nanog mailing list archives

Re: Warning: Cisco RW community backdoor.


From: <jlewis () lewis org>
Date: Tue, 27 Feb 2001 19:11:58 -0500 (EST)


On Mon, 26 Feb 2001, David Schwartz wrote:

While I agree that "public" and "private" are "wellknowns," in most
implementations, they at least show up in the code.  Cisco chose to hide
this one where it would not show up in the code.  That IMHO is a very bad
thing and does bad things to my confidence level in Cisco.

    Do a "show snmp group" from an enabled console prompt. It does show.

On some routers that have the backdoor, "show snmp group" isn't even a
valid command.

-- 
----------------------------------------------------------------------
 Jon Lewis *jlewis () lewis org*|  I route
 System Administrator        |  therefore you are
 Atlantic Net                |
_________ http://www.lewis.org/~jlewis/pgp for PGP public key_________





Current thread: