Mental Note: Tracking L3 Glean Attacks

Here’s a handy debug command for tracking L3 Glean attacks on IOS based Cisco routers / L3 switches.

From there, you can take the output, paste the contents into a file, then use some Linux foo to determine the attacker.

Supporting documentation: Built-in CPU Sniffer

November 28, 2014

pyMultiChange – SSH Script Update

I updated the script from my pyMultiChange repository. It’s now fully functional and allows you to enter ‘enable’ mode on Cisco routers and switches. As I’m using the paramiko library to interact with routers and switches via SSH, I had to switch from using the ‘exec_command’ API to invoke_shell, send, and recv API’s. It took a little more work – and I’m not completely thrilled with how the ‘recv’ API is implemented in paramiko, but it’s what we have to work with for now.

The pyMuliChange repository is available on my github.

November 26, 2014

