← All cheat sheets

CISCO-AUDITING-TOOL

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

Cisco Auditing Tool (CAT) scans Cisco routers for common
vulnerabilities including default passwords, SNMP community strings,
and known IOS bugs. It performs basic security auditing of Cisco
network devices.

BASIC USAGE#

CAT -h <target>                  # Scan single host
CAT -h <target> -p <port>       # Scan with custom port
CAT -h <target> -a <wordlist>   # Brute force passwords

OPTIONS#

CAT -h <host>                    # Target hostname/IP
CAT -p <port>                    # Telnet port (default: 23)
CAT -w <wordlist>                # SNMP community string wordlist
CAT -a <wordlist>                # Password wordlist
CAT -q                           # Quiet mode (less output)

CHECKS PERFORMED#

# 1. Default Password Check
# - Tests common default Cisco passwords
# - Tests blank/empty passwords
# - Tests "cisco", "admin", "password", etc.

# 2. SNMP Community String Check
# - Tests "public" (read-only)
# - Tests "private" (read-write)
# - Custom wordlist via -w flag

# 3. Known Vulnerability Check
# - HTTP configuration disclosure
# - IOS version-specific bugs
# - TFTP misconfiguration

EXAMPLES#

# Basic scan with default checks
CAT -h 192.168.1.1

# Scan with password brute force
CAT -h 192.168.1.1 -a passwords.txt

# Scan with SNMP community string list
CAT -h 192.168.1.1 -w community_strings.txt

# Scan non-standard Telnet port
CAT -h 192.168.1.1 -p 2323

# Full scan with custom wordlists
CAT -h 192.168.1.1 -a passwords.txt -w snmp_strings.txt

COMMON DEFAULT CREDENTIALS#

# Cisco default passwords to test:
cisco / cisco
admin / admin
admin / cisco
admin / (blank)
(blank) / (blank)
cisco / (blank)
enable / cisco

COMMON SNMP STRINGS#

public                           # Default read-only
private                          # Default read-write
cisco                            # Vendor-specific
community                        # Common default
cable-docsis                     # Cable modem default
ILMI                             # ATM default

NOTES#

- Perl-based script
- Requires network access to Cisco devices
- May lock accounts after failed attempts
- Test in maintenance windows
- Check Cisco SmartNet for IOS advisories
- Legacy tool - consider cisco-torch for more features
- Only for authorized security auditing