Entries for September, 2008

How to analyze traffic with SPAN feature

Usually when we admin a network, we need to know what are the protocols used more frequently, and why not, discover if someone are using improper P2P software; so we can use SPAN.
The Switched Port Analyzer (SPAN) feature, which is sometimes called port mirroring or port monitoring, selects network traffic for analysis by a network [...]

Routed versus routing protocols

Two categories of protocol exist at the network layer: routed and routing.
A routed protocol is a Network Layer protocol that is used to move traffic between networks. Routed protocols allow a host on one network to communicate with a host on another, with routers forwarding traffic between the source and destination networks. IP, IPX, and [...]

Sep.24, 2008?! 12 new Cisco vulnerability advisories!

On September 24, 2008, at about 16:00 GMT, the The Cisco Product Security Incident Response Team (PSIRT) has published 12 new vulnerability advisories. Mainly these vulnerabilities are DOS attack.

The configuration register

The configuration register can be used to change router behavior in several ways, such as:

how the router boots (into ROMmon, NetBoot)
options while booting (ignore configuration, disable boot messages)
console speed (baud rate for a terminal emulation session)

To view the current setting of the configuration register, use the show version command:

Cisco to acquire Jabber

Cisco has agreed to purchase open-source instant messaging firm Jabber. The company plans to use the Jabber messaging software within its WebEx Connect and Unified Communications packages.
“Enterprise organizations want an extensible presence and messaging platform that can integrate with business process applications and easily adapt to their changing needs,” said Doug Dennerline, Cisco senior vice [...]

Cisco On-Stage TelePresence Experience

Have you ever seen a sci-fi movie where object and people were represented through holography? Now, this technology is no more sci-fi!
The system uses a high-definition camera to shoot scenes and a high-definition projector with a special screen.
The Cisco On-Stage TelePresence Experience was an ambitious collaboration between Cisco and Musion Systems, which took place during [...]

How to test Cisco Cross-Site Request Forgery

Cisco Router HTTP Administration CSRF Remote Command Execution Universal Exploit. Replace “10.10.10.1″ with the IP address of the target router, embed this in a web page and hope for the best. This is only for test use.

Cisco Cross-Site Request Forgery

Cisco routers with the HTTP administration interface enabled are vulnerable to an CSRF (Cross-Site Request Forgery) vulnerability that can yield remote command execution with level 15 privileges.
An attacker can execute ANY command on the router with level 15 (root, same as enable) privileges (usually level 15 user by default) by getting a target user (administrator [...]

An introduction to SNMP

In a network environment, it is a good practice monitor Cisco devices.
One of the most famous protocol to control and manage Cisco devices is SNMP (Simple Network Management Protocol).
SNMP exposes management data in the form of variables on the managed systems, which describe the system configuration. These variables can then be queried (and sometimes set) [...]

Is your Cisco Wlan product certified in your country?

You never be asked if your Cisco Wlan product agrees with your country standards?
Do you know that in New Zealand and Australia, the 802.11abg Access Points are approved only with antennas of 6dBi or less and indoor use only from 5150-5350 MHz?
Do you know that in Russian Federation, the 802.11abg Mesh Access Points end user [...]