Re: Cisco PSIRT response on IRM Demonstrates Multiple Cisco IOS

看板Bugtraq作者時間18年前 (2007/10/12 02:12), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串3/6 (看更多)
* Halvar Flake: > So in short, they are demonstrating that > > * IF you have console access > * AND the enable password > * AND you enable the debugger > > you can execute code ? > > So all in all, it's a complete non-issue ? Not completely. There are some configurations in which EXEC mode is not fully privileged. For instance, someone might be covertly capturing flows passing through the router. The ability to execute arbitrary code can be used to reveal that activity, and the router operator may not be authorized to do so. However, it seems to me that this is more or less a compliance thing, not a security issue.
文章代碼(AID): #173cU400 (Bugtraq)
討論串 (同標題文章)
文章代碼(AID): #173cU400 (Bugtraq)