2010年6月18日 星期五

Cấm không cho khôi phục password Cisco

Trên router Cisco có chức năng Secure ROMMON để cấm không cho khôi phục password
Để sử dụng tính năng ta cấu hình như sau :

router1(config)#no service password−recovery
Executing this command will disable password recovery mechanism.
Do not execute this command without another plan for
password recovery.
Are you sure you want to continue? [yes/no]: yes

Nếu đã bật chức năng Secure ROMMON thì sẽ không thể đổi thanh ghi về 0x2142 để bỏ qua quá trình load start-up configure lúc khởi động

router1(config)#no service password−recovery
router1(config)#config−register 0x2142
Password recovery is disabled, can not enable diag or
ignore configuration.

Và nểu có sử dụng lệnh no service password−recovery trong cấu hình thì lúc khởi động ta sẽ thấy thông tin sau

System Bootstrap, Version 11.1(19)AA, EARLY DEPLOYMENT RELEASE SOFTWARE (fc1)
Copyright (c) 1998 by cisco Systems, Inc.
C3600 processor with 65536 Kbytes of main memory
Main memory is configured to 64 bit mode with parity enabled
program load complete, entry point: 0x80008000, size: 0x10ce394
Self decompressing the image : ####################################
################################################# [OK]
Smart Init is disabled. IOMEM set to: 10
Using iomem percentage: 10
Restricted Rights Legend
Use, duplication, or disclosure by the Government is
subject to restrictions as set forth in subparagraph
(c) of the Commercial Computer Software − Restricted
Rights clause at FAR sec. 52.227−19 and subparagraph
(c) (1) (ii) of the Rights in Technical Data and Computer
Software clause at DFARS sec. 252.227−7013.
Cisco Systems, Inc.
170 West Tasman Drive
San Jose, California 95134−1706
Cisco Internetwork Operating System Software
IOS (tm) 3600 Software (C3640−IS−M), Version 12.3(3), RELEASE SOFTWARE (fc2)
Copyright (c) 1986−2003 by Cisco Systems, Inc.
Compiled Mon 18−Aug−03 19:03 by dchih
Image text−base: 0x60008950, data−base: 0x61B3E000

Trong truờng hợp chức năng Secure ROMMON đã được sử dụng ,nếu quên mật khẩu thì ta vẫn khôi phục lại được nhưng sẽ mất hoàn toàn cấu hình băng cách khởi động lại router và nhấn CTR + BREAK trong 5 đến 10s để có thể đưa router trở về cấu hình mặc định ban đầu

System Bootstrap, Version 11.1(19)AA, EARLY DEPLOYMENT RELEASE SOFTWARE (fc1)
Copyright (c) 1998 by Cisco Systems, Inc.
C3600 processor with 65536 Kbytes of main memory
Main memory is configured to 64 bit mode with parity enabled
program load complete, entry point: 0x80008000, size: 0x10ce394
Self decompressing the image : #########################################################
####################################################################### [OK]
Smart Init is disabled. IOMEM set to: 10
Using iomem percentage: 10
Restricted Rights Legend
Use, duplication, or disclosure by the Government is
subject to restrictions as set forth in subparagraph
(c) of the Commercial Computer Software − Restricted
Rights clause at FAR sec. 52.227−19 and subparagraph
(c) (1) (ii) of the Rights in Technical Data and Computer
Software clause at DFARS sec. 252.227−7013.
Cisco Systems, Inc.
170 West Tasman Drive
San Jose, California 95134−1706
Cisco Internetwork Operating System Software
IOS (tm) 3600 Software (C3640−IS−M), Version 12.3(3), RELEASE SOFTWARE (fc2)
Copyright (c) 1986−2003 by Cisco Systems, Inc.
Compiled Mon 18−Aug−03 19:03 by dchih
Image text−base: 0x60008950, data−base: 0x61B3E000
Do you want to reset the router to factory default
configuration and proceed [y/n] ?
Reset router configuration to factory default.
Cisco 3640 (R4700) processor (revision 0x00) with 59392K/6144K bytes of memory.
Processor board ID 09196037
R4700 CPU at 100Mhz, Implementation 33, Rev 1.0
Bridging software.
X.25 software, Version 3.0.0.
SuperLAT software (copyright 1990 by Meridian Technology Corp).
2 Ethernet/IEEE 802.3 interface(s)
2 Voice FXO interface(s)
2 Voice FXS interface(s)
DRAM configuration is 64 bits wide with parity enabled.
125K bytes of non−volatile configuration memory.
8192K bytes of processor board System flash (Read/Write)
8192K bytes of processor board PCMCIA Slot0 flash (Read/Write)
20480K bytes of processor board PCMCIA Slot1 flash (Read/Write)
SETUP: new interface Ethernet0/0 placed in "shutdown" state
SETUP: new interface Ethernet1/0 placed in "shutdown" state
Press RETURN to get started!

