[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[cobalt-security] Locked out of used cobalt raq3
- Subject: [cobalt-security] Locked out of used cobalt raq3
- From: "Dave Ward" <dward@xxxxxxxxxxx>
- Date: Fri, 30 May 2003 08:21:17 -0400
- List-id: Mailing list for users to address network security on Cobalt products. <cobalt-security.list.cobalt.com>
We have recently purchased a Cobalt RaQ3 off of eBay. Unfortunately, the
server was locked down pretty tight and the password(s) are unknown.
I am trying to gain access to the system but have not been unable to do so
due to the following:
(I am hooked up with a crossconnect to my laptop as well as serial to
console port, I can ping the IP.)
1) It appears that the web admin gui is disabled or modified since no site
comes up when addressing with any of the following:
http://10.0.1.2/
http://10.0.1.2/admin/
http://10.0.1.2:81/.cobalt/sysManage/index.html
I setup my host file on my laptop with the original hostname and ip and
tried those as well:
http://www.domain.com/
http://www.domain.com/admin/
http://www.domain.com:81/.cobalt/sysManage/index.html
2) I tried telnetting but telnet must be disabled as it does not respond.
3) I reset the password for admin using the paperclip in the front panel and
then tried ssh using ttssh.exe as well as ssh1 & ssh2 using SecureCRT
trying a variety of passwords at the prompt.
admin root
admin admin
admin <null>
root root
root admin
root <null>
as well as a number of other guesses.
4) I tried using the console port but it only shows the startup as it is
rebooting and never shows me a prompt or responds to any commands. A fix
was posted on this list but it is necessary to modify /etc/inittab in order
to correct this problem - Catch22!)
5) FTP must be turned off as it doesn't respond.
Any suggestions would be greatly appreciated.
Thanks,
Dave