[113119] in North American Network Operators' Group
RE: Nipper and Cisco configuration results
daemon@ATHENA.MIT.EDU (Subba Rao)
Thu Apr 2 21:45:39 2009
Date: Thu, 2 Apr 2009 18:43:27 -0700 (PDT)
From: Subba Rao <castellan2004-nsm@yahoo.com>
To: nanog@nanog.org, =?iso-8859-1?Q?Jo=A2?= <jbfixurpc@gmail.com>
Reply-To: castellan2004-nsm@yahoo.com
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
Joe,
Thank you for replying.=A0 I am asking about the Nipper complaint.=A0 Why i=
s Nipper report saying "Rlogin" is enabled when I don't see any ACL in the =
config?
Using IOS 12.4
Cheers,
Subba Rao
--- On Thu, 4/2/09, Jo=A2 <jbfixurpc@gmail.com> wrote:
From: Jo=A2 <jbfixurpc@gmail.com>
Subject: RE: Nipper and Cisco configuration results
To: castellan2004-nsm@yahoo.com, nanog@nanog.org
Date: Thursday, April 2, 2009, 9:09 PM
Subba,
Sorry, perhaps I am confussed about the nature of your question? Did you
have acls up for logging these attempts and they weren't logged? or are you
asking for help from the Nipper portion of this as to why its reporting thi=
s
item.=20
With my logging turned up to debug I do see entries about RSHPORTATTEMPTs,
but I suspect theres a lesser logging
for that based on facility.
At 12.3 I don't see any sort of problem with an open Rlogin/Rsh, and I have
tested this on a router running a very minimal configuration. Hands out DHC=
P
and does OSPF, but that's about it.=20
Can you clarify your problem a bit?=20
-Joe
=20
________________________________
=A0=A0=A0 From: Subba Rao [mailto:castellan2004-nsm@yahoo.com]=20
=A0=A0=A0 Sent: Thursday, April 02, 2009 8:25 PM
=A0=A0=A0 To: nanog@nanog.org; Jo=A2
=A0=A0=A0 Subject: RE: Nipper and Cisco configuration results
=A0=A0=A0=20
=A0=A0=A0=20
=A0=A0=A0 I did not scan the routers yet with nmap.=A0 These results are fr=
om
Nipper analysis.=A0 None of the access lists are showing "port 513" as Nipp=
er
is complaining about.=A0 The IOS version is 12.4
=A0=A0=A0=20
=A0=A0=A0 Subba Rao
=A0=A0=A0=20
=A0=A0=A0=20
=A0=A0=A0 --- On Thu, 4/2/09, Jo=A2 <jbfixurpc@gmail.com> wrote:
=A0=A0=A0=20
=A0=A0=A0 =A0=A0=A0 From: Jo=A2 <jbfixurpc@gmail.com>
=A0=A0=A0 =A0=A0=A0 Subject: RE: Nipper and Cisco configuration results
=A0=A0=A0 =A0=A0=A0 To: castellan2004-nsm@yahoo.com, nanog@nanog.org
=A0=A0=A0 =A0=A0=A0 Date: Thursday, April 2, 2009, 8:18 PM
=A0=A0=A0 =A0=A0=A0=20
=A0=A0=A0 =A0=A0=A0=20
=A0=A0=A0 =A0=A0=A0 What IOS version are you using? I don't see that behavi=
or
(rlogin/rsh) by
=A0=A0=A0 =A0=A0=A0 default, but I'm a few revisions behind on the latest. =
@
12.2
=A0=A0=A0 =A0=A0=A0 I do see from the router:=20
=A0=A0=A0 =A0=A0=A0 RCMD-4-RSHPORTATTEMPT Attempted to connect to RSHELL fr=
om
192.168.1.52
=A0=A0=A0 =A0=A0=A0 from nmaps, but theres no response to the SYN packet of=
the
attempting IP. I
=A0=A0=A0 =A0=A0=A0 think this has been
=A0=A0=A0 =A0=A0=A0 the case since w-a-y earlier versions of IOS for loggin=
g
levels but not sure
=A0=A0=A0 =A0=A0=A0 at which level.
=A0=A0=A0 =A0=A0=A0 Looks to only be logging an attempt, no session is made=
,
sort of like a
=A0=A0=A0 =A0=A0=A0 firewall=20
=A0=A0=A0 =A0=A0=A0 just letting you know there was an attempt. The router =
gets
the request but
=A0=A0=A0 =A0=A0=A0 it falls on deaf
=A0=A0=A0 =A0=A0=A0 ears, no one home. Unless perhaps theres some other sor=
t of
flag/bit that
=A0=A0=A0 =A0=A0=A0 can be presented to=20
=A0=A0=A0 =A0=A0=A0 open that connection(extremely doubtful) I don't believ=
e
theres any way to
=A0=A0=A0 =A0=A0=A0 connect.=20
=A0=A0=A0 =A0=A0=A0=20
=A0=A0=A0 =A0=A0=A0 Perhaps turning down your logging will prevent your tes=
ting
program from
=A0=A0=A0 =A0=A0=A0 reporting a false positive?
=A0=A0=A0 =A0=A0=A0 I'd snoop/sniff the traffic and see if your router is
SYN/ACK-ing the
=A0=A0=A0 =A0=A0=A0 request of rlogin/rsh to be sure.
=A0=A0=A0 =A0=A0=A0=20
=A0=A0=A0 =A0=A0=A0 <sarcasm>And make sure their not to close to one anothe=
r,
incase their using
=A0=A0=A0 =A0=A0=A0 undocumented=20
=A0=A0=A0 =A0=A0=A0 internal wireless units as a means to complete the
connection, those Cisco
=A0=A0=A0 =A0=A0=A0 guys you know..</sarcasm>
=A0=A0=A0 =A0=A0=A0=20
=A0=A0=A0 =A0=A0=A0 Regards
=A0=A0=A0 =A0=A0=A0 Joe Blanchard
=A0=A0=A0 =A0=A0=A0=20
=A0=A0=A0 =A0=A0=A0 > -----Original Message-----
=A0=A0=A0 =A0=A0=A0 > From: Subba Rao [mailto:castellan2004-nsm@yahoo.com]=
=20
=A0=A0=A0 =A0=A0=A0 > Sent: Thursday, April 02, 2009 6:33 PM
=A0=A0=A0 =A0=A0=A0 > To: nanog@nanog.org
=A0=A0=A0 =A0=A0=A0 > Subject: Nipper and Cisco configuration results
=A0=A0=A0 =A0=A0=A0 >=20
=A0=A0=A0 =A0=A0=A0 > I am using Nipper for verifying my Cisco configuratio=
n.=A0=20
=A0=A0=A0 =A0=A0=A0 > Nipper is finding the "rlogin" service that is not in=
the=20
=A0=A0=A0 =A0=A0=A0 > configuration.=A0 I have searched the access lists an=
d do
not=20
=A0=A0=A0 =A0=A0=A0 > see it anywhere.=A0 The explanation by Nipper about t=
his=20
=A0=A0=A0 =A0=A0=A0 > finding, "....Telnet protocol implemented by this=20
=A0=A0=A0 =A0=A0=A0 > service...." is confusing.=A0 Here is the Nipper's ou=
tput:
=A0=A0=A0 =A0=A0=A0 >=20
=A0=A0=A0 =A0=A0=A0 > ______________________________
=A0=A0=A0 =A0=A0=A0 > Rlogin Service Settings
=A0=A0=A0 =A0=A0=A0 >=20
=A0=A0=A0 =A0=A0=A0 > The Rlogin service enables remote administrative acce=
ss to
a=20
=A0=A0=A0 =A0=A0=A0 > CLI on Cisco Router Devices.=A0 The Telnet protocol
implemented=20
=A0=A0=A0 =A0=A0=A0 > by th service is simple and provides no encryption of=
the=20
=A0=A0=A0 =A0=A0=A0 > network communications between client and the server.
This=20
=A0=A0=A0 =A0=A0=A0 > section details the Rlogin settings.
=A0=A0=A0 =A0=A0=A0 >=20
=A0=A0=A0 =A0=A0=A0 > Description=A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 Setting
=A0=A0=A0 =A0=A0=A0 > Rlogin Service=A0 =A0 =A0 =A0 =A0 =A0 Enabled
=A0=A0=A0 =A0=A0=A0 > Service TCP Port=A0 =A0 =A0 =A0 513
=A0=A0=A0 =A0=A0=A0 > ______________________________
=A0=A0=A0 =A0=A0=A0 >=20
=A0=A0=A0 =A0=A0=A0 > I have checked a few other routers where SSH was not
enabled=20
=A0=A0=A0 =A0=A0=A0 > with the same results.
=A0=A0=A0 =A0=A0=A0 >=20
=A0=A0=A0 =A0=A0=A0 > Can someone explain why Nipper is saying "Rlogin is
enabled"=20
=A0=A0=A0 =A0=A0=A0 > when I do not see it in the configuration file?=A0 Is=
there=20
=A0=A0=A0 =A0=A0=A0 > something else that I need to be looking at?
=A0=A0=A0 =A0=A0=A0 >=20
=A0=A0=A0 =A0=A0=A0 > Thank you in advance for any help.
=A0=A0=A0 =A0=A0=A0 >=20
=A0=A0=A0 =A0=A0=A0 > Subba Rao
=A0=A0=A0 =A0=A0=A0=20
=A0=A0=A0 =A0=A0=A0=20
=A0=A0=A0 =A0=A0=A0=20