Hacker News new | ask | show | jobs
by Shank 3597 days ago
It's a pivot though. If you can compromise anything that's on the LAN you can pivot inside with this. The sample files provide prove that they have working exploits, that they're NSA-grade, and that they function. The actual auction files are probably much more "fire and forget" grade -- either acting over the internet or doing privilege escalation combined with these attacks.
1 comments

yes, absolutely true. If the exploit is running on a non-Cisco compromised device that's in RFC1918 IP space somewhere that it can reach internal, SNMP-listening interfaces of the device, that's a good way to attack it.