Author
defconrussia
View
1.026
Download
6
Embed Size (px)
Tacacs+
Tacacs+Digital SecurityAlexey GreenDog [email protected]
Tacacs+ Cisco
(49/TCP) AAA (.authentication, authorization, accounting) Cisco ( ) , (tacplus)
Defcon Russia (DCG #7812)2
: Tacacs+Defcon Russia (DCG #7812)3
Tacacs+ serverUser
1. :aaa authentication login default group tacacs+ locallocal . timeout
Defcon Russia (DCG #7812)4
15
Tacacs+ serverPentester1
23
Defcon Russia (DCG #7812)
2. MitM? MitM? Pre Shared Key
Defcon Russia (DCG #7812)6
Tacacs+ serverPentester
2. ,
Defcon Russia (DCG #7812)7
2. XOR:encrypted_data=data^pseudo_pad
Pseudo_padpseudo_pad = {MD5_1 [,MD5_2 [ ... ,MD5_n]]}
MD5xMD5_1 = MD5{session_id, key, version, seq_no}MD5_2 = MD5{session_id, key, version, seq_no, MD5_1}....MD5_n = MD5{session_id, key, version, seq_no, MD5_n-1}
key. enc_data? data?
Defcon Russia (DCG #7812)8
2. ( padding) MD5_1 (128 ) 1. :
Defcon Russia (DCG #7812)9
2Pseudo_pad=enc_data^dataPseudo_pad -> MD5_1 -> local bruteforce
Defcon Russia (DCG #7812)10
Tacacs+ serverPentester
2. Pseudo_pad (seq_num MD5) 2. . 0 - :
Defcon Russia (DCG #7812)11
2. SSH
Defcon Russia (DCG #7812)12
2. ! tac2cat (Tacacs 2 HashCat) type 1 ssh, type 2- telnet
HashCat 2 MD5{session_id, key, version, seq_no}
Defcon Russia (DCG #7812)13
Q&ADefcon Russia (DCG #7812)14
https://twitter.com/antyurinhttps://github.com/grrrdog