CISCO-TORCH
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
Cisco Torch is a mass scanning, fingerprinting, and exploitation tool for Cisco devices. It uses multiple protocols simultaneously (Telnet, SSH, HTTP, SNMP, TFTP, NTP) to discover and audit Cisco infrastructure at scale.
BASIC USAGE#
cisco-torch -A <target> # All scanning types cisco-torch <target> # Default scan
OPTIONS#
cisco-torch -t <target> # Target (IP, range, or CIDR) cisco-torch -F <file> # Targets from file cisco-torch -A # All scanning types combined cisco-torch -b # Banner grabbing cisco-torch -f # Fingerprint devices cisco-torch -g # HTTP config gathering cisco-torch -j # TFTP config copying cisco-torch -n # NTP fingerprinting cisco-torch -s # SNMP scanning cisco-torch -w # Cisco web interface scanning cisco-torch -z # SSH scanning cisco-torch -c # CDP discovery cisco-torch -v # Verbose mode
SCAN TYPES#
# Banner Grabbing (-b): cisco-torch -b <target> # Grab Telnet/SSH banners # Fingerprinting (-f): cisco-torch -f <target> # Fingerprint Cisco device type # HTTP Scanning (-g, -w): cisco-torch -g <target> # HTTP config gathering cisco-torch -w <target> # Web interface scanning # SNMP Scanning (-s): cisco-torch -s <target> # SNMP community scanning # TFTP (-j): cisco-torch -j <target> # TFTP config download attempt # NTP (-n): cisco-torch -n <target> # NTP information gathering # SSH (-z): cisco-torch -z <target> # SSH version scanning
EXAMPLES#
# Full scan of a single device cisco-torch -A 192.168.1.1 # Scan a subnet cisco-torch -A 192.168.1.0/24 # Scan targets from file cisco-torch -A -F targets.txt # SNMP and banner grab only cisco-torch -s -b 192.168.1.0/24 # Fingerprint and web scan cisco-torch -f -w 10.0.0.0/24 # SSH scanning across range cisco-torch -z 172.16.0.0/16
CONFIGURATION#
# Config file: torch.conf # Default credentials file: passwords.txt # SNMP community strings file: community.txt # # Edit these files to customize: # - Default passwords to test # - SNMP community strings # - Scan timeouts # - Thread count
INFORMATION GATHERED#
# Per device: # - Device type (router, switch, AP) # - IOS version # - Hostname # - Open services # - SNMP community strings # - Configuration (if accessible) # - SSH version # - HTTP server version # - NTP status
NOTES#
- Perl-based tool - Multi-threaded for fast scanning - Can scan large networks quickly - Uses multiple protocols simultaneously - May trigger IDS/IPS alerts - Can be noisy on the network - Only for authorized security auditing - Results help prioritize manual auditing - Pair with Cisco Auditing Tool for deeper checks