Warning: Cisco RW community backdoor.

jlewis at lewis.org jlewis at lewis.org
Wed Feb 28 00:11:58 UTC 2001


On Mon, 26 Feb 2001, David Schwartz wrote:

> > While I agree that "public" and "private" are "wellknowns," in most
> > implementations, they at least show up in the code.  Cisco chose to hide
> > this one where it would not show up in the code.  That IMHO is a very bad
> > thing and does bad things to my confidence level in Cisco.
>
>     Do a "show snmp group" from an enabled console prompt. It does show.

On some routers that have the backdoor, "show snmp group" isn't even a
valid command.

-- 
----------------------------------------------------------------------
 Jon Lewis *jlewis at lewis.org*|  I route
 System Administrator        |  therefore you are
 Atlantic Net                |
_________ http://www.lewis.org/~jlewis/pgp for PGP public key_________





More information about the NANOG mailing list