
Coleção de scripts TCL para testes de penetração em Cisco IOS
Com o TCLtools você pode transformar qualquer hardware Cisco IOS em uma estação de pivoting. É fácil de configurar e usar!
TCLproxy é uma ferramenta para pivoting através de dispositivos Cisco. É capaz de encaminhar qualquer porta TCP ou iniciar um servidor proxy.
TCLproxy v0.0.3
Usage: tclsh ./tclproxy.tcl [-L address]... [-D address]...
Proxy server implementation. Binary protocols are supported.
-L [bind_address:]port:remote_host:remote_port
Forward a remote port to a local port.
Multiple connections and multiple forwards are supported.
-D [bind_address:]port
Launch a SOCKS4a proxy server.
Forwarding between VRF tables:
-D [VRF_table_for_listening@][bind_address]:port[@VRF_table_for_outbound_connections]
-L [VRF_table_for_listening@][bind_address]:port[@VRF_table_for_outbound_connections]:remote_host:remote_port
optional arguments:
-f, --disable-eof-check Speed increases by 1-15 KB/s, but connections don't close automatically. Dangerous!
-h, --help Show this help message and exit.
-q, --disable-output Quite mode. In this mode, you can disconnect from the console without script termination. Dangerous!
-l, --low-ports Use privileged source ports. Required for NFS (source port increments from 1 to 1023 every connection)
-n, --disable-dns Do not resolve DNS names in SOCKS mode
The effect of --disable-eof-check and --disable-output options depends on hardware architecture and firmware version.
TCLproxy will not work for port scanning, use tclmap.tcl instead.
example:
$ sudo py3tftp -p 69
cisco# configure terminal
cisco(config)# scripting tcl low-memory 5242880
cisco(config)# end
cisco# copy tftp://192.168.1.10/tclproxy.tcl flash:/
cisco# tclsh tclproxy.tcl -h
cisco# tclsh tclproxy.tcl -L 5901:10.0.0.1:445 -D :5902@enterpriseVRF -D 5900
...
cisco# del flash:/tclproxy.tcl
TCL é uma linguagem de programação dinâmica, interpretada, de alto nível e propósito geral. O Cisco IOS implementa TCL 8.3.4:
cisco# tclsh
cisco(tcl)# puts $tcl_version
8.3
cisco(tcl)# puts $tcl_patchLevel
8.3.4
TCLtools requer nível de privilégio 15 no hardware.
Existem quatro métodos para carregar scripts TCL:
$ sudo py3tftp -p 69
or
$ python2 -m pyftpdlib
cisco# copy tftp://192.168.1.10/tclproxy.tcl flash:/
cisco# copy ftp://192.168.1.10:2121/tclproxy.tcl flash:/
cisco# tclsh tclproxy.tcl
or
cisco# tclsh ftp://192.168.1.10:2121/tclproxy.tcl
$ cat tclproxy.tcl | sed -E 's/([{}$\[])/\\\1/g'
cisco# tclsh
cisco(tcl)# puts [open "flash:tclproxy.tcl" w+] {
cisco(tcl)# ; Copy file contents onto this
cisco(tcl)# }
cisco(tcl)# exit
cisco#
cisco# tclsh tclproxy.tcl
cisco# tclsh
cisco(tcl)# set argv [list -D 1080]
cisco(tcl)# ; Copy file contents onto this
cisco# configure terminal
cisco(config)# scripting tcl init ftp://192.168.1.10/tclproxy.tcl
cisco(config)# end
cisco# tclsh
Uma boa prática é definir o tamanho mínimo de memória livre:
cisco# configure terminal
cisco(config)# scripting tcl low-memory 5242880
cisco(config)# end
Além disso, ou em vez disso, você pode visualizar o desempenho do dispositivo com os seguintes comandos:
cisco# show processes cpu | i Tcl
cisco# show processes mem | i Tcl
Testado em Cisco 2811 / Cisco 2821 Integrated Services Router, Cisco Catalyst 2960 e Cisco Catalyst 3750-X.
Você pode abrir uma Nova Issue para relatar um bug ou sugerir uma nova funcionalidade para melhorar o projeto. Ou pode enviar algumas linhas para [email protected].