I've got a Cisco router here in front of me, the router is "reconditioned", but was received with a console password on it. Now, this is interesting for two reasons. As it's reconditioned (apparently) it shouldn't have a config on it anyway, and even so, whoever had it beforehand should really have cleared the config off.

More interestingly, the router is identifying itself with the name of a medical company. Interesting. So, rommon the box, get into it and do a sh start and see what we've got.

Username and password for the VPN service that said company uses, further identifying information for the company, firewall rules, SNMP server information, and, of course, the console password (in type 7, so easily breakable) for the router. What says that the same password is used on a number of bits of their kit?

It's not difficult - really. This is basic network security stuff. Just clear any configs off before the router gets taken away.

shadyron | General, Work, Geekery | 18 April, 11:05am

Leave a Comment







Comment XML feeds: RSS | Atom
October 2008
Sun Mon Tue Wed Thu Fri Sat
28 29 30 1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30 31 1

Category Cloud

rss
atom