networking-forum.com
Community BlogCommunity Wiki * Register  * Search  * Login
View unanswered postsView active topics

All times are UTC - 6 hours [ DST ]



Post new topic Reply to topic  [ 15 posts ] 
Author Message
 Post subject: nexus openSSH versions
PostPosted: Wed Jul 25, 2012 9:43 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Tue Aug 21, 2007 2:15 pm
Posts: 8260
Location: Frederick MD
Certs: Instanity
how can I determine what versions of openSSH are built into which cisco nexus versions.
working through a Cert report requiring openSSH version 5.2 or greater.
don't know how to determine which IOS I need to upgrade to that will support this.
any idea? tac case is next.

_________________
"If you're good at anticipating the human mind. It leaves nothing to chance."
-Jigsaw


Top
 Profile  
 
PostPosted: Wed Jul 25, 2012 9:51 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Mon Jan 17, 2005 11:01 pm
Posts: 5148
Location: Canada eh
Certs: 350-001, CCNP, CXFF, ITILv3F
Telnet to port 22
Attachment:
ssh.png
ssh.png [ 8.91 KiB | Viewed 1083 times ]

_________________
blog.brokennetwork.ca


Top
 Profile  
 
PostPosted: Wed Jul 25, 2012 11:06 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Tue Aug 21, 2007 2:15 pm
Posts: 8260
Location: Frederick MD
Certs: Instanity
mine says 4.5 now, I need to get to at least 5.2
which IOS do I need to run ?
that's the million dollar question.

_________________
"If you're good at anticipating the human mind. It leaves nothing to chance."
-Jigsaw


Top
 Profile  
 
PostPosted: Wed Jul 25, 2012 11:18 am 
Offline
Ultimate Member
Ultimate Member
User avatar

Joined: Thu Jan 13, 2011 5:10 pm
Posts: 984
Location: Leeds, UK
Certs: CCIE R&S #38338, CCNP, CCIP
Hopefully you don't try and upgrade the IOS seen as they run NX-OS ;)

A 7k I have here is running 'SSH-2.0-OpenSSH_5.5' and is running NX-OS 6.0(1)

_________________
---
David
CCIE R&S #38338, CCIP, CCNP

http://networkbroadcast.co.uk - My Blog
http://twitter.com/davidrothera


Top
 Profile  
 
PostPosted: Sun Jul 29, 2012 9:29 pm 
Offline
Junior Member
Junior Member
User avatar

Joined: Wed May 09, 2012 10:44 pm
Posts: 66
Location: RTP, NC
Certs: CCNP
Why do you need 5.2? What problem are you running into?

_________________
http://www.defendingnetworks.com/


Top
 Profile  
 
PostPosted: Mon Jul 30, 2012 7:45 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Fri Apr 25, 2008 2:16 pm
Posts: 1361
Location: Jacksonville, FL
Certs: CCNP, CCNA:Sec, MCSE
SSH-2.0-OpenSSH_5.5 FIPS = n5000-uk9.5.0.3.N2.1.bin

_________________
"A problem well stated is a problem half solved". (Charles Kettering)


Top
 Profile  
 
PostPosted: Mon Jul 30, 2012 8:58 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Tue Aug 21, 2007 2:15 pm
Posts: 8260
Location: Frederick MD
Certs: Instanity
dnetworks wrote:
Why do you need 5.2? What problem are you running into?


nessus audit
CVE-2008-5161
CVE-2008-3234
CVE-2008-1483
CVE-2008-1657

yeah, I know 4 years ago.

_________________
"If you're good at anticipating the human mind. It leaves nothing to chance."
-Jigsaw


Top
 Profile  
 
PostPosted: Mon Jul 30, 2012 2:15 pm 
Offline
Junior Member
Junior Member
User avatar

Joined: Wed May 09, 2012 10:44 pm
Posts: 66
Location: RTP, NC
Certs: CCNP
ristau5741 wrote:
nessus audit
CVE-2008-5161
CVE-2008-3234
CVE-2008-1483
CVE-2008-1657

yeah, I know 4 years ago.


Not sure if you're running into this or not. Just something to be aware of though

http://tools.cisco.com/Support/BugToolK ... CSCti81843

_________________
http://www.defendingnetworks.com/


Top
 Profile  
 
PostPosted: Mon Jul 30, 2012 2:19 pm 
Offline
Post Whore
Post Whore
User avatar

Joined: Tue Aug 21, 2007 2:15 pm
Posts: 8260
Location: Frederick MD
Certs: Instanity
dnetworks wrote:
ristau5741 wrote:
nessus audit
CVE-2008-5161
CVE-2008-3234
CVE-2008-1483
CVE-2008-1657

yeah, I know 4 years ago.


Not sure if you're running into this or not. Just something to be aware of though

http://tools.cisco.com/Support/BugToolK ... CSCti81843



nice find, thanks. takes a few hits off the reports

_________________
"If you're good at anticipating the human mind. It leaves nothing to chance."
-Jigsaw


Top
 Profile  
 
PostPosted: Mon Jul 30, 2012 7:43 pm 
Offline
Junior Member
Junior Member
User avatar

Joined: Wed May 09, 2012 10:44 pm
Posts: 66
Location: RTP, NC
Certs: CCNP
Ristau,

What version are you running? You could also turn off http by doing 'no feature http' and retest again.

_________________
http://www.defendingnetworks.com/


Top
 Profile  
 
PostPosted: Tue Jul 31, 2012 7:56 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Tue Aug 21, 2007 2:15 pm
Posts: 8260
Location: Frederick MD
Certs: Instanity
dnetworks wrote:
Ristau,

What version are you running? You could also turn off http by doing 'no feature http' and retest again.



various code on different devices, from 4.2.4 to 5.1.3, need an upgrade, especially on the 4.2.4 devices.

_________________
"If you're good at anticipating the human mind. It leaves nothing to chance."
-Jigsaw


Top
 Profile  
 
PostPosted: Fri Aug 03, 2012 6:43 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Tue Aug 21, 2007 2:15 pm
Posts: 8260
Location: Frederick MD
Certs: Instanity
here is the response from Cisco regarding the CVEs

CVE-2007-2243 Summary:
OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is
enabled, allows remote attackers to determine the existence of user
accounts by attempting to authenticate via S/KEY, which displays a
different response if the user account exists

[Result] ChallengeResponseAuthentication is not enabled in NX-OS


CVE-2007-4752 Summary:
ssh in OpenSSH before 4.7 does not properly handle when an untrusted
cookie cannot be created and uses a trusted X11 cookie instead, which
allows attackers to violate intended policy and gain privileges by
causing an X client to be treated as trusted. Here is the link to know
more info http://web.nvd.nist.gov/view/vuln/detai ... -2007-4752

[Result] X11 forwarding is not enabled in NX-OS
So NX-OS is not impacted by both these vulnerabilities

CVE-2008-3234 - (False Positive)
Evaluated in CSCti81843. The X11 forwarding feature of OpenSSH is explicitly
disabled in all supported versions of NX-OS

CVE-2008-1657 - (False Positive)
Evalutated in CSCtx04369.

[Result]The ForceCommand directive is to force a command
to be executed by the ssh server whenever a user logs in. But for this to be
done , there has to be a configuration directive in the sshd_config file.
The sshd_config files does'nt have this option on. Also by default
ForceCommand option is not enabled in the code.

CVS-2008-1483 – Nexus switches do not run X (False Positive). X11 Forwarding is disabled.
These devices are not susceptible to this attack.
CSCti81843

[Result]Bug filed and closed stating X11 is not effecting Nexus.

CVS-2008-5161 -
As of 7K code version 5.1 (Open SSH v5.5) and Nexus 5K version below is running OpenSSH 5.5 as well which are past your CVE's.
5K Code for openSSH 5.5
(running 5.1(3)N1(1)

_________________
"If you're good at anticipating the human mind. It leaves nothing to chance."
-Jigsaw


Top
 Profile  
 
PostPosted: Mon Aug 20, 2012 10:50 am 
Offline
Member
Member

Joined: Fri Apr 17, 2009 4:15 am
Posts: 244
Location: Canada
Certs: CCNA:Sec/CCNP/CCDP/CCIP
Does anyone know what's the NX-OS equivalent for Ctrl+Shift+6 (X)? Quite annoying that it is changed.

_________________
"It can also be argued that DNA is nothing more than a program designed to preserve itself. Life has become more complex in the overwhelming sea of information. And life, when organized into species, relies upon genes to be its memory system."


Top
 Profile  
 
PostPosted: Mon Aug 20, 2012 12:08 pm 
Offline
Junior Member
Junior Member
User avatar

Joined: Wed May 09, 2012 10:44 pm
Posts: 66
Location: RTP, NC
Certs: CCNP
Sepiraph wrote:
Does anyone know what's the NX-OS equivalent for Ctrl+Shift+6 (X)? Quite annoying that it is changed.



Are you looking to break to do a password recovery? If so its Cltr-]

_________________
http://www.defendingnetworks.com/


Top
 Profile  
 
PostPosted: Mon Aug 20, 2012 2:14 pm 
Offline
Member
Member

Joined: Fri Apr 17, 2009 4:15 am
Posts: 244
Location: Canada
Certs: CCNA:Sec/CCNP/CCDP/CCIP
dnetworks wrote:
Sepiraph wrote:
Does anyone know what's the NX-OS equivalent for Ctrl+Shift+6 (X)? Quite annoying that it is changed.



Are you looking to break to do a password recovery? If so its Cltr-]


No trying to get back to original device from a ssh session.

_________________
"It can also be argued that DNA is nothing more than a program designed to preserve itself. Life has become more complex in the overwhelming sea of information. And life, when organized into species, relies upon genes to be its memory system."


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 15 posts ] 

All times are UTC - 6 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 14 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group