device it is vulnerable, but you can check yourself using the exploit code. Vulnerability scanners will start detecting it soon and time will tell I guess. In the meantime, you could disable all management interfaces and manage your switches using a console cable.
Showing posts with label HAR 2009. Show all posts
Showing posts with label HAR 2009. Show all posts
Thursday, September 2, 2010
Tuesday, August 25, 2009
HAR 2009 talk references
I promised to put up some nice ‘further reading’ material for those who have seen my HAR talk. So here it is:
LM/NTLM
Disabling the LM hash
Free Rainbow Tables and download site
Passing the hash
The original post from 1997 by Paul Ashton
Core Pass-The-Hash toolkit
Tenable SMBshell
Token stealing
Luke Jennings research page
A tutorial on the tool by CG
You can see the video of my talk here or download it here or here.
LM/NTLM
Disabling the LM hash
Free Rainbow Tables and download site
Passing the hash
The original post from 1997 by Paul Ashton
Core Pass-The-Hash toolkit
Tenable SMBshell
Token stealing
Luke Jennings research page
A tutorial on the tool by CG
You can see the video of my talk here or download it here or here.
Saturday, August 15, 2009
RevDump v0.2 release
This is my tool to dump password stored using reversible encryption. You can download it here. Enjoy your stay at HAR.
Monday, July 6, 2009
Speaking at HAR 2009
The program for HAR 2009 was publicly announced a couple of days ago and I’m on the speakers list. My talk is called 'How we break into domains' and I will go over the steps I usually take when breaking into Windows domains. I have an hour for my talk, so I should be able to cover the technical details as well. Of course, I will also be presenting some new stuff I’ve been working on.
I had a lot of fun at the two previous events (HAL 2001 and WTH 2005) and am glad I can contribute a talk this year. See you all at HAR!
I had a lot of fun at the two previous events (HAL 2001 and WTH 2005) and am glad I can contribute a talk this year. See you all at HAR!
Subscribe to:
Posts (Atom)