Vault7: CIA Hacking Tools Revealed
Navigation: » Latest version
Owner: User #11629142
RANCID
Following is paraphrased from a CWE email from User #14587667 (1/22/15):
RANCID is up & running in the NDBNetwork Devices Branch lab. Currently it is "monitoring" the NDBNetwork Devices Branch Lab BB_Switch (192.168.0.5) and the Test Range Core Switch (192.168.128.14). The network device configs are queried every hour, and they are saved if there are changes. The current config, previous configs, and config changes can be viewed by accessing the RANCID server's web page.
To access the RANCID web page from DEVLAN or the NDBNetwork Devices Branch Lab, open a browser & go to:
http://10.9.9.70/viewvc/networking/configs
You will see a listing of IP addresses for each device. If you click on one of the IP addresses, you can view the revision history and the differences from the previous config versions.
Note: When viewing a config it will also include information regarding VLANs, interfaces, etc. The current config (result of the "sho run" command) starts after this other information.
If you go back to the main page (http://10.9.9.70/viewvc/networking/configs) and click on the "Rev" number for a specific device, it will show the most recently queried config running on the device. The "Age" column will let you know the last time the device's config was modified. Since RANCID only polls the network devices every hour (at the top of the hour), don't be alarmed if updates don't appear on the web page immediately after making a config change.
If you are on one of the NDBNetwork Devices Branch Lab workstations, you can also access the RANCID web page by using the server's DNSDomain Name System name (this will not work from DEVLAN since we cannot add DNSDomain Name System entries on DEVLAN). The DNSDomain Name System entry for accessing the RANCID web page is: http://rancid.loki/lab/viewvc/networking/configs).