Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Vuln-Dev
[Top] [All Lists]

Re: several vulnerabilities present in Belkin wireless routers

Subject: Re: several vulnerabilities present in Belkin wireless routers
Date: Fri, 22 Jul 2005 14:15:08 +0200
I can't comment on the Belkin stuff.  As for Cisco IIRC, telnet is
enabled by default, however it doesn't allow anyone to log in unless a
telnet password is set on the vty lines and the login command is
configured as well, and those are not set by default.

So, you can certainly use a telnet exploit against them because the
port is open, but you're not going in via the non-existant password.

Regards,
Roman Daszczyszak

---------- Original message ----------
From: steven.salaets@windriver.com
To: bugtraq@securityfocus.com
Date: 20 Jul 2005 08:58:29 -0000
Subject: Re: Re: several vulnerabilities present in Belkin wireless routers
What I wonder is: How much of a security threat is this? Are we not
talking about default settings here? How secure is a linksys or cisco
AP out of the box? As far as I recall Cisco also enables telnet by
default and if you Google for a default administrative password for
any network device it won't take you 5 minutes to find it.

-Steven

<Prev in Thread] Current Thread [Next in Thread>