of 14 /14
Атаки на Tacacs+ Digital Security Alexey GreenDog Tyurin @antyurin

Attacks on tacacs - Алексей Тюрин

Embed Size (px)

Text of Attacks on tacacs - Алексей Тюрин

Tacacs+

Tacacs+Digital SecurityAlexey GreenDog [email protected]

Tacacs+ Cisco

(49/TCP) AAA (.authentication, authorization, accounting) Cisco ( ) , (tacplus)

Defcon Russia (DCG #7812)2

: Tacacs+Defcon Russia (DCG #7812)3

Tacacs+ serverUser

1. :aaa authentication login default group tacacs+ locallocal . timeout

Defcon Russia (DCG #7812)4

15

Tacacs+ serverPentester1

23

Defcon Russia (DCG #7812)

2. MitM? MitM? Pre Shared Key

Defcon Russia (DCG #7812)6

Tacacs+ serverPentester

2. ,

Defcon Russia (DCG #7812)7

2. XOR:encrypted_data=data^pseudo_pad

Pseudo_padpseudo_pad = {MD5_1 [,MD5_2 [ ... ,MD5_n]]}

MD5xMD5_1 = MD5{session_id, key, version, seq_no}MD5_2 = MD5{session_id, key, version, seq_no, MD5_1}....MD5_n = MD5{session_id, key, version, seq_no, MD5_n-1}

key. enc_data? data?

Defcon Russia (DCG #7812)8

2. ( padding) MD5_1 (128 ) 1. :

Defcon Russia (DCG #7812)9

2Pseudo_pad=enc_data^dataPseudo_pad -> MD5_1 -> local bruteforce

Defcon Russia (DCG #7812)10

Tacacs+ serverPentester

2. Pseudo_pad (seq_num MD5) 2. . 0 - :

Defcon Russia (DCG #7812)11

2. SSH

Defcon Russia (DCG #7812)12

2. ! tac2cat (Tacacs 2 HashCat) type 1 ssh, type 2- telnet

HashCat 2 MD5{session_id, key, version, seq_no}

Defcon Russia (DCG #7812)13

Q&ADefcon Russia (DCG #7812)14

https://twitter.com/antyurinhttps://github.com/grrrdog