<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/rss2full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/itemcontent.css" type="text/css" media="screen"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>evilrouters.net</title>
	
	<link>http://evilrouters.net</link>
	<description>im in ur datacentrz fixin' ur routerz</description>
	<pubDate>Fri, 21 Nov 2008 22:05:31 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
	<language>en</language>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/evilrouters" type="application/rss+xml" /><feedburner:emailServiceId>2662134</feedburner:emailServiceId><feedburner:feedburnerHostname>http://www.feedburner.com</feedburner:feedburnerHostname><item>
		<title>VMware Converter 4.0 Standalone Beta</title>
		<link>http://feeds.feedburner.com/~r/evilrouters/~3/459901104/</link>
		<comments>http://evilrouters.net/2008/11/20/vmware-converter-40-standalone-beta/#comments</comments>
		<pubDate>Thu, 20 Nov 2008 19:09:20 +0000</pubDate>
		<dc:creator>jeremy</dc:creator>
		
		<category><![CDATA[1]]></category>

		<category><![CDATA[linux]]></category>

		<category><![CDATA[software]]></category>

		<category><![CDATA[virtualization]]></category>

		<category><![CDATA[work]]></category>

		<guid isPermaLink="false">http://evilrouters.net/2008/11/20/vmware-converter-40-standalone-beta/</guid>
		<description><![CDATA[From an e-mail I received Tuesday:

Hello Jeremy,

Thank you for your interest in VMware beta programs. Our upcoming release of VMware Converter 4.0 Standalone product includes many exciting enhancements that our customers have been requesting including P2V support for Linux and Win 2K8 sources, hot cloning enhancements as well as workflow automation enhancements. We are certain [...]]]></description>
			<content:encoded><![CDATA[<p>From an e-mail I received Tuesday:</p>

<blockquote>Hello Jeremy,<br />
<br />
Thank you for your interest in <a href="http://www.vmware.com/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.vmware.com');">VMware</a> beta programs. Our upcoming release of <a href="http://www.vmware.com/products/converter/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.vmware.com');">VMware Converter</a> 4.0 Standalone product includes many exciting enhancements that our customers have been requesting including <a href="http://en.wikipedia.org/wiki/Physical-to-Virtual" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/en.wikipedia.org');">P2V</a> support for Linux and Win 2K8 sources, hot cloning enhancements as well as workflow automation enhancements. We are certain you will find participation in this beta program a valuable experience. We are looking forward to working closely with you during this beta program.<br />
<br />
As part of this beta, we request you to extensively test several areas of feature enhancements including P2V support for Linux and Win 2K8 sources, hot cloning enhancements as well as workflow automation enhancements. Your active participation in this beta program is critical. We appreciate and value your efforts to install upon downloading the software and actively provide us with your valuable product feedback.<br /></blockquote>

<p>I&#8217;m just about (in the next week or so) to attempt to P2V a <a href="http://www.redhat.com/rhel/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.redhat.com');">Red Hat Enterprise Linux</a> 4 host over to <a href="http://www.vmware.com/products/vi/esx/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.vmware.com');">ESX</a>, so maybe I&#8217;ll give the new 4.0 beta a shot.  Anyone used it yet, especially to P2V Linux hosts?  I am, of course, interested in hearing feedback on it.</p>
<img src="http://feeds.feedburner.com/~r/evilrouters/~4/459901104" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://evilrouters.net/2008/11/20/vmware-converter-40-standalone-beta/feed/</wfw:commentRss>
		<feedburner:origLink>http://evilrouters.net/2008/11/20/vmware-converter-40-standalone-beta/</feedburner:origLink></item>
		<item>
		<title>Big Three auto CEOs flew private jets to ask for taxpayer money</title>
		<link>http://feeds.feedburner.com/~r/evilrouters/~3/459830196/</link>
		<comments>http://evilrouters.net/2008/11/20/big-three-auto-ceos-flew-private-jets-to-ask-for-taxpayer-money/#comments</comments>
		<pubDate>Thu, 20 Nov 2008 18:00:45 +0000</pubDate>
		<dc:creator>jeremy</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[government]]></category>

		<category><![CDATA[news]]></category>

		<category><![CDATA[politics]]></category>

		<category><![CDATA[stupid]]></category>

		<guid isPermaLink="false">http://evilrouters.net/2008/11/20/big-three-auto-ceos-flew-private-jets-to-ask-for-taxpayer-money/</guid>
		<description><![CDATA[From CNN:

 &#8220;There is a delicious irony in seeing private luxury jets flying into Washington, D.C., and people coming off of them with tin cups in their hand, saying that they&#8217;re going to be trimming down and streamlining their businesses,&#8221; Rep. Gary Ackerman, D-New York, told the chief executive officers of Ford, Chrysler and General [...]]]></description>
			<content:encoded><![CDATA[<p>From <a href="http://us.cnn.com/2008/US/11/19/autos.ceo.jets/index.html" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/us.cnn.com');">CNN</a>:</p>

<blockquote> &#8220;There is a delicious irony in seeing private luxury jets flying into Washington, D.C., and people coming off of them with tin cups in their hand, saying that they&#8217;re going to be trimming down and streamlining their businesses,&#8221; <a href="http://www.house.gov/ackerman/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.house.gov');">Rep. Gary Ackerman</a>, D-New York, told the chief executive officers of <a href="http://www.ford.com/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.ford.com');">Ford</a>, <a href="http://www.chrysler.com/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.chrysler.com');">Chrysler</a> and <a href="http://www.gm.com/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.gm.com');">General Motors</a> at a hearing of the House Financial Services Committee.</blockquote>

<blockquote>&#8220;It&#8217;s almost like seeing a guy show up at the soup kitchen in high hat and tuxedo. It kind of makes you a little bit suspicious.&#8221;</blockquote>

<blockquote>He added, &#8220;couldn&#8217;t you all have downgraded to first class or jet-pooled or something to get here? It would have at least sent a message that you do get it.&#8221;</blockquote>

<p>Personally, I say screw &#8216;em.</p>
<img src="http://feeds.feedburner.com/~r/evilrouters/~4/459830196" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://evilrouters.net/2008/11/20/big-three-auto-ceos-flew-private-jets-to-ask-for-taxpayer-money/feed/</wfw:commentRss>
		<feedburner:origLink>http://evilrouters.net/2008/11/20/big-three-auto-ceos-flew-private-jets-to-ask-for-taxpayer-money/</feedburner:origLink></item>
		<item>
		<title>Configuring FreeRADIUS to support Cisco AAA Clients</title>
		<link>http://feeds.feedburner.com/~r/evilrouters/~3/458017055/</link>
		<comments>http://evilrouters.net/2008/11/19/configuring-freeradius-to-support-cisco-aaa-clients/#comments</comments>
		<pubDate>Wed, 19 Nov 2008 05:40:22 +0000</pubDate>
		<dc:creator>jeremy</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[cisco]]></category>

		<category><![CDATA[labs]]></category>

		<category><![CDATA[linux]]></category>

		<category><![CDATA[networking]]></category>

		<category><![CDATA[open-source]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://evilrouters.net/2008/11/19/configuring-freeradius-to-support-cisco-aaa-clients/</guid>
		<description><![CDATA[In this demonstration, we&#8217;re going to install FreeRADIUS onto a CentOS 5.2 server and configure it to support AAA on Cisco devices.

&#8220;FreeRADIUS is the most widely deployed RADIUS server in the world. It is the basis for multiple commercial offerings. It supplies the AAA needs of many Fortune-500 companies and Tier 1 ISPs. It is [...]]]></description>
			<content:encoded><![CDATA[<p>In this demonstration, we&#8217;re going to install <a href="http://freeradius.org/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/freeradius.org');">FreeRADIUS</a> onto a <a href="http://www.centos.org/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.centos.org');">CentOS</a> 5.2 server and configure it to support <a href="http://en.wikipedia.org/wiki/AAA_protocol" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/en.wikipedia.org');">AAA</a> on <a href="http://www.cisco.com/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.cisco.com');">Cisco</a> devices.</p>

<blockquote>&#8220;FreeRADIUS is the most widely deployed RADIUS server in the world. It is the basis for multiple commercial offerings. It supplies the AAA needs of many Fortune-500 companies and Tier 1 ISPs. It is also widely used in the academic community, including eduroam. The server is fast, feature-rich, modular, and scalable.&#8221;  &#8211;FreeRADIUS home page</blockquote>

<p>I&#8217;ve been using FreeRADIUS in production for a few years now, mostly to support wireless users.  One of the benefits of FreeRADIUS &#8212; besides being open source, of course &#8212; is the numbers of backends one can use for authentication:</p>

<blockquote>&#8220;If a password is not available locally for some reason, the server can pass the authentication to another system such as <a href="http://en.wikipedia.org/wiki/Lightweight_Directory_Access_Protocol" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/en.wikipedia.org');">LDAP</a>, <a href="http://en.wikipedia.org/wiki/Pluggable_Authentication_Modules" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/en.wikipedia.org');">PAM</a>, Unix (/etc/passwd), <a href="http://en.wikipedia.org/wiki/Kerberos_(protocol)" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/en.wikipedia.org');">Kerberos</a>, <a href="http://en.wikipedia.org/wiki/Active_Directory" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/en.wikipedia.org');">Active Directory</a>, or <a href="http://en.wikipedia.org/wiki/RADIUS" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/en.wikipedia.org');">RADIUS</a> server via RADIUS proxying. Local programs (e.g. CGI scripts) can also be used to authenticate users via shell scripts or any other method. <a href="http://www.perl.org/about.html" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.perl.org');">Perl</a> or <a href="http://www.python.org/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.python.org');">Python</a> scripts can be pre-loaded into the server, which significantly lowers the cost of running such programs.&#8221;</blockquote>

<p>Powerful, huh?  Indeed.</p>

<p>For this demonstration, I&#8217;m installing a new CentOS 5.2 virtual machine on my <a href="http://www.apple.com/macbook/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.apple.com');">MacBook</a> under <a href="http://www.vmware.com/products/fusion/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.vmware.com');">VMware Fusion</a>.  Installing the operating system, however, is beyond the scope of this document.  Also, we&#8217;ll just be using the local system database for now &#8212; we&#8217;ll save SQL and LDAP (perhaps even Active Directory) authentication for later.  After we get FreeRADIUS up and running, we&#8217;ll set up a user account and then configure a Cisco router to use RADIUS for authentication.</p>

<p>Let&#8217;s begin with installing FreeRADIUS by running (as root) the following command:</p>

<pre><code>[root@bertram ~]# yum -y install freeradius</code></pre>

<p>&#8220;yum&#8221; should have went out, grabbed the appropriates packages and dependencies, and installed them.  If the end of your output looks like this, you&#8217;re all set:</p>

<pre><code>Complete!
[root@bertram ~]#</code></pre>

<p>Because FreeRADIUS will need to use the local system database for authentication, we need to set &#8216;user = root&#8217; and &#8216;group = root&#8217; in radiusd.conf.  This is easy enough, just open up /etc/raddb/radiusd.conf, and change the lines that reads &#8220;user = radiusd&#8221; and &#8220;group = radiusd&#8221; to &#8220;user = root&#8221; and &#8220;group = root&#8221;, respectively.  Note that this (running our daemons as root) is almost always something we want to avoid.  Using other authentication backends, such as SQL or LDAP, would not require this change and would allow the FreeRADIUS service to run under the default &#8220;radiusd&#8221; unprivileged account.</p>

<p>Next, we need to let FreeRADIUS know about our NAS &#8212; in this case, our Cisco router.  For the sake of this demonstration, our router (R1) will have IP address 192.168.1.201.  We&#8217;ll also need a shared secret that the router and RADIUS server use.  Let&#8217;s use the ever popular &#8220;SECRET_KEY&#8221;.  Add the following to the end of /etc/raddb/clients.conf:</p>

<pre><code>client 192.168.1.201 {
        secret = SECRET_KEY
        shortname = R1
        nastype = cisco
}</code></pre>

<p>Then, on the FreeRADIUS side, we need to create a user account in the local user database that we&#8217;ll use for actually authenticating to R1.  Nothing special here, just creating a new user account and setting the password.  I&#8217;ve passed the plain-text password into &#8220;passwd&#8221; via stdin so that you can see it.  Normally, we wouldn&#8217;t do that &#8212; just run &#8220;passwd cisco&#8221; and enter the password when prompted:</p>

<pre><code>[root@bertram ~]# /usr/sbin/useradd cisco
[root@bertram ~]# echo secret | passwd --stdin cisco
Changing password for user cisco.
passwd: all authentication tokens updated successfully.
[root@bertram ~]#</code></pre>

<p>We now have a local user named &#8220;cisco&#8221; with a password of &#8220;secret&#8221; that we&#8217;ll use when it comes time to authenticate to R1.  Before we can do that, however, we must let FreeRADIUS know about the user.  Append the following to /etc/raddb/users:</p>

<pre><code>cisco   Auth-Type := System
        Service-Type = NAS-Prompt-User,
        cisco-avpair = "shell:priv-lvl=15"</code></pre>

<p>This notifies FreeRADIUS of a local user account named &#8220;cisco&#8221;.  Using the &#8220;cisco-avpair&#8221; attribute in this manner allows us to automatically assign privilege level 15 to the user, removing the requirement for the user to issue &#8220;enable&#8221; (and the enable secret) in order to gain elevated access.</p>

<p>Let&#8217;s get started configuring R1.  I&#8217;m going to assume that you&#8217;re starting from a default configuration.  The first thing we want to do is create a &#8220;fallback&#8221; user account (on the router itself) that we can use to authenticate if, for some reason, connectivity to the RADIUS server is lost.  Let&#8217;s create a user named &#8220;admin&#8221; with a password of &#8220;letmein&#8221;:</p>

<pre><code>R1(config)#username admin privilege 15 secret letmein</code></pre>

<p>Under normal circumstances, we&#8217;ll never use this local account &#8212; only when the RADIUS server is unavailable.</p>

<p>The first thing I need to do is configure my interface on R1 and verify we can ping the RADIUS server.  Assuming you already have your router up and running, you can likely skip this step:</p>

<pre><code>R1(config)#interface fastethernet 3/0
R1(config-if)#ip address 192.168.1.201 255.255.255.0
R1(config-if)#no shutdown
R1(config-if)#
*Mar  1 00:10:14.635: %LINK-3-UPDOWN: Interface FastEthernet3/0, changed state to up
*Mar  1 00:10:15.635: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet3/0, changed state to up
R1(config-if)#do ping 192.168.1.51

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.1.51, timeout is 2 seconds:
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 4/11/24 ms
R1(config-if)#</code></pre>

<p>Excellent, all set!  Let&#8217;s start configuring R1 for AAA:</p>

<pre><code>R1(config)#aaa new-model
R1(config)#radius-server host 192.168.1.51 auth-port 1812 acct-port 1813 key SECRET_KEY</code></pre>

<p>AAA should now be enabled on R1.  Note that we provided the IP address of the RADIUS server as well as the shared secret we configured in FreeRADIUS earlier.  In addition, we must specify the &#8220;auth-port&#8221; and &#8220;acct-port&#8221; used by FreeRADIUS, as these are different from Cisco&#8217;s defaults (1645 and 1646).  Let&#8217;s configure authentication:</p>

<pre><code>R1(config)#aaa authentication login default group radius local
R1(config)#line vty 0 4
R1(config-line)#login authentication default
R1(config-line)#line con 0
R1(config-line)#login authentication default</code></pre>

<p>Here, we&#8217;ve told R1 to use RADIUS for authentication and to fall back to the local user database if the RADIUS server is not available.  We don&#8217;t want to DoS ourselves!</p>

<p>The following command will allow the user to run an &#8220;exec&#8221; shell when logging into the router:</p>

<pre><code>R1(config)#aaa authorization exec default group radius if-authenticated </code></pre>

<p>Last, but not least, we want accounting (the final &#8220;A&#8221; in &#8220;AAA&#8221;):</p>

<pre><code>R1(config)#aaa accounting exec default start-stop group radius
R1(config)#aaa accounting system default start-stop group radius</code></pre>

<p>That should be enough to allow us to login with our local (Linux) system account &#8220;cisco&#8221; that we created earlier.  Let&#8217;s give it a shot:</p>

<pre><code>macbook:~ jlgaddis$ telnet 192.168.1.201
Trying 192.168.1.201...
Connected to 192.168.1.201.
Escape character is '^]'.


User Access Verification

Username: cisco
Password:

R1#show ip interface brief
Interface                  IP-Address      OK? Method Status                Protocol
Ethernet0/0                unassigned      YES unset  administratively down down
Ethernet0/1                unassigned      YES unset  administratively down down
Ethernet0/2                unassigned      YES unset  administratively down down
Ethernet0/3                unassigned      YES unset  administratively down down
Serial1/0                  unassigned      YES unset  administratively down down
Serial1/1                  unassigned      YES unset  administratively down down
Serial1/2                  unassigned      YES unset  administratively down down
Serial1/3                  unassigned      YES unset  administratively down down
FastEthernet3/0            192.168.1.201   YES manual up                    up
R1#exit
Connection closed by foreign host.
macbook:~ jlgaddis$</code></pre>

<p>Success!  We&#8217;ve installed FreeRADIUS, added a local user account, set up the NAS client (R1) and configured it to authenticate against the RADIUS server.  Let&#8217;s take a look at what was logged by FreeRADIUS:</p>

<pre><code>[root@bertram ~]# cat /var/log/radius/radacct/192.168.1.201/detail-20081119
Wed Nov 19 00:24:47 2008
        Acct-Session-Id = "00000005"
        User-Name = "cisco"
        Acct-Authentic = RADIUS
        Acct-Status-Type = Start
        NAS-Port = 130
        NAS-Port-Id = "tty130"
        NAS-Port-Type = Virtual
        Calling-Station-Id = "192.168.1.49"
        Service-Type = NAS-Prompt-User
        NAS-IP-Address = 192.168.1.201
        Acct-Delay-Time = 0
        Client-IP-Address = 192.168.1.201
        Acct-Unique-Session-Id = "31b757fca2145e79"
        Timestamp = 1227072287

Wed Nov 19 00:25:14 2008
        Acct-Session-Id = "00000005"
        User-Name = "cisco"
        Acct-Authentic = RADIUS
        Acct-Terminate-Cause = User-Request
        Acct-Session-Time = 27
        Acct-Status-Type = Stop
        NAS-Port = 130
        NAS-Port-Id = "tty130"
        NAS-Port-Type = Virtual
        Calling-Station-Id = "192.168.1.49"
        Service-Type = NAS-Prompt-User
        NAS-IP-Address = 192.168.1.201
        Acct-Delay-Time = 0
        Client-IP-Address = 192.168.1.201
        Acct-Unique-Session-Id = "31b757fca2145e79"
        Timestamp = 1227072314

[root@bertram ~]#</code></pre>

<p>If there&#8217;s interest, I may expand on this later to include huntgroups, multiple RADIUS servers, using MySQL for accounting, or even through some LDAP and/or Active Directory authentication into the mix.  If you&#8217;re interested, please leave a comment below!</p>
<img src="http://feeds.feedburner.com/~r/evilrouters/~4/458017055" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://evilrouters.net/2008/11/19/configuring-freeradius-to-support-cisco-aaa-clients/feed/</wfw:commentRss>
		<feedburner:origLink>http://evilrouters.net/2008/11/19/configuring-freeradius-to-support-cisco-aaa-clients/</feedburner:origLink></item>
		<item>
		<title>Upgrading DD-WRT on the Buffalo WHR-G125</title>
		<link>http://feeds.feedburner.com/~r/evilrouters/~3/456858460/</link>
		<comments>http://evilrouters.net/2008/11/18/upgrading-dd-wrt-on-the-buffalo-whr-g125/#comments</comments>
		<pubDate>Tue, 18 Nov 2008 06:56:07 +0000</pubDate>
		<dc:creator>jeremy</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[hacking]]></category>

		<category><![CDATA[internet]]></category>

		<category><![CDATA[linux]]></category>

		<category><![CDATA[networking]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://evilrouters.net/2008/11/18/upgrading-dd-wrt-on-the-buffalo-whr-g125/</guid>
		<description><![CDATA[While browsing through my archives tonight, my thoughts went back to the reliable little Buffalo WHR-G125 router/access point over in the corner.  Back in January, I wrote about having issues with my MacBook&#8217;s wireless and upgrading to &#8212; at the time &#8212; the latest version of DD-WRT to see if it would help with [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://evilrouters.net/wp-content/uploads/2008/11/whr-g125.gif" width="140" height="140" alt="" border="0" align="left" hspace="15">While browsing through my archives tonight, my thoughts went back to the reliable little Buffalo WHR-G125 router/access point over in the corner.  Back in January, I wrote about having issues with my MacBook&#8217;s wireless and upgrading to &#8212; at the time &#8212; the latest version of DD-WRT to see if it would help with the issues.</p>

<p>Many months have passed since then and the wireless issues have went away.  Unfortunately, I don&#8217;t really remember when they went away.  I&#8217;m not sure if it had anything to do with the firmware upgrade or not.</p>

<p>Regardless, I browsed over to the DD-WRT site again to see if there was newer firmware available.  There was, so I decided to upgrade.  Upgrading to the latest version was really easy:</p>

<pre><code>[jlgaddis@cleveland ~]$ ssh root@ap
root@ap's password:
root@router:~# cd /tmp
root@router:/tmp# wget http://tinyurl.com/5qv69u
root@router:/tmp# write dd-wrt.v24_vpn_generic.bin linux</code></pre>

<p>At this point, we have a few minutes to kill.  The flash memory isn&#8217;t the fastest in the world, and it&#8217;ll take a bit to save the file to flash.  Once it&#8217;s done and our prompt has came back back, we just need to reboot.</p>

<pre><code>root@router:/tmp# reboot</code></pre>

<p>Give the router a minute or two to reboot, and we should be able to login again:</p>

<pre><code>[jlgaddis@cleveland ~]$ ssh root@ap
DD-WRT v24 vpn (c) 2008 NewMedia-NET GmbH
Release: 07/27/08 (SVN revision: 10011)
root@ap's password:
==========================================================

 ____  ___    __        ______ _____         ____  _  _
 | _ \| _ \   \ \      / /  _ \_   _| __   _|___ \| || |
 || | || ||____\ \ /\ / /| |_) || |   \ \ / / __) | || |_
 ||_| ||_||_____\ V  V / |  _ < | |    \ V / / __/|__   _|
 |___/|___/      \_/\_/  |_| \_\|_|     \_/ |_____|  |_|

                       DD-WRT v24
                   http://www.dd-wrt.com

==========================================================


BusyBox v1.11.1 (2008-07-27 16:20:53 CEST) built-in shell (ash)
Enter 'help' for a list of built-in commands.

root@router:~# exit
Connection to ap closed.
[jlgaddis@cleveland ~]$</code></pre>
<img src="http://feeds.feedburner.com/~r/evilrouters/~4/456858460" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://evilrouters.net/2008/11/18/upgrading-dd-wrt-on-the-buffalo-whr-g125/feed/</wfw:commentRss>
		<feedburner:origLink>http://evilrouters.net/2008/11/18/upgrading-dd-wrt-on-the-buffalo-whr-g125/</feedburner:origLink></item>
		<item>
		<title>Basic IPSec VPN Lab for Dynamips</title>
		<link>http://feeds.feedburner.com/~r/evilrouters/~3/456683794/</link>
		<comments>http://evilrouters.net/2008/11/17/basic-ipsec-vpn-lab-for-dynamips/#comments</comments>
		<pubDate>Tue, 18 Nov 2008 02:54:57 +0000</pubDate>
		<dc:creator>jeremy</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[cisco]]></category>

		<category><![CDATA[labs]]></category>

		<category><![CDATA[networking]]></category>

		<guid isPermaLink="false">http://evilrouters.net/2008/11/17/basic-ipsec-vpn-lab-for-dynamips/</guid>
		<description><![CDATA[As I mentioned at the end of the Basic Frame Relay Lab for Dynamips, the next lab will cover how to set up an IPSec site-to-site VPN between R2 and R3 to encrypt our data in transit.

I adhere to the KISS principle so to avoid adding more virtual routers to the topology to act as [...]]]></description>
			<content:encoded><![CDATA[<p>As I mentioned at the end of the <a href="http://evilrouters.net/2008/11/15/basic-frame-relay-lab-for-dynamips/" target="_blank">Basic Frame Relay Lab for Dynamips</a>, the next lab will cover how to set up an <a href="http://en.wikipedia.org/wiki/IPsec" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/en.wikipedia.org');">IPSec</a> site-to-site <a href="http://en.wikipedia.org/wiki/Virtual_private_network" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/en.wikipedia.org');">VPN</a> between R2 and R3 to encrypt our data in transit.</p>

<p>I adhere to the <a href="http://en.wikipedia.org/wiki/KISS_principle" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/en.wikipedia.org');">KISS principle</a> so to avoid adding more virtual routers to the topology to act as hosts, we&#8217;re going to use the loopback 0 interfaces on R2 and R3 that we configured last time as our end IP addresses for testing.  If you missed the last lab, <a href="http://evilrouters.net/2008/11/15/basic-frame-relay-lab-for-dynamips/" target="_blank">go ahead and get it set up</a> and verify full connectivity between the routers and then continue on.</p>

<p>Okay, so we have R1, R2, and R3 up and running, <a href="http://en.wikipedia.org/wiki/EIGRP" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/en.wikipedia.org');">EIGRP</a> adjacencies established, and full routing between all interfaces.  Let&#8217;s jump right in to setting up our IPSec VPN!</p>

<p>Our first step is to configure the <a href="http://en.wikipedia.org/wiki/Internet_Security_Association_and_Key_Management_Protocol" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/en.wikipedia.org');">ISAKMP</a> policies on each router.  In this lab, we&#8217;ll use a pre-shared key for authentication, 128-bit <a href="http://en.wikipedia.org/wiki/Advanced_Encryption_Standard" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/en.wikipedia.org');">AES</a> for our encryption algorithm, <a href="http://en.wikipedia.org/wiki/Diffie-Hellman" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/en.wikipedia.org');">Diffie-Helman</a> group 2 (1024-bit modulus) and <a href="http://en.wikipedia.org/wiki/SHA1" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/en.wikipedia.org');">SHA</a> hashing:</p>

<pre><code>R2#conf t
Enter configuration commands, one per line.  End with CNTL/Z.
R2(config)#crypto isakmp policy 10
R2(config-isakmp)#authentication pre-share
R2(config-isakmp)#encryption aes 128
R2(config-isakmp)#group 2
R2(config-isakmp)#hash sha</code></pre>

<pre><code>R3#conf t
Enter configuration commands, one per line.  End with CNTL/Z.
R3(config)#crypto isakmp policy 10
R3(config-isakmp)#authentication pre-share
R3(config-isakmp)#encryption aes 128
R3(config-isakmp)#group 2
R3(config-isakmp)#hash sha</code></pre>

<p>Our next step is to configure the pre-shared key that we wish to use.  Note that we must use the same key (&#8221;SECRET_KEY&#8221;) on both ends of the VPN:</p>

<pre><code>R2(config-isakmp)#crypto isakmp key 0 SECRET_KEY address 172.16.123.3 no-xauth</code></pre>

<pre><code>R3(config-isakmp)#crypto isakmp key 0 SECRET_KEY address 172.16.123.2 no-xauth</code></pre>

<p>With our ISAKMP policy and pre-shared key configured, we can now define our transform set:</p>

<pre><code>R2(config)#crypto ipsec transform-set R2_R3_TRANSFORM esp-aes 128 esp-sha-hmac</code></pre>

<pre><code>R3(config)#crypto ipsec transform-set R3_R2_TRANSFORM esp-aes 128 esp-sha-hmac</code></pre>

<p>Our next step will be to tell the routers what traffic should be encrypted.  We do this with an access list.  For this lab, we&#8217;ll tell R2 that any traffic from 172.16.2.2 destined for 172.16.3.3 should be encrypted.  On R3, we&#8217;ll do just the opposite:  any traffic from 172.16.3.3 destined for 172.16.2.2 should be encrypted.  Note that the access lists on each end must be a &#8220;mirror image&#8221; of each other for the VPN to properly function:</p>

<pre><code>R2(cfg-crypto-trans)#ip access-list extended ENCRYPTED_TRAFFIC
R2(config-ext-nacl)#permit ip host 172.16.2.2 host 172.16.3.3</code></pre>

<pre><code>R3(cfg-crypto-trans)#ip access-list extended ENCRYPTED_TRAFFIC
R3(config-ext-nacl)#permit ip host 172.16.3.3 host 172.16.2.2</code></pre>

<p>Awesome, almost done!  We have two steps left.  We still need to configure our crypto maps and then apply them to the appropriate interfaces.  Once that&#8217;s done, we should have connectivity.  Let&#8217;s set up the crypto maps:</p>

<pre><code>R2(config-ext-nacl)#crypto map R2_R3_MAP 10 ipsec-isakmp
% NOTE: This new crypto map will remain disabled until a peer
        and a valid access list have been configured.
R2(config-crypto-map)#set peer 172.16.123.3
R2(config-crypto-map)#match address ENCRYPTED_TRAFFIC
R2(config-crypto-map)#set transform-set R2_R3_TRANSFORM</code></pre>

<pre><code>R3(config-ext-nacl)#crypto map R3_R2_MAP 10 ipsec-isakmp
% NOTE: This new crypto map will remain disabled until a peer
        and a valid access list have been configured.
R3(config-crypto-map)#set peer 172.16.123.2
R3(config-crypto-map)#match address ENCRYPTED_TRAFFIC
R3(config-crypto-map)#set transform-set R3_R2_TRANSFORM</code></pre>

<p>Now we just apply the crypto maps to the appropriate interfaces (serial 0/0, in both cases here) and we should be good to go:</p>

<pre><code>R2(config-crypto-map)#interface serial 0/0
R2(config-if)#crypto map R2_R3_MAP
R2(config-if)#
*Mar  1 00:13:02.011: %CRYPTO-6-ISAKMP_ON_OFF: ISAKMP is ON</code></pre>

<pre><code>R3(config-crypto-map)#interface serial 0/0
R3(config-if)#crypto map R3_R2_MAP
R3(config-if)#
*Mar  1 00:14:31.447: %CRYPTO-6-ISAKMP_ON_OFF: ISAKMP is ON</code></pre>

<p>With everything now in place, we should be able to send a ping from 172.16.2.2 (R2&#8217;s loopback0 interface) to 172.16.3.3 (R3&#8217;s loopback0 interface) and get a response.  Note that, because of our access list, we must specify 172.16.2.2 as the source IP address of the pings:</p>

<pre><code>R2#ping 172.16.3.3 source 172.16.2.2

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 172.16.3.3, timeout is 2 seconds:
Packet sent with a source address of 172.16.2.2 
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 32/71/112 ms</code></pre>

<p>We can verify that the VPN is up and running with the use of &#8220;show crypto isakmp sa&#8221; and &#8220;show crypto ipsec sa&#8221;:</p>

<pre><code>R2#show crypto isakmp sa
dst             src             state          conn-id slot status
172.16.123.3    172.16.123.2    QM_IDLE              1    0 ACTIVE

R2#show crypto ipsec sa

interface: Serial0/0
    Crypto map tag: R2_R3_MAP, local addr 172.16.123.2

   protected vrf: (none)
   local  ident (addr/mask/prot/port): (172.16.2.2/255.255.255.255/0/0)
   remote ident (addr/mask/prot/port): (172.16.3.3/255.255.255.255/0/0)
   current_peer 172.16.123.3 port 500
     PERMIT, flags={origin_is_acl,ipsec_sa_request_sent}
    #pkts encaps: 4, #pkts encrypt: 4, #pkts digest: 4
    #pkts decaps: 4, #pkts decrypt: 4, #pkts verify: 4
    #pkts compressed: 0, #pkts decompressed: 0
    #pkts not compressed: 0, #pkts compr. failed: 0
    #pkts not decompressed: 0, #pkts decompress failed: 0
    #send errors 1, #recv errors 0

     local crypto endpt.: 172.16.123.2, remote crypto endpt.: 172.16.123.3
     path mtu 1500, ip mtu 1500
     current outbound spi: 0x995FE2D0(2573198032)

     inbound esp sas:
      spi: 0x18DD060C(417138188)
        transform: esp-aes esp-sha-hmac ,
        in use settings ={Tunnel, }
        conn id: 2002, flow_id: SW:2, crypto map: R2_R3_MAP
        sa timing: remaining key lifetime (k/sec): (4439841/3591)
        IV size: 16 bytes
        replay detection support: Y
        Status: ACTIVE

     inbound ah sas:

     inbound pcp sas:

     outbound esp sas:
      spi: 0x995FE2D0(2573198032)
        transform: esp-aes esp-sha-hmac ,
        in use settings ={Tunnel, }
        conn id: 2001, flow_id: SW:1, crypto map: R2_R3_MAP
        sa timing: remaining key lifetime (k/sec): (4439841/3544)
        IV size: 16 bytes
        replay detection support: Y
        Status: ACTIVE

     outbound ah sas:

     outbound pcp sas:</code></pre>

<p>Prior to running that ping, we could&#8217;ve done the following in <a href="http://dynagen.org/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/dynagen.org');">Dynagen</a> to start a packet capture:</p>

<pre><code>=> capture R1 s0/0 ipsec.cap FR</code></pre>

<p>We would then have ended up with a packet capture file we could load up into <a href="http://www.wireshark.org/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.wireshark.org');">Wireshark</a>.  If you had done that, you would see something like this (click for larger image):</p>

<p><a href="http://farm4.static.flickr.com/3280/3040081474_a3fe274026_o.png" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/farm4.static.flickr.com');"><img src="http://farm4.static.flickr.com/3280/3040081474_b32f1ea11b.jpg" title="" border="0"></a></p>

<p>From the packet capture, we can see the ISAKMP negotiation, the IPSec negotation, as well as the <a href="http://en.wikipedia.org/wiki/IPsec#Encapsulating_Security_Payload_.28ESP.29" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/en.wikipedia.org');">ESP</a> (encrypted) traffic between R2 and R3.  Because we did the capturing on R1&#8217;s serial 0/0 interface, we actually see each packet listed twice in the capture.  If we had captured at R2 or R3&#8217;s serial 0/0 interface, we would only see them once.</p>

<p>I hope you enjoyed the lab and learned something from it.  Let me know if there&#8217;s something specific you&#8217;d like to see in future labs or video demos!</p>
<img src="http://feeds.feedburner.com/~r/evilrouters/~4/456683794" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://evilrouters.net/2008/11/17/basic-ipsec-vpn-lab-for-dynamips/feed/</wfw:commentRss>
		<feedburner:origLink>http://evilrouters.net/2008/11/17/basic-ipsec-vpn-lab-for-dynamips/</feedburner:origLink></item>
		<item>
		<title>This is never good</title>
		<link>http://feeds.feedburner.com/~r/evilrouters/~3/455471557/</link>
		<comments>http://evilrouters.net/2008/11/15/this-is-never-good/#comments</comments>
		<pubDate>Sat, 15 Nov 2008 23:24:45 +0000</pubDate>
		<dc:creator>jeremy</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[work]]></category>

		<guid isPermaLink="false">http://evilrouters.net/2008/11/15/this-is-never-good/</guid>
		<description><![CDATA[Coming in to work to see this is never good.  It wasn&#8217;t bad, it just wasn&#8217;t good.  RAID FTW!




]]></description>
			<content:encoded><![CDATA[<p>Coming in to work to see this is never good.  It wasn&#8217;t <b>bad</b>, it just wasn&#8217;t good.  <a href="http://en.wikipedia.org/wiki/Redundant_array_of_independent_disks" onclick="javascript:pageTracker._trackPageview ('/outbound/en.wikipedia.org');">RAID</a> <a href="http://www.urbandictionary.com/define.php?term=ftw" onclick="javascript:pageTracker._trackPageview ('/outbound/www.urbandictionary.com');">FTW</a>!</p>

<p><img src="http://farm4.static.flickr.com/3138/3025728525_12f50f2909.jpg" title="" border="0"><br /></p>

<p><img src="http://farm4.static.flickr.com/3012/3025728177_56d396a568.jpg" title="" border="0"></p>
<img src="http://feeds.feedburner.com/~r/evilrouters/~4/455471557" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://evilrouters.net/2008/11/15/this-is-never-good/feed/</wfw:commentRss>
		<feedburner:origLink>http://evilrouters.net/2008/11/15/this-is-never-good/</feedburner:origLink></item>
		<item>
		<title>Basic Frame Relay Lab for Dynamips</title>
		<link>http://feeds.feedburner.com/~r/evilrouters/~3/455471558/</link>
		<comments>http://evilrouters.net/2008/11/15/basic-frame-relay-lab-for-dynamips/#comments</comments>
		<pubDate>Sat, 15 Nov 2008 21:04:19 +0000</pubDate>
		<dc:creator>jeremy</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[cisco]]></category>

		<category><![CDATA[labs]]></category>

		<category><![CDATA[networking]]></category>

		<guid isPermaLink="false">http://evilrouters.net/2008/11/15/basic-frame-relay-lab-for-dynamips/</guid>
		<description><![CDATA[Last night I put together a basic frame relay lab for dynamips, made up of three routers:  one hub and two spokes.  I&#8217;m sure there are a thousand others out there like it but I was putting something together to get a friend started on dynamips and it&#8217;s what I came up with.

First, [...]]]></description>
			<content:encoded><![CDATA[<p>Last night I put together a basic <a href="http://en.wikipedia.org/wiki/Frame_Relay" onclick="javascript:pageTracker._trackPageview ('/outbound/en.wikipedia.org');">frame relay</a> lab for <a href="http://www.ipflow.utc.fr/index.php/Cisco_7200_Simulator" onclick="javascript:pageTracker._trackPageview ('/outbound/www.ipflow.utc.fr');">dynamips</a>, made up of three routers:  one hub and two spokes.  I&#8217;m sure there are a thousand others out there like it but I was putting something together to get a friend started on dynamips and it&#8217;s what I came up with.</p>

<p>First, the physical topology:</p>

<p><center><img src="http://evilrouters.net/wp-content/uploads/2008/11/basic-frame-relay.png" border="0" alt="" /></center></p>

<p>R1 is our hub router and R2 and R3 are our spoke routers.  Each router has loopback0 configured with an IP address of 172.16.x.x and each&#8217;s serial0/0 interface is configured with an IP address of 172.16.123.x, &#8220;x&#8221; being the router number (1/2/3), of course.  We also throw <a href="http://en.wikipedia.org/wiki/EIGRP" onclick="javascript:pageTracker._trackPageview ('/outbound/en.wikipedia.org');">EIGRP</a> into the mix to get full connectivity between devices (we&#8217;ll need full connectivity for my next lab).</p>

<p><a href="http://dynagen.org/" onclick="javascript:pageTracker._trackPageview ('/outbound/dynagen.org');">Dynagen</a> .net file:</p>

<pre><code>autostart = false

[localhost:7200]

     workingdir = /home/jlgaddis/dynamips/working/frame-relay

     [[3640]]
          image = /home/jlgaddis/dynamips/ios/c3640-jk9o3s-mz.123-14.T7.img
          idlepc = 0x60530abc
          ram = 128
          disk0 = 8
          disk1 = 0
          mmap = true
          ghostios = true

     [[ROUTER R1]]
          model = 3640
          console = 2000
          slot0 = NM-4T
          s0/0 = FR 1

     [[ROUTER R2]]
          model = 3640
          console = 2001
          slot0 = NM-4T
          s0/0 = FR 2

     [[ROUTER R3]]
          model = 3640
          console = 2002
          slot0 = NM-4T
          s0/0 = FR 3

     [[FRSW FR]]
          1:102 = 2:201
          1:103 = 3:301
</code></pre>

<p>R1 Configuration:</p>

<pre><code>hostname R1
!
interface loopback 0
 ip address 172.16.1.1 255.255.255.255
!
interface serial 0/0
 encapsulation frame-relay
 no frame-relay inverse-arp
 ip address 172.16.123.1 255.255.255.0
 frame-relay map ip 172.16.123.2 102 broadcast
 frame-relay map ip 172.16.123.3 103 broadcast
 no ip split-horizon eigrp 123
 no shutdown
!
router eigrp 123
 network 172.16.1.1 0.0.0.0
 network 172.16.123.0 0.0.0.255
!
</code></pre>

<p>R2 Configuration:</p>

<pre><code>hostname R2
!
interface loopback 0
 ip address 172.16.2.2 255.255.255.255
!
interface serial 0/0
 encapsulation frame-relay
 no frame-relay inverse-arp
 ip address 172.16.123.2 255.255.255.0
 frame-relay map ip 172.16.123.1 201 broadcast
 frame-relay map ip 172.16.123.3 201
 no shutdown
!
router eigrp 123
 network 172.16.2.2 0.0.0.0
 network 172.16.123.0 0.0.0.255
!
</code></pre>

<p>R3 Configuration:</p>

<pre><code>hostname R3
!
interface loopback 0
 ip address 172.16.3.3 255.255.255.255
!
interface serial 0/0
 encapsulation frame-relay
 no frame-relay inverse-arp
 ip address 172.16.123.3 255.255.255.0
 frame-relay map ip 172.16.123.1 301 broadcast
 frame-relay map ip 172.16.123.2 301
 no shutdown
!
router eigrp 123
 network 172.16.3.3 0.0.0.0
 network 172.16.123.0 0.0.0.255
!
</code></pre>

<p>Now that everything is up and running, let&#8217;s verify that we have full connectivity between our three routers:</p>

<pre><code>R1#ping 172.16.123.2

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 172.16.123.2, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 16/23/36 ms
R1#ping 172.16.123.3

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 172.16.123.3, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 12/17/20 ms
R1#show ip route eigrp
     172.16.0.0/16 is variably subnetted, 4 subnets, 2 masks
D       172.16.3.3/32 [90/2297856] via 172.16.123.3, 00:01:17, Serial0/0
D       172.16.2.2/32 [90/2297856] via 172.16.123.2, 00:01:17, Serial0/0
</code></pre>

<pre><code>R2#ping 172.16.123.3

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 172.16.123.3, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 16/30/48 ms
R2#ping 172.16.3.3

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 172.16.3.3, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 16/29/44 ms
</code></pre>

<pre><code>R3#ping 172.16.2.2 source 172.16.3.3

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 172.16.2.2, timeout is 2 seconds:
Packet sent with a source address of 172.16.3.3
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 24/31/40 ms
</code></pre>

<p>Success!  We have full connectivity across our <a href="http://en.wikipedia.org/wiki/Frame_Relay" onclick="javascript:pageTracker._trackPageview ('/outbound/en.wikipedia.org');">frame relay</a> network.  My next lab will be covering how to set up an <a href="http://en.wikipedia.org/wiki/IPsec" onclick="javascript:pageTracker._trackPageview ('/outbound/en.wikipedia.org');">IPSec</a> site-to-site <a href="http://en.wikipedia.org/wiki/Virtual_private_network" onclick="javascript:pageTracker._trackPageview ('/outbound/en.wikipedia.org');">VPN</a> between R2 and R3 to encrypt our data in transit.</p>
<img src="http://feeds.feedburner.com/~r/evilrouters/~4/455471558" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://evilrouters.net/2008/11/15/basic-frame-relay-lab-for-dynamips/feed/</wfw:commentRss>
		<feedburner:origLink>http://evilrouters.net/2008/11/15/basic-frame-relay-lab-for-dynamips/</feedburner:origLink></item>
		<item>
		<title>HELL BID SC</title>
		<link>http://feeds.feedburner.com/~r/evilrouters/~3/455471559/</link>
		<comments>http://evilrouters.net/2008/11/12/hell-bid-sc/#comments</comments>
		<pubDate>Wed, 12 Nov 2008 06:10:25 +0000</pubDate>
		<dc:creator>jeremy</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[cisco]]></category>

		<category><![CDATA[labs]]></category>

		<category><![CDATA[networking]]></category>

		<guid isPermaLink="false">http://evilrouters.net/2008/11/12/hell-bid-sc/</guid>
		<description><![CDATA[The first time that you boot up a Cisco router without a startup-configuration (for example, after a &#8220;write erase&#8221; and a &#8220;reload&#8221;), there are a list of commands that should be executed for a basic configuration of the router.

Remembering this list of commands is made easier by the acronym &#8220;HELL BID SC&#8221;:


hostname
enable secret
line con 0
line [...]]]></description>
			<content:encoded><![CDATA[<p>The first time that you boot up a Cisco router without a startup-configuration (for example, after a &#8220;write erase&#8221; and a &#8220;reload&#8221;), there are a list of commands that should be executed for a basic configuration of the router.</p>

<p>Remembering this list of commands is made easier by the acronym &#8220;HELL BID SC&#8221;:</p>

<ul>
<li>hostname</li>
<li>enable secret</li>
<li>line con 0</li>
<li>line vty 0 4</li>
<li>banner motd</li>
<li>interfaces and descriptions</li>
<li>show running-config</li>
<li>copy run start</li>
</ul>
<img src="http://feeds.feedburner.com/~r/evilrouters/~4/455471559" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://evilrouters.net/2008/11/12/hell-bid-sc/feed/</wfw:commentRss>
		<feedburner:origLink>http://evilrouters.net/2008/11/12/hell-bid-sc/</feedburner:origLink></item>
		<item>
		<title>south park mac vs. pc</title>
		<link>http://feeds.feedburner.com/~r/evilrouters/~3/455471560/</link>
		<comments>http://evilrouters.net/2008/10/28/south-park-mac-vs-pc/#comments</comments>
		<pubDate>Tue, 28 Oct 2008 20:21:16 +0000</pubDate>
		<dc:creator>jeremy</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[apple]]></category>

		<category><![CDATA[funny]]></category>

		<category><![CDATA[microsoft]]></category>

		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">http://evilrouters.net/2008/10/28/south-park-mac-vs-pc/</guid>
		<description><![CDATA[a parody of the mac vs. pc commercials with south park characters.  created as the final project for a multimedia production class at california state university northridge (csun).


]]></description>
			<content:encoded><![CDATA[<p>a parody of the <a href="http://www.apple.com/getamac/" title="Apple - Get a Mac">mac vs. pc</a> commercials with <a href="http://www.southparkstudios.com/" title="South Park Studios">south park</a> characters.  created as the final project for a multimedia production class at <a href="http://www.csun.edu/" title="California State University, Northridge">california state university northridge</a> (csun).</p>

<p><center><object width="425" height="344"><param name="movie" value="http://www.youtube.com/v/Id_kGL3M5Cg&#038;hl=en&#038;fs=1"></param><param name="allowFullScreen" value="true"></param><embed src="http://www.youtube.com/v/Id_kGL3M5Cg&#038;hl=en&#038;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" width="425" height="344"></embed></object></center></p>
<img src="http://feeds.feedburner.com/~r/evilrouters/~4/455471560" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://evilrouters.net/2008/10/28/south-park-mac-vs-pc/feed/</wfw:commentRss>
		<feedburner:origLink>http://evilrouters.net/2008/10/28/south-park-mac-vs-pc/</feedburner:origLink></item>
		<item>
		<title>new cisco certification security tip line</title>
		<link>http://feeds.feedburner.com/~r/evilrouters/~3/455471561/</link>
		<comments>http://evilrouters.net/2008/10/15/new-cisco-certification-security-tip-line/#comments</comments>
		<pubDate>Thu, 16 Oct 2008 02:01:41 +0000</pubDate>
		<dc:creator>jeremy</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[cisco]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://evilrouters.net/2008/10/15/new-cisco-certification-security-tip-line/</guid>
		<description><![CDATA[
  &#8220;We just launched a new alias for reporting certification security issues.  It&#8217;s security-tipline@external.cisco.com.&#8221;
  
  &#8220;Please use this for submitting any issues of exam theft or cheating.&#8221;


&#8211;cris cohen, from a post on linkedin.
]]></description>
			<content:encoded><![CDATA[<blockquote>
  <p>&#8220;We just launched a new alias for reporting certification security issues.  It&#8217;s security-tipline@external.cisco.com.&#8221;</p>
  
  <p>&#8220;Please use this for submitting any issues of exam theft or cheating.&#8221;</p>
</blockquote>

<p>&#8211;cris cohen, from a post on <a href="http://www.linkedin.com/" title="LinkedIn: Relationships Matter">linkedin</a>.</p>
<img src="http://feeds.feedburner.com/~r/evilrouters/~4/455471561" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://evilrouters.net/2008/10/15/new-cisco-certification-security-tip-line/feed/</wfw:commentRss>
		<feedburner:origLink>http://evilrouters.net/2008/10/15/new-cisco-certification-security-tip-line/</feedburner:origLink></item>
	</channel>
</rss>
