It is always a best practice to keep full track of all IP address assignments inside our local area network. From time to time, it might also be a good idea for security purposes to check whether we have any hidden nodes inside our network.
To discover any node with active IP addresses inside our network, we might imagine that we must acquire powerful tools such as Cisco Prime Infrastructure before we can achieve anything. In fact, it might be much easier than you have expected. Let me show you how.
All you must have is a Windows 10 PC. I think that should be easy.
Do you like this site? Remember to share it to all your friends on Facebook and Twitter!
Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts
Sunday, October 20, 2019
Wednesday, July 25, 2018
Bank lost 1 million US Dollars because of outdated routers
A recent news was about hackers hacked into a Russian bank because of outdated routers. When I saw the keyword “router”, I felt that I must dig further about what really happened.
The victim is PIR Bank. One of the suspects is MoneyTaker. After the breach, PIR Bank hired company Group-IB to do the clean-ups, recovery, and investigating how the hackers got into their internal network.
Up to this moment, Group-IB disclosed hackers exploited the outdated routers of PIR Bank. The model of the routers was Cisco 800 series routers, which was already declared publicly that the End of Support date would be someday in Year 2016, by Cisco. The running Cisco IOS version was 12.4.
What I have understood now
The victim is PIR Bank. One of the suspects is MoneyTaker. After the breach, PIR Bank hired company Group-IB to do the clean-ups, recovery, and investigating how the hackers got into their internal network.
Up to this moment, Group-IB disclosed hackers exploited the outdated routers of PIR Bank. The model of the routers was Cisco 800 series routers, which was already declared publicly that the End of Support date would be someday in Year 2016, by Cisco. The running Cisco IOS version was 12.4.
Related Posts:
Security
Location:
Wanhua District, Taipei City, Taiwan 108
Friday, April 27, 2018
BGP Injection instead of Leak, my observation notes for MyEtherWallet incident
After reading articles by Doug Madory, and by Louis Poinsignon, here are some notes I observed and learned.
[What happened in this incident?]
Hackers somehow made some BGP routers of “eNet” to falsely announce that they own the following 5 IP subnets, which are indeed NOT belonging to “eNet”. The true owner is Amazon. To be more specific, they are for Amazon’s Route 53 DNS name resolution services.
The registered domain server for domain “MyEtherWallet.com” is hosted on Amazon Route 53.
Hackers also somehow embedded malicious DNS server (or servers, I really don’t know) also inside service network of “eNet”.
After that, any affected clients’ DNS query for domain “MyEtherWallet.com” would hit hacker’s malicious DNS server. Of course, malicious DNS server would respond with false IP addresses, and those false IP addresses are indeed hacker’s own web servers.
At this moment, clients thought they were accessing “MyEtherWallet.com”, and they indeed were accessing hacker’s web servers.
[What happened in this incident?]
Hackers somehow made some BGP routers of “eNet” to falsely announce that they own the following 5 IP subnets, which are indeed NOT belonging to “eNet”. The true owner is Amazon. To be more specific, they are for Amazon’s Route 53 DNS name resolution services.
- 205.251.192.0/24
- 205.251.193.0/24
- 205.251.195.0/24
- 205.251.197.0/24
- 205.251.199.0/24
The registered domain server for domain “MyEtherWallet.com” is hosted on Amazon Route 53.
Hackers also somehow embedded malicious DNS server (or servers, I really don’t know) also inside service network of “eNet”.
After that, any affected clients’ DNS query for domain “MyEtherWallet.com” would hit hacker’s malicious DNS server. Of course, malicious DNS server would respond with false IP addresses, and those false IP addresses are indeed hacker’s own web servers.
At this moment, clients thought they were accessing “MyEtherWallet.com”, and they indeed were accessing hacker’s web servers.
Location:
Wanhua District, Taipei City, Taiwan 108
Thursday, March 23, 2017
Cisco IOS/IOS XE Vulnerabiliy announced. Disable TELNET fast
This is just a short notice for you in case you are not aware of it. Cisco announced a vulnerability on Cisco IOS and IOS XE operating system. For short, you only have to disable incoming TELNET service onto the router itself to avoid this vulnerability. You can use Secure Shell (SSH) instead for remote management. SSH is not vulnerable in this problem.
![]() |
| The Jin-Dai Bridge (錦帶橋) in Dahu Park (大湖公園). Taipei City, Taiwan. |
Related Posts:
Security
Location:
Wanhua District, Taipei City, Taiwan 108
Tuesday, May 12, 2015
Thursday, January 16, 2014
Fw: NTP Amplification Attacks Using CVE-2013-5211 | US-CERT
![]() |
| Screen capture of this alert page. |
If you are running NTP Daemon, remember to upgrade to Version 4.2.7, or just disable “monlist” functionality.
Related Posts:
Security
Location:
Wanhua District, Taipei City, Taiwan 108
Monday, January 13, 2014
What I have learned from this vulnerability: Undocumented Test Interface in Cisco Small Business Devices
![]() |
| "Two adult Guinea Pigs" Photo taken by Sandos on Wikipedia. |
Recently Eloi Vanderbecken discovered a security hole on his home Internet gateway. An undocumented TCP port 32764 is listened on this gateway. Intruders can use this hole to reset administrator’s password and then gain control of that Internet gateway. There is a post about how Eloi discovered this security hole and possible way for an intruder to gain control.
The brand of that Internet gateway is Linksys, which was once part of Cisco System but now is part of Belkin. That is why I look more carefully about this case. Cisco published this report about the discovered security hole.
I have learned many things about this case.
Related Posts:
Security
Location:
Wanhua District, Taipei City, Taiwan 108
Thursday, June 6, 2013
New updates to be in Cisco ISE 1.2
![]() |
| Jih Yueh Shan Jing Leisure Farm (日月山景休閒農場). Changhua County, Taiwan (Google Plus) |
I summarize the key points I learned from this Q&A on Cisco web site.
[New Features]
- MDM Integration
- Device Feed Service
- Doubling of Scale and Performance
- Bootstrap Wizards
Tuesday, June 4, 2013
Cisco ISE Licensing in plain words
![]() |
| Feng-Le Sculpture Park (豐樂雕塑公園). Taichung City, Taiwan. (Google Plus) |
No worry at all when exceeding device license count.
You can continue to manage and use ISE to authenticate and authorize network uses even when you run out of licenses count. The only inconveniences are the annoying warnings.
If you've reached limits of your current license, you also need to obtain new license. It could be completely new license, or an upgrade. ISE implements the concept of soft limits. So the system will throw "license enforcement" alarms (see http://www.cisco.com/en/US/docs/security/ise/1.0.4/user_guide/ise10_mnt.html).
Important note: ISE is not locked when license is overhelmed.
Monday, February 18, 2013
Video: Hacking Cisco Phones
Hackers demonstrated how to transform a Cisco phone (with vulnerabilities firmwares) into a audio recording station for spying without loosing phone's original capabilities.
Amazing!
Amazing!
Related Posts:
Cisco Products,
Security,
Unified Communications,
VoIP
Monday, February 4, 2013
My study notes on Cisco ASA 1000V video: "See the Cisco ASA 1000V in Action"
Here are the points I learned from this video. Have fun with it!
Related Posts:
Cisco Products,
Data Center,
Security,
Virtualization
Thursday, March 1, 2012
Resetting admin password to save my time re-installing Cisco ISE on VMware
| Take a biking rest. From 20010616 花蓮 |
Because installing Cisco ISE 1.0 on VMware takes over 30 minutes, it is a natural choice to let the fresh installation run overnight.
When I come back in the morning, I found myself locked out even using default “admin” password “cisco”, when I try to log into the web interface. The error just showed something like “Account has been disabled …”.
Related Posts:
BYOD,
Cisco ISE,
Cisco Products,
Lab Tips,
Security
Friday, October 22, 2010
Fwd: Choosing Different Passwords for Different Websites
I always wonder how to pick a good password, strong enough not to be guessed, and easy enough to be remembered, for my so many identities on the Internet.
I believe this post might be a good start!
Digital Inspiration - Choosing Different Passwords for Different Websites
I believe this post might be a good start!
Digital Inspiration - Choosing Different Passwords for Different Websites
Location:
Wanhua District, Taipei City, Taiwan 108
Wednesday, September 1, 2010
Monday, August 30, 2010
Some Internet BGP routers reset neighbors within half an hour last Friday
We know when the BGP neighbor relation resets itself, the network would become disrupted before the new relation re-establishes. In the Intenet BGP scenario, this means a sudden outage of couple of minutes.
This was what happened last Friday (August 27, 2010, from 08:41 to 09:08 UTC)
This was what happened last Friday (August 27, 2010, from 08:41 to 09:08 UTC)
Location:
Wanhua District, Taipei City, Taiwan 108
Friday, August 13, 2010
TCP Denial of Service Vulnerability of Cisco IOS 15.1(2)T
If the IOS version your Cisco Router (or Switch) is 15.1(2)T and exposed publicly on the Internet, you might have to schedule an emergency IOS update this weekend.
Related Posts:
Security,
Timely Info
Location:
Wanhua District, Taipei City, Taiwan 108
Saturday, July 17, 2010
How to look up the "default passwords" on the web?
Youtube Video: "Learn the Default Password for Every Network Router!"
Related Posts:
Security
Location:
Wanhua District, Taipei City, Taiwan 108
Thursday, January 21, 2010
Do not use these passwords, ever!
I received this post on Twitter. The topic is about "Popular Passwords" of a real (hacked) site as an example.
Since the post is published, if it happens to you that your password is one on the list, be sure to change it immediately!
Since the post is published, if it happens to you that your password is one on the list, be sure to change it immediately!
Related Posts:
Security
Location:
Wanhua District, Taipei City, Taiwan
Subscribe to:
Posts (Atom)
Popular Posts
-
CCNA Exploration 4.0, Semester 4, "Dual Stack IPv6 and IPv4 configuration " Packet Tracer 5.0 practice file (CNA-04-006). ...
-
I created this practice to test the Packet Tracer 5.3 features of BGP.
-
Fire-like Kapok blossoms in Taipei City, Taiwan To show the reserved VLAN numbers on both IOS and NX-OS, the common command is: sho...
-
We hear a lot of directions when we are talking about Data Center technologies: Northbound, Southbound, and even Eastbound/Westbound. What d...
-
One working switch port on my Cisco Catalyst 2950 suddenly went down by itself! Of course, my phone rang when I was having dinner, and the...





.jpg)

