[113118] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

RE: Nipper and Cisco configuration results

daemon@ATHENA.MIT.EDU (=?iso-8859-1?B?Sm+i?=)
Thu Apr 2 21:12:45 2009

From: =?iso-8859-1?B?Sm+i?= <jbfixurpc@gmail.com>
To: <castellan2004-nsm@yahoo.com>,
	<nanog@nanog.org>
Date: Thu, 2 Apr 2009 21:09:01 -0400
In-Reply-To: <885753.34347.qm@web30803.mail.mud.yahoo.com>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org

This is a multi-part message in MIME format.

------=_NextPart_000_00B9_01C9B3D7.41978780
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable


Subba,

Sorry, perhaps I am confussed about the nature of your question? Did you
have acls up for logging these attempts and they weren't logged? or are =
you
asking for help from the Nipper portion of this as to why its reporting =
this
item.=20
With my logging turned up to debug I do see entries about =
RSHPORTATTEMPTs,
but I suspect theres a lesser logging
for that based on facility.
At 12.3 I don't see any sort of problem with an open Rlogin/Rsh, and I =
have
tested this on a router running a very minimal configuration. Hands out =
DHCP
and does OSPF, but that's about it.=20

Can you clarify your problem a bit?=20

-Joe

=20


________________________________

	From: Subba Rao [mailto:castellan2004-nsm@yahoo.com]=20
	Sent: Thursday, April 02, 2009 8:25 PM
	To: nanog@nanog.org; Jo=A2
	Subject: RE: Nipper and Cisco configuration results
=09
=09
	I did not scan the routers yet with nmap.  These results are from
Nipper analysis.  None of the access lists are showing "port 513" as =
Nipper
is complaining about.  The IOS version is 12.4
=09
	Subba Rao
=09
=09
	--- On Thu, 4/2/09, Jo=A2 <jbfixurpc@gmail.com> wrote:
=09


		From: Jo=A2 <jbfixurpc@gmail.com>
		Subject: RE: Nipper and Cisco configuration results
		To: castellan2004-nsm@yahoo.com, nanog@nanog.org
		Date: Thursday, April 2, 2009, 8:18 PM
	=09
	=09
		What IOS version are you using? I don't see that behavior
(rlogin/rsh) by
		default, but I'm a few revisions behind on the latest. @
12.2
		I do see from the router:=20
		RCMD-4-RSHPORTATTEMPT Attempted to connect to RSHELL from
192.168.1.52
		from nmaps, but theres no response to the SYN packet of the
attempting IP. I
		think this has been
		the case since w-a-y earlier versions of IOS for logging
levels but not sure
		at which level.
		Looks to only be logging an attempt, no session is made,
sort of like a
		firewall=20
		just letting you know there was an attempt. The router gets
the request but
		it falls on deaf
		ears, no one home. Unless perhaps theres some other sort of
flag/bit that
		can be presented to=20
		open that connection(extremely doubtful) I don't believe
theres any way to
		connect.=20
	=09
		Perhaps turning down your logging will prevent your testing
program from
		reporting a false positive?
		I'd snoop/sniff the traffic and see if your router is
SYN/ACK-ing the
		request of rlogin/rsh to be sure.
	=09
		<sarcasm>And make sure their not to close to one another,
incase their using
		undocumented=20
		internal wireless units as a means to complete the
connection, those Cisco
		guys you know..</sarcasm>
	=09
		Regards
		Joe Blanchard
	=09
		> -----Original Message-----
		> From: Subba Rao [mailto:castellan2004-nsm@yahoo.com]=20
		> Sent: Thursday, April 02, 2009 6:33 PM
		> To: nanog@nanog.org
		> Subject: Nipper and Cisco configuration results
		>=20
		> I am using Nipper for verifying my Cisco configuration. =20
		> Nipper is finding the "rlogin" service that is not in the=20
		> configuration.  I have searched the access lists and do
not=20
		> see it anywhere.  The explanation by Nipper about this=20
		> finding, "....Telnet protocol implemented by this=20
		> service...." is confusing.  Here is the Nipper's output:
		>=20
		> ______________________________
		> Rlogin Service Settings
		>=20
		> The Rlogin service enables remote administrative access to
a=20
		> CLI on Cisco Router Devices.  The Telnet protocol
implemented=20
		> by th service is simple and provides no encryption of the=20
		> network communications between client and the server.
This=20
		> section details the Rlogin settings.
		>=20
		> Description                Setting
		> Rlogin Service            Enabled
		> Service TCP Port        513
		> ______________________________
		>=20
		> I have checked a few other routers where SSH was not
enabled=20
		> with the same results.
		>=20
		> Can someone explain why Nipper is saying "Rlogin is
enabled"=20
		> when I do not see it in the configuration file?  Is there=20
		> something else that I need to be looking at?
		>=20
		> Thank you in advance for any help.
		>=20
		> Subba Rao
	=09
	=09

	=09


------=_NextPart_000_00B9_01C9B3D7.41978780--



home help back first fref pref prev next nref lref last post