EquationGroup Tool Leak – ExtraBacon Demo
xorcatt.wordpress.com
xorcatt.wordpress.com
For what I could tell, it looked like Cisco use to have a full independent OS (ios) and when they switched to Intel hardware, it was easier for them to just build a shim layer between Linux and their OS so they could run on cheaper/newer hardware without a massive rewrite.
Anyway, that guy responsibly disclosed and his exploit was patched, but it did give full access to everything, including the ability to create new routes and filters that wouldn't even be visible from within ios.
BM-2cXe6wAT7yTgoxGCpDMmdWq2xxWcdmL3Ek
[1] https://bitmessage.org/wiki/Main_Page
[2] https://en.bitcoin.it/wiki/OP_RETURNThe same person seems to have sent several others, including one listing cryptome's email address and several rude[1] and vulger[2] messages. Charming.
0. https://blockchain.info/tx/8974f9ba743f073bfe18a2f1505ad9934...
1. https://blockchain.info/tx/8e1e3cda1caf23e2f3071595efdbc794b...
2. https://blockchain.info/tx/527202542acc7d87a763bafa5fc66a0a9...
My understanding is this exploit disables password authentication and allows you to access the device. A seperate command allows you to re-enable it.
Would this re-enabling kill your current connection? Is the password later needed to change settings on the router (like if you typed sudo and are forced to re-authenticate)?
I guess the name comes from enabling admin functionality, but I don't know why Cisco didn't call the command admin. Anyway, this enable is different from enabling/disabling the login authentication.
If you used ExtraBacon to clear the login user/password you would get a basic shell on connection. This would open at least 2 options to you as an attacker-1) using a local exploit to become an enabled user and 2) you can now send traffic to ALL the networks that the firewall/router knows about-for example, a non-internet connected management network that might be filled with never upgraded KVM/OOB control equipment.
> XORcat 18 minutes ago [dead] [-]
> In my lab, re-enabling did not kill the current connection, so it could be a very quick switch flick, login, revert to try and avoid detection.
It would be interesting to see how various stylistic fingerprints analysis points survive lexical washing, a la https://freedom-to-tinker.com/blog/aylin/anonymous-programme...
Here is another exploit in ruby, https://github.com/jduck/addjsif/blob/master/add_js_interfac...
What counts in the real world is that it gets the job done, unfortunately no time for fancy pythonic delicacies or experiments in functional coding paradigms.
Sorry for the little rant and nothing personal, I just find critizicing other people's code without considering the constraints under it was created an extremely annoying habit among my fellow coders.