[113116] in North American Network Operators' Group
RE: Nipper and Cisco configuration results
daemon@ATHENA.MIT.EDU (Subba Rao)
Thu Apr 2 20:28:41 2009
Date: Thu, 2 Apr 2009 17:25:08 -0700 (PDT)
From: Subba Rao <castellan2004-nsm@yahoo.com>
To: nanog@nanog.org, =?iso-8859-1?Q?Jo=A2?= <jbfixurpc@gmail.com>
Reply-To: castellan2004-nsm@yahoo.com
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
I did not scan the routers yet with nmap.=A0 These results are from Nipper =
analysis.=A0 None of the access lists are showing "port 513" as Nipper is c=
omplaining about.=A0 The IOS version is 12.4
Subba Rao
--- On Thu, 4/2/09, Jo=A2 <jbfixurpc@gmail.com> wrote:
From: Jo=A2 <jbfixurpc@gmail.com>
Subject: RE: Nipper and Cisco configuration results
To: castellan2004-nsm@yahoo.com, nanog@nanog.org
Date: Thursday, April 2, 2009, 8:18 PM
What IOS version are you using? I don't see that behavior (rlogin/rsh) by
default, but I'm a few revisions behind on the latest. @ 12.2
I do see from the router:=20
RCMD-4-RSHPORTATTEMPT Attempted to connect to RSHELL from 192.168.1.52
from nmaps, but theres no response to the SYN packet of the attempting IP. =
I
think this has been
the case since w-a-y earlier versions of IOS for logging levels but not sur=
e
at which level.
Looks to only be logging an attempt, no session is made, sort of like a
firewall=20
just letting you know there was an attempt. The router gets the request but
it falls on deaf
ears, no one home. Unless perhaps theres some other sort of flag/bit that
can be presented to=20
open that connection(extremely doubtful) I don't believe theres any way to
connect.=20
Perhaps turning down your logging will prevent your testing program from
reporting a false positive?
I'd snoop/sniff the traffic and see if your router is SYN/ACK-ing the
request of rlogin/rsh to be sure.
<sarcasm>And make sure their not to close to one another, incase their usin=
g
undocumented=20
internal wireless units as a means to complete the connection, those Cisco
guys you know..</sarcasm>
Regards
Joe Blanchard
> -----Original Message-----
> From: Subba Rao [mailto:castellan2004-nsm@yahoo.com]=20
> Sent: Thursday, April 02, 2009 6:33 PM
> To: nanog@nanog.org
> Subject: Nipper and Cisco configuration results
>=20
> I am using Nipper for verifying my Cisco configuration.=A0=20
> Nipper is finding the "rlogin" service that is not in the=20
> configuration.=A0 I have searched the access lists and do not=20
> see it anywhere.=A0 The explanation by Nipper about this=20
> finding, "....Telnet protocol implemented by this=20
> service...." is confusing.=A0 Here is the Nipper's output:
>=20
> ______________________________
> Rlogin Service Settings
>=20
> The Rlogin service enables remote administrative access to a=20
> CLI on Cisco Router Devices.=A0 The Telnet protocol implemented=20
> by th service is simple and provides no encryption of the=20
> network communications between client and the server.=A0 This=20
> section details the Rlogin settings.
>=20
> Description=A0=A0 =A0=A0=A0 =A0=A0=A0 =A0=A0=A0 =A0Setting
> Rlogin Service=A0=A0 =A0=A0=A0 =A0=A0=A0 =A0Enabled
> Service TCP Port=A0=A0 =A0=A0=A0 =A0513
> ______________________________
>=20
> I have checked a few other routers where SSH was not enabled=20
> with the same results.
>=20
> Can someone explain why Nipper is saying "Rlogin is enabled"=20
> when I do not see it in the configuration file?=A0 Is there=20
> something else that I need to be looking at?
>=20
> Thank you in advance for any help.
>=20
> Subba Rao