Do you like this site? Remember to share it to all your friends on Facebook and Twitter!

Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Sunday, October 20, 2019

Scanning active IPv4 addresses is difficult? Simpler than you think

It is always a best practice to keep full track of all IP address assignments inside our local area network. From time to time, it might also be a good idea for security purposes to check whether we have any hidden nodes inside our network.

To discover any node with active IP addresses inside our network, we might imagine that we must acquire powerful tools such as Cisco Prime Infrastructure before we can achieve anything. In fact, it might be much easier than you have expected. Let me show you how.

All you must have is a Windows 10 PC. I think that should be easy.

Wednesday, July 25, 2018

Bank lost 1 million US Dollars because of outdated routers

A recent news was about hackers hacked into a Russian bank because of outdated routers. When I saw the keyword “router”, I felt that I must dig further about what really happened.

What I have understood now


The victim is PIR Bank. One of the suspects is MoneyTaker. After the breach, PIR Bank hired company Group-IB to do the clean-ups, recovery, and investigating how the hackers got into their internal network.

Up to this moment, Group-IB disclosed hackers exploited the outdated routers of PIR Bank. The model of the routers was Cisco 800 series routers, which was already declared publicly that the End of Support date would be someday in Year 2016, by Cisco. The running Cisco IOS version was 12.4.

Friday, April 27, 2018

BGP Injection instead of Leak, my observation notes for MyEtherWallet incident

After reading articles by Doug Madory, and by Louis Poinsignon, here are some notes I observed and learned.

[What happened in this incident?]

Hackers somehow made some BGP routers of “eNet” to falsely announce that they own the following 5 IP subnets, which are indeed NOT belonging to “eNet”. The true owner is Amazon. To be more specific, they are for Amazon’s Route 53 DNS name resolution services.

  • 205.251.192.0/24
  • 205.251.193.0/24
  • 205.251.195.0/24
  • 205.251.197.0/24
  • 205.251.199.0/24

The registered domain server for domain “MyEtherWallet.com” is hosted on Amazon Route 53.

Hackers also somehow embedded malicious DNS server (or servers, I really don’t know) also inside service network of “eNet”.

After that, any affected clients’ DNS query for domain “MyEtherWallet.com” would hit hacker’s malicious DNS server. Of course, malicious DNS server would respond with false IP addresses, and those false IP addresses are indeed hacker’s own web servers.

At this moment, clients thought they were accessing “MyEtherWallet.com”, and they indeed were accessing hacker’s web servers.

Thursday, March 23, 2017

Cisco IOS/IOS XE Vulnerabiliy announced. Disable TELNET fast

This is just a short notice for you in case you are not aware of it. Cisco announced a vulnerability on Cisco IOS and IOS XE operating system. For short, you only have to disable incoming TELNET service onto the router itself to avoid this vulnerability. You can use Secure Shell (SSH) instead for remote management. SSH is not vulnerable in this problem.

The Jin-Dai Bridge (錦帶橋) in Dahu Park (大湖公園).
Taipei City, Taiwan.

Thursday, January 16, 2014

Fw: NTP Amplification Attacks Using CVE-2013-5211 | US-CERT

Screen capture of this alert page.

If you are running NTP Daemon, remember to upgrade to Version 4.2.7, or just disable “monlist” functionality.

Monday, January 13, 2014

What I have learned from this vulnerability: Undocumented Test Interface in Cisco Small Business Devices

"Two adult Guinea Pigs"
Photo taken by Sandos on Wikipedia.

Recently Eloi Vanderbecken discovered a security hole on his home Internet gateway. An undocumented TCP port 32764 is listened on this gateway. Intruders can use this hole to reset administrator’s password and then gain control of that Internet gateway. There is a post about how Eloi discovered this security hole and possible way for an intruder to gain control.

The brand of that Internet gateway is Linksys, which was once part of Cisco System but now is part of Belkin. That is why I look more carefully about this case. Cisco published this report about the discovered security hole.

I have learned many things about this case.

Thursday, June 6, 2013

New updates to be in Cisco ISE 1.2

Jih Yueh Shan Jing Leisure Farm (日月山景休閒農場).
Changhua County, Taiwan (Google Plus)

I summarize the key points I learned from this Q&A on Cisco web site.

[New Features]
  • MDM Integration
  • Device Feed Service
  • Doubling of Scale and Performance
  • Bootstrap Wizards

Tuesday, June 4, 2013

Cisco ISE Licensing in plain words

Feng-Le Sculpture Park (豐樂雕塑公園). Taichung City, Taiwan. (Google Plus)
Maybe I can summarize the description in this post as below.

No worry at all when exceeding device license count.

You can continue to manage and use ISE to authenticate and authorize network uses even when you run out of licenses count. The only inconveniences are the annoying warnings.
If you've reached limits of your current license, you also need to obtain new license. It could be completely new license, or an upgrade. ISE implements the concept of soft limits. So the system will throw "license enforcement" alarms (see http://www.cisco.com/en/US/docs/security/ise/1.0.4/user_guide/ise10_mnt.html).

Important note: ISE is not locked when license is overhelmed.

Monday, February 18, 2013

Video: Hacking Cisco Phones

Hackers demonstrated how to transform a Cisco phone (with vulnerabilities firmwares) into a audio recording station for spying without loosing phone's original capabilities.

Amazing!



Thursday, March 1, 2012

Resetting admin password to save my time re-installing Cisco ISE on VMware

Take a biking rest. From 20010616 花蓮

Because installing Cisco ISE 1.0 on VMware takes over 30 minutes, it is a natural choice to let the fresh installation run overnight.

When I come back in the morning, I found myself locked out even using default “admin” password “cisco”, when I try to log into the web interface. The error just showed something like “Account has been disabled …”.

Friday, October 22, 2010

Fwd: Choosing Different Passwords for Different Websites

I always wonder how to pick a good password, strong enough not to be guessed, and easy enough to be remembered, for my so many identities on the Internet.

I believe this post might be a good start!
Digital Inspiration - Choosing Different Passwords for Different Websites

Monday, August 30, 2010

Some Internet BGP routers reset neighbors within half an hour last Friday

We know when the BGP neighbor relation resets itself, the network would become disrupted before the new relation re-establishes. In the Intenet BGP scenario, this means a sudden outage of couple of minutes.

This was what happened last Friday (August 27, 2010, from 08:41 to 09:08 UTC)

Friday, August 13, 2010

TCP Denial of Service Vulnerability of Cisco IOS 15.1(2)T

If the IOS version your Cisco Router (or Switch) is 15.1(2)T and exposed publicly on the Internet, you might have to schedule an emergency IOS update this weekend.

Saturday, July 17, 2010

Thursday, January 21, 2010

Do not use these passwords, ever!

I received this post on Twitter. The topic is about "Popular Passwords" of a real (hacked) site as an example.

Since the post is published, if it happens to you that your password is one on the list, be sure to change it immediately!

Popular Posts