Re: Pentesting Cisco 3640 devices via dialup ?

From: Evrim ULU (evrim@envy.com.tr)
Date: Fri Aug 02 2002 - 08:50:33 EDT


r00t@online.ie wrote:
>>From what I know so far, by default Cisco devices will disconnect a user from a
> dialup session after 3 unsucessfull authentication attempts, which means I need
> to manually re-iniate the dialup connection every 50-60 seconds. I feel this
> will be infeasable due to the time required to crack a single password.

> Could anyone suggest a way to automate this. Or could anyone who has pen-tested
> RAS servers over dialup specify an alternative method.

You may simply use wvdial or a chat script to automate this. Write a simply c
code and bind it with chat then read your wordlist and write results to a file
by redirecting the output. Heh simple?

Regards,

-- 
Evrim ULU
evrim@envy.com.tr / evrim@core.gen.tr
sysadm
http://www.core.gen.tr
----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/


This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:53:24 EDT