[4200] in bugtraq
Cisco 2509/2511
daemon@ATHENA.MIT.EDU (Albert Siersema)
Mon Mar 24 15:40:44 1997
Date: Mon, 24 Mar 1997 18:06:18 -0100
Reply-To: Albert Siersema <appie@CASTEL.NET>
From: Albert Siersema <appie@CASTEL.NET>
To: BUGTRAQ@NETSPACE.ORG
This is an old one, but I keep seeing comfigurations (also posted to
UseNet) where people forget to do a:
transport input none
on their 'line 1 16' (or whatever) config.
If you use the default values ('telnet' I think) and you have no filters
(stupid idea too) on your Cisco then someone is able to use ports 2001 and
up to connect to one of the devices attached to it. If this is a modem
that same person can type any AT command he/she wants. Go figure..