Re: Easy question about downloading-uploading IOS

2000-11-06 Thread Jacques Atlas
hi On Mon, 6 Nov 2000, [iso-8859-1] Carlos Márquez wrote: |Can I download the IOS from a router and upload it on another router? yip, that is taking into account that the IOS is correct for that router. |router 1: copy flash tftp |router 2: copy tftp flash | |and then the router 2 will boot w

RE: Disable telnet port [7:3237]

2001-05-04 Thread Jacques Atlas
On Fri, 4 May 2001, Chuck Larrieu wrote: |By "telnet port" do you mean TCP port 23. Or do you mean the VTY's |themselves? | |If the latter, the most effective way is to require a login but set no |password. |Eg | |Line vty 0 4 |Login anyone know if you can _disable_ telnet to a cisco and only ss

RE: Disable telnet port [7:3237]

2001-05-04 Thread Jacques Atlas
On Fri, 4 May 2001, Chuck Larrieu wrote: |There is no option "no service telnet" on the IOS I have available to me. :-) that was just an example of something that would be nice. |Your choice would then become an access-list denying telnet to appropriate |router interfaces. You can also apply ac

Re: Disable telnet port [7:3237]

2001-05-05 Thread Jacques Atlas
hi On Sat, 5 May 2001, EA Louie wrote: |If you have the right version of IOS, you can |transport input ssh that works :-) thanks -- jacques Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=3293&t=3237 -- FAQ, list archives,

RE: Disable telnet port (Cisco Trivia) [7:3287]

2001-05-05 Thread Jacques Atlas
On Sat, 5 May 2001, Brian Dennis wrote: |Anyone know how to get to a Cisco router remotely that doesn't have an IP |address configured on it? Going in through a console, aux or async line |doesn't count. cool so we can do this through a sync interface :-) use ip helper-address, just tested it

RE: Disable telnet port (Cisco Trivia) [7:3287]

2001-05-05 Thread Jacques Atlas
On Sat, 5 May 2001, ElephantChild wrote: |Read the question again. What helper address are you going to configure, |if your target router doesn't have any IP address assigned to any of its |interfaces? router b (no config) | | sync interface | router a (config with access to the world) yo

Re: linux on a 2500 ? Was: Programming under IOS [7:3362]

2001-05-06 Thread Jacques Atlas
On Sun, 6 May 2001, Jason wrote: |It has already BEEN done !! :-) got a url for us ? -- jacques Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=3363&t=3362 -- FAQ, list archives, and subscription info: http://www.groupstudy.c

Re: linux on a 2500 ? Was: Programming under IOS [7:3362]

2001-05-06 Thread Jacques Atlas
On Sun, 6 May 2001, Jacques Atlas wrote: ||It has already BEEN done !! :-) | |got a url for us ? http://www.mcvax.org/~koen/uClinux-cisco2500/ -- jacques Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=3364&t=3362 --

RE: Cisco HSRP Denial of Service Vulnerability [7:3534]

2001-05-07 Thread Jacques Atlas
On Tue, 8 May 2001, Curtis Call wrote: |In other words always use authentication. i dont think the authentication in clear text is going to help, the solution from the vendor is to run HSRP with IPSec. -- jacques Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=3557&t=3534

Re: Cisco HSRP Denial of Service Vulnerability [7:3534]

2001-05-08 Thread Jacques Atlas
hi On Tue, 8 May 2001, Priscilla Oppenheimer wrote: |Also, instead of using HSRP you could use the Virtual Router Redundancy |Protocol (VRRP) defined in RFC 2338. VRRP is the standards-track |replacement for HSRP. The Security Considerations section explains |authentication options, including us

Re: Cisco HSRP Denial of Service Vulnerability [7:3534]

2001-05-08 Thread Jacques Atlas
hi On Tue, 8 May 2001, Priscilla Oppenheimer wrote: |I'm surprised it's not in more products??? being surprised is something that i am getting used to ;-) -- jacques Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=3674&t=3534 --

RE: security opinions please [7:3666]

2001-05-08 Thread Jacques Atlas
On Tue, 8 May 2001, Michael Cohen wrote: |How does one go upon "penetrating" the internal VLAN on a switch while only |having access to the external VLAN and not traversing the PIX in the middle? i would also be interted in finding out the theory behind this. |I have heard the response from num

Re: security opinions please [7:3666]

2001-05-08 Thread Jacques Atlas
hi On Tue, 8 May 2001, [EMAIL PROTECTED] wrote: |event of just the right failure/misconfiguration, someone could |theoretically re-configure the switch to do bad things. failure or misconfiguration has a direct fault which has to do with the owner. the switch doing something which people do no

Re: security opinions please [7:3666]

2001-05-08 Thread Jacques Atlas
On Tue, 8 May 2001, Drew Simonis wrote: |Some decent reads: | |http://mlarchive.ima.com/firewalls/1999/4507.html |http://packetstorm.securify.com/9909-exploits/vlan_security.txt anyone want to confirm this for 65xx ? -- jacques Message Posted at: http://www.groupstudy.com/form/read.php?f=7

Re: security opinions please [7:3666]

2001-05-09 Thread Jacques Atlas
On Wed, 9 May 2001 [EMAIL PROTECTED] wrote: |Do you disagree based on the idea that you can blame someone |when a problem occurs? While it may be nice to know you can |point a finger at someone when there are problems, I believe its |better to eliminate the source of the problem to begin with.

RE: security opinions please [7:3666]

2001-05-09 Thread Jacques Atlas
On Wed, 9 May 2001, [EMAIL PROTECTED] wrote: |For example, what if a bug occured under certain network |conditions that caused a switch to lose its VLAN configuration, |even though the config showed they were there? that is like saying what happens if the router drop a route or even a packe