Discussion:
[rancid] Re: Need to know if mutiple usernames can be setin the.clogin file
Lance
2007-06-25 15:43:05 UTC
Permalink
Todd,

Nice URL. :-D bad URL or a hacked site.

Miss Cindy's Neighborhood Nursery School


Hehehe.

Happy Mondays.

-Lance
-------- Original Message --------
Subject: [rancid] Re: Need to know if mutiple usernames can be setin
the.clogin file
Date: Mon, June 25, 2007 6:18 am
Setup a Tacacs+ server on the Rancid box. The one I use which has a nice
front end is found here, http://www.networkforums.net Once installed and
working it is easy to check the logs to see what has been done and by
whom.
Thanks
Todd Heide
Equivoice Inc.
CCNA CWLSS CS-CISecS
847-235-3308
Nothing ever goes as planned, Its a hell of a notion,
Even pharaohs turn to sand, Like a drop in the ocean
-----Original Message-----
Ollie
Sent: Monday, June 25, 2007 8:02 AM
Subject: [rancid] Re: Need to know if mutiple usernames can be setin
the.clogin file
Thanks for the swift response . We do have cisco tacacs installed
using
ACS.
Even when we have that there may be multiple users who will be a part
of
the authentication group who will actually have level 15 access .
So say for eg we have a group called noc-users and there are 3 users
namely user1 ,user2 ,user3 who will have privilege 15 access .
So how can I check if I login as a user2 and do some change ?
Currently all I get from rancid is that a diff output mail with the
difference and no mention of the username doing the change .
RANCID cannot do what you ask. All that RANCID can do is give you a
summary of the changes made between two points in time, it cannot show
you who made those changes. It also cannot show you changes that were
made then unmade in between the times that RANCID scans your routers.
You need to enable command accounting on your router to get the kind of
http://www.cisco.com/en/US/customer/products/sw/iosswrel/ps1828/products
_configuration_guide_chapter09186a00800ca5f1.html#xtocid183737
Jeff
_______________________________________________
Rancid-discuss mailing list
http://www.shrubbery.net/mailman/listinfo.cgi/rancid-discuss
Todd Heide
2007-06-25 15:47:16 UTC
Permalink
Oh great! Yep, been hacked, again it appears. I have the files for the
install if interested.

Thanks
Todd Heide
Equivoice Inc.

CCNA CWLSS CS-CISecS

Nothing ever goes as planned, Its a hell of a notion,
Even pharaohs turn to sand, Like a drop in the ocean

-----Original Message-----
From: Lance [mailto:***@gheek.net]
Sent: Monday, June 25, 2007 10:43 AM
To: Todd Heide
Cc: Jeffrey C. Ollie; rancid-***@shrubbery.net
Subject: RE: [rancid] Re: Need to know if mutiple usernames can be setin
the.clogin file

Todd,

Nice URL. :-D bad URL or a hacked site.

Miss Cindy's Neighborhood Nursery School


Hehehe.

Happy Mondays.

-Lance
-------- Original Message --------
Subject: [rancid] Re: Need to know if mutiple usernames can be setin
the.clogin file
Date: Mon, June 25, 2007 6:18 am
Setup a Tacacs+ server on the Rancid box. The one I use which has a
nice
front end is found here, http://www.networkforums.net Once installed
and
working it is easy to check the logs to see what has been done and by
whom.
Thanks
Todd Heide
Equivoice Inc.
CCNA CWLSS CS-CISecS
847-235-3308
Nothing ever goes as planned, Its a hell of a notion,
Even pharaohs turn to sand, Like a drop in the ocean
-----Original Message-----
Ollie
Sent: Monday, June 25, 2007 8:02 AM
Subject: [rancid] Re: Need to know if mutiple usernames can be setin
the.clogin file
Thanks for the swift response . We do have cisco tacacs installed
using
ACS.
Even when we have that there may be multiple users who will be a
part
of
the authentication group who will actually have level 15 access .
So say for eg we have a group called noc-users and there are 3 users
namely user1 ,user2 ,user3 who will have privilege 15 access .
So how can I check if I login as a user2 and do some change ?
Currently all I get from rancid is that a diff output mail with the
difference and no mention of the username doing the change .
RANCID cannot do what you ask. All that RANCID can do is give you a
summary of the changes made between two points in time, it cannot show
you who made those changes. It also cannot show you changes that were
made then unmade in between the times that RANCID scans your routers.
You need to enable command accounting on your router to get the kind
of
http://www.cisco.com/en/US/customer/products/sw/iosswrel/ps1828/products
_configuration_guide_chapter09186a00800ca5f1.html#xtocid183737
Jeff
_______________________________________________
Rancid-discuss mailing list
http://www.shrubbery.net/mailman/listinfo.cgi/rancid-discuss
Saku Ytti
2007-06-25 16:05:17 UTC
Permalink
Post by Todd Heide
Oh great! Yep, been hacked, again it appears. I have the files for the
install if interested.
Off-topic, but why does it appear 'hacked'? To me it seems like web hoster
didn't setup sane default page for unknown 'Host: x', e.g.
networkforums.net has been removed from that site and it falls back to
some config it found.
--
++ytti
Justin Shore
2007-06-25 16:43:51 UTC
Permalink
Post by Saku Ytti
Post by Todd Heide
Oh great! Yep, been hacked, again it appears. I have the files for the
install if interested.
Off-topic, but why does it appear 'hacked'? To me it seems like web hoster
didn't setup sane default page for unknown 'Host: x', e.g.
networkforums.net has been removed from that site and it falls back to
some config it found.
Saku,

I think you're right.

Name: www.networkforums.net
Address: 71.169.3.3

Name: www.misscindysschool.com
Address: 71.169.3.3

All these URLs give you the same site.

http://www.misscindysschool.com
http://www.networkforums.net
http://71.169.3.3

The web hoster is apparently having problems...

Justin
Ed Ravin
2007-06-25 17:08:43 UTC
Permalink
Post by Justin Shore
Post by Saku Ytti
Off-topic, but why does it appear 'hacked'? To me it seems like web hoster
didn't setup sane default page for unknown 'Host: x', e.g.
networkforums.net has been removed from that site and it falls back to
some config it found.
Saku,
I think you're right.
Name: www.networkforums.net
Address: 71.169.3.3
Name: www.misscindysschool.com
Address: 71.169.3.3
All these URLs give you the same site.
Awww, shucks, I was hoping that this was a case of Pre-K
"script kiddies", who were going to follow up on this hack by
writing the Playskool UI for RANCID.

Todd Heide
2007-06-25 16:07:30 UTC
Permalink
It has happened before with this site, someone gets in there and
replaced the content with something else. Worked last week.

Thanks
Todd Heide
Equivoice Inc.

CCNA CWLSS CS-CISecS
847-235-3308

Nothing ever goes as planned, Its a hell of a notion,
Even pharaohs turn to sand, Like a drop in the ocean

-----Original Message-----
From: rancid-discuss-***@shrubbery.net
[mailto:rancid-discuss-***@shrubbery.net] On Behalf Of Saku Ytti
Sent: Monday, June 25, 2007 11:05 AM
To: rancid-***@shrubbery.net
Subject: [rancid] Re: Need to know if mutiple usernames can be
setinthe.clogin file
Post by Todd Heide
Oh great! Yep, been hacked, again it appears. I have the files for the
install if interested.
Off-topic, but why does it appear 'hacked'? To me it seems like web
hoster
didn't setup sane default page for unknown 'Host: x', e.g.
networkforums.net has been removed from that site and it falls back to
some config it found.
--
++ytti
Loading...