← All cheat sheets

CISCO-OCS

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

Cisco OCS (Cisco Operational Configuration Scanner) is a mass
Cisco device scanner that uses SNMP and Telnet to audit Cisco
routers and switches for security misconfigurations and weak
credentials.

BASIC USAGE#

cisco-ocs <target>               # Scan target device
cisco-ocs -f <file>              # Scan targets from file

OPTIONS#

cisco-ocs <target>               # Target IP/hostname
cisco-ocs -f <file>              # File with target list
cisco-ocs -c <community>        # SNMP community string
cisco-ocs -p <port>              # Port to connect to
cisco-ocs -t <timeout>           # Connection timeout
cisco-ocs -v                     # Verbose output

CHECKS PERFORMED#

# Configuration Audit:
# - Password encryption (service password-encryption)
# - Enable secret vs enable password
# - VTY line access control
# - Console access restrictions
# - SNMP community strings strength
# - Logging configuration
# - NTP configuration
# - Banner presence

# Security Checks:
# - Default credentials
# - SNMP write access
# - Unnecessary services enabled
# - CDP (Cisco Discovery Protocol) status
# - HTTP server enabled
# - Source routing enabled
# - Proxy ARP status

EXAMPLES#

# Scan single device
cisco-ocs 192.168.1.1

# Scan with custom community string
cisco-ocs -c mycommunity 192.168.1.1

# Scan multiple targets from file
cisco-ocs -f routers.txt

# Verbose scan with timeout
cisco-ocs -v -t 10 192.168.1.1

CISCO HARDENING CHECKLIST#

# Items typically checked:
# [ ] service password-encryption enabled
# [ ] enable secret (not enable password)
# [ ] no ip source-route
# [ ] no cdp run (on external interfaces)
# [ ] no ip http server
# [ ] access-list on VTY lines
# [ ] logging configured
# [ ] NTP authentication
# [ ] SNMP v3 (not v1/v2c)
# [ ] no service finger
# [ ] no service tcp-small-servers
# [ ] no service udp-small-servers
# [ ] banner motd configured

NOTES#

- Requires SNMP or Telnet/SSH access
- Use SNMP v3 when possible for security
- May need enable-level access for full audit
- Results should be compared against CIS benchmarks
- Pair with Nipper for configuration analysis
- Only for authorized network auditing