module

Cisco ASA Authentication Bypass (EXTRABACON)

Disclosed
N/A
Created
2018-05-30

Description

This module patches the authentication functions of a Cisco ASA
to allow uncredentialed logins. Uses improved shellcode for payload.

Authors

Sean Dillon sean.dillon@risksense.com
Zachary Harding zachary.harding@risksense.com
Nate Caroe nate.caroe@risksense.com
Dylan Davis dylan.davis@risksense.com
William Webb william_webb@rapid7.com
Jeff Jarmoc jjarmoc
Equation Group
Shadow Brokers

Module Options

To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:


msf > use auxiliary/admin/cisco/cisco_asa_extrabacon
msf auxiliary(cisco_asa_extrabacon) > show actions
...actions...
msf auxiliary(cisco_asa_extrabacon) > set ACTION < action-name >
msf auxiliary(cisco_asa_extrabacon) > show options
...show and set options...
msf auxiliary(cisco_asa_extrabacon) > run

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.