<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: How to get Root access on Call Manager 5/6 Server</title>
	<atom:link href="http://www.blindhog.net/how-to-get-root-access-on-call-manager-56-server/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.blindhog.net/how-to-get-root-access-on-call-manager-56-server/</link>
	<description>Tips and Video Tutorials - Cisco .:. Linux .:. VOIP</description>
	<lastBuildDate>Tue, 29 Nov 2011 04:01:10 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Missing CUCM Configuration Files &#124; The Networking Nerd</title>
		<link>http://www.blindhog.net/how-to-get-root-access-on-call-manager-56-server/comment-page-1/#comment-38886</link>
		<dc:creator>Missing CUCM Configuration Files &#124; The Networking Nerd</dc:creator>
		<pubDate>Thu, 18 Aug 2011 21:34:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.blindhog.net/how-to-get-root-access-on-call-manager-56-server/#comment-38886</guid>
		<description>[...] the least bit squeemish.  The first thing you should read is the great guide at blindhog.net about gaining root access on CUCM 5.x/6.x.  It&#8217;s a very handy way to show you that the underlying system in CUCM is actually RedHat [...]</description>
		<content:encoded><![CDATA[<p>[...] the least bit squeemish.  The first thing you should read is the great guide at blindhog.net about gaining root access on CUCM 5.x/6.x.  It&#8217;s a very handy way to show you that the underlying system in CUCM is actually RedHat [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Conseguindo acesso Root ao CUCM &#171; Architecture for Voice, Video and Integrated Data</title>
		<link>http://www.blindhog.net/how-to-get-root-access-on-call-manager-56-server/comment-page-1/#comment-38292</link>
		<dc:creator>Conseguindo acesso Root ao CUCM &#171; Architecture for Voice, Video and Integrated Data</dc:creator>
		<pubDate>Mon, 25 Apr 2011 18:21:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.blindhog.net/how-to-get-root-access-on-call-manager-56-server/#comment-38292</guid>
		<description>[...] http://www.blindhog.net/how-to-get-root-access-on-call-manager-56-server/ [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://www.blindhog.net/how-to-get-root-access-on-call-manager-56-server/" rel="nofollow">http://www.blindhog.net/how-to-get-root-access-on-call-manager-56-server/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sandro Gauci</title>
		<link>http://www.blindhog.net/how-to-get-root-access-on-call-manager-56-server/comment-page-1/#comment-33622</link>
		<dc:creator>Sandro Gauci</dc:creator>
		<pubDate>Tue, 01 Jun 2010 10:18:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.blindhog.net/how-to-get-root-access-on-call-manager-56-server/#comment-33622</guid>
		<description>Hi there - thanks this has been useful for us. Wanted to drop a note: Recurity labs published an alternative method to this which does not involve booting off a livecd:
http://blog.recurity-labs.com/articles/jail-breaking_cisco_unified_communication_manager/index.html


- sandro</description>
		<content:encoded><![CDATA[<p>Hi there &#8211; thanks this has been useful for us. Wanted to drop a note: Recurity labs published an alternative method to this which does not involve booting off a livecd:<br />
<a href="http://blog.recurity-labs.com/articles/jail-breaking_cisco_unified_communication_manager/index.html" rel="nofollow">http://blog.recurity-labs.com/articles/jail-breaking_cisco_unified_communication_manager/index.html</a></p>
<p>- sandro</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Unified Communications Manager 7.1(3) in VMWare &#124; دانلود بازی کلیپ موبایل موزیک فیلم</title>
		<link>http://www.blindhog.net/how-to-get-root-access-on-call-manager-56-server/comment-page-1/#comment-33611</link>
		<dc:creator>Unified Communications Manager 7.1(3) in VMWare &#124; دانلود بازی کلیپ موبایل موزیک فیلم</dc:creator>
		<pubDate>Thu, 27 May 2010 19:23:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.blindhog.net/how-to-get-root-access-on-call-manager-56-server/#comment-33611</guid>
		<description>[...] can access its underlying Linux operating system and obtain root access. There are known methods to bypass this. If you have already found a way then you may configure the virtual machine such as CUPS [...]</description>
		<content:encoded><![CDATA[<p>[...] can access its underlying Linux operating system and obtain root access. There are known methods to bypass this. If you have already found a way then you may configure the virtual machine such as CUPS [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Unified Communications Manager 7.1(3) in VMWare</title>
		<link>http://www.blindhog.net/how-to-get-root-access-on-call-manager-56-server/comment-page-1/#comment-33610</link>
		<dc:creator>Unified Communications Manager 7.1(3) in VMWare</dc:creator>
		<pubDate>Thu, 27 May 2010 17:58:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.blindhog.net/how-to-get-root-access-on-call-manager-56-server/#comment-33610</guid>
		<description>[...] can access its underlying Linux operating system and obtain root access. There are known methods to bypass this. If you have already found a way then you may configure the virtual machine such as CUPS [...]</description>
		<content:encoded><![CDATA[<p>[...] can access its underlying Linux operating system and obtain root access. There are known methods to bypass this. If you have already found a way then you may configure the virtual machine such as CUPS [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cisco CUCM/Call Manager &#8211; Running on Sun&#8217;s Virtual Box &#171; Kevsters Blog</title>
		<link>http://www.blindhog.net/how-to-get-root-access-on-call-manager-56-server/comment-page-1/#comment-33242</link>
		<dc:creator>Cisco CUCM/Call Manager &#8211; Running on Sun&#8217;s Virtual Box &#171; Kevsters Blog</dc:creator>
		<pubDate>Tue, 02 Feb 2010 23:08:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.blindhog.net/how-to-get-root-access-on-call-manager-56-server/#comment-33242</guid>
		<description>[...] Next follow the guide here http://www.blindhog.net/how-to-get-root-access-on-call-manager-56-server/ to get root access.  Make sure you use the CentOS Disk 1 rather than the Live [...]</description>
		<content:encoded><![CDATA[<p>[...] Next follow the guide here <a href="http://www.blindhog.net/how-to-get-root-access-on-call-manager-56-server/ to" rel="nofollow">http://www.blindhog.net/how-to-get-root-access-on-call-manager-56-server/ to</a> get root access.  Make sure you use the CentOS Disk 1 rather than the Live [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Amit</title>
		<link>http://www.blindhog.net/how-to-get-root-access-on-call-manager-56-server/comment-page-1/#comment-33191</link>
		<dc:creator>Amit</dc:creator>
		<pubDate>Thu, 21 Jan 2010 16:34:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.blindhog.net/how-to-get-root-access-on-call-manager-56-server/#comment-33191</guid>
		<description>I am new to Linux
I am tring to edit /usr/local/bin/base_scripts/hardware_check.sh file but I am getting error saying read only file,
can any one help me with?</description>
		<content:encoded><![CDATA[<p>I am new to Linux<br />
I am tring to edit /usr/local/bin/base_scripts/hardware_check.sh file but I am getting error saying read only file,<br />
can any one help me with?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Holloway &#187; Blog Archive &#187; Unified Communications Manager 7.1(3) in VMWare</title>
		<link>http://www.blindhog.net/how-to-get-root-access-on-call-manager-56-server/comment-page-1/#comment-32903</link>
		<dc:creator>Mark Holloway &#187; Blog Archive &#187; Unified Communications Manager 7.1(3) in VMWare</dc:creator>
		<pubDate>Wed, 18 Nov 2009 19:18:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.blindhog.net/how-to-get-root-access-on-call-manager-56-server/#comment-32903</guid>
		<description>[...] access its underlying Linux operating system and obtain root access.  There are known methods to bypass this.  If you have already found a way, then you may configure the virtual machine such as CUPS [...]</description>
		<content:encoded><![CDATA[<p>[...] access its underlying Linux operating system and obtain root access.  There are known methods to bypass this.  If you have already found a way, then you may configure the virtual machine such as CUPS [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Salman</title>
		<link>http://www.blindhog.net/how-to-get-root-access-on-call-manager-56-server/comment-page-1/#comment-27846</link>
		<dc:creator>Salman</dc:creator>
		<pubDate>Wed, 18 Mar 2009 12:25:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.blindhog.net/how-to-get-root-access-on-call-manager-56-server/#comment-27846</guid>
		<description>Thanks Pushkar for sharing this, that worked.

salman</description>
		<content:encoded><![CDATA[<p>Thanks Pushkar for sharing this, that worked.</p>
<p>salman</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Martyn</title>
		<link>http://www.blindhog.net/how-to-get-root-access-on-call-manager-56-server/comment-page-1/#comment-26990</link>
		<dc:creator>David Martyn</dc:creator>
		<pubDate>Tue, 03 Mar 2009 13:29:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.blindhog.net/how-to-get-root-access-on-call-manager-56-server/#comment-26990</guid>
		<description>I have tested this link and it works like a charm.

I am a big fan of Pushkar Bhatkoti&#039;s blog.

Link:  
http://pushkarbhatkoti.wordpress.com/2009/01/25/a-fun-with-cisco-call-manager-6x-how-to-root-access-to-ccm6x-box/

Topic: 
A fun with Cisco Call manager 6x - root access to CCM6x box

cut and paste:

January 25, 2009 at 3:55 am &#124; In CCM 5x 6x 7x stuffs &#124; &#124; Edit this post
Tags: hacking cisco call manager 6x, how to get root access to ccm ccm6x ccm7x, logging in as a root in cisco call manager

———————————————————————————————-
Duh… its 42 degree outside here in Sydney and it is also a long weekend - this sounds boreing… nothing to do outdoor.
My mind got crazy and then I thought to play with my new toy - CCM  version 6.x.
Note: before you read this please note, do not try to apply it on your production server.
Quite often, when we are working on the production server and we need access to call manager 5x 6x 7x root shell (penguin shell), we had to call bloody TAC and do wait for ages before we get access to the root shell.
Last week this happend to my friend and he told me that is there anyway to get access to the call manager root shell. He upgraded his CCM from v5 to 6x and the disk space got on ccm server got full. So he had to delete some files from ccm using LINUX shell. Somehow cisco has managed to lock it down so that no root access to the ccm appliance. I given my old method to my friend and he got access to the root shell [grub /lilo breakin method like we do to recover root password].

Today I got some time to do some research on this and found out a less effort method which you can safely apply to your production server without breaking anything related to Cisco’s software.

So using below method you would be able to access your call manager in the same fashion like TAC guys do. You don’t have to call them and wait…hehhe…

download fedora9, redhat linux 4 or above or centos disk1. burn it on a CD or dvd. this disk iwll be used in the step #3

STEP#1: Create remote account on your CUCM.
———————————————————–
ssh to your CUCM box. I use Ubuntu as a desktop, if you are billy fane you can use ssh or secureCRT.

frog# ssh administrator@142.2.64.254

you’ll get below prompt:

admin:

create a account and enable remote account to this box:

admin:utils remote_account create frog  100
admin:utils remote_account enable

noticed 100 in the above is number of days ‘frog’ username / account will be valid. If you want it forever, then just type 0

STEP#2: reboot the server:
———————————-
admin:utils system restart

STEP#3: create password for ‘frog’ remote user
———————————————————-

While server reboots, pop-in a linux booteble disk (downloaded centos or redhat first disk) to MCS server or your lab toy. When you see boot prompt type ‘linux rescue:

boot:linux rescue

That will give you the root shell access of root#

initblah#

Rescue disk mounts the CCM hard disk image as a /mnt/sysimage. Now chroot to this image to change in the /etc/ files or passwords:

#chroot /mnt/sysimage

[root#ccm-] #

Note1: if you dont’ see the root prompt and /etc/pass file, then you may need to mount your sysimage.

Note2: If you are Opensource folk and know how to penguinworks u can jump direct to step#4. Actually adding user here vs adding them when u get root# shell using a booteble CD, is that u don’t have to apply all admin groups to remote user.

according to the one of the hacker wesite, remote user must be a member of the following groups in CCM BOX:

disk, sys, adm, bin, wheel and root

STEP#4: change attribute of /etc files and create ‘frog’ user’s password:
—————————————————————————————
Cisco have locked the attribute to read only to all /etc/passwd /etc/group /etc/shadow and /etc/gshadow file to protect those files.

Make all of below files attribute from read only to read/write. So when you change ‘frog’ users password the system will let you change it.

root#chattr -i /etc/passwd
root#chattr -i /etc/shadow
root#chattr -i /etc/group
root#chattr -i /etc/gshadow

root#passwd frog 

Now restart the server: use reboot command

Dont’ forget to remove your DVD/CD from MCS server.
Once that is done, access to the ccm from your favourite ssh client. mine is ubuntu these days.

frog# ssh frog@142.2.64.254

Welcome to Remote Support

[root@CUCM6~]#
[root@CUCM6~]#
[root@CUCM6~]#

hehe… its your little linux box now. Do with it whatever you like. I will install freeRADIUS and some other cool tool like NMAP on this Cisco box.</description>
		<content:encoded><![CDATA[<p>I have tested this link and it works like a charm.</p>
<p>I am a big fan of Pushkar Bhatkoti&#8217;s blog.</p>
<p>Link:<br />
<a href="http://pushkarbhatkoti.wordpress.com/2009/01/25/a-fun-with-cisco-call-manager-6x-how-to-root-access-to-ccm6x-box/" rel="nofollow">http://pushkarbhatkoti.wordpress.com/2009/01/25/a-fun-with-cisco-call-manager-6x-how-to-root-access-to-ccm6x-box/</a></p>
<p>Topic:<br />
A fun with Cisco Call manager 6x &#8211; root access to CCM6x box</p>
<p>cut and paste:</p>
<p>January 25, 2009 at 3:55 am | In CCM 5x 6x 7x stuffs | | Edit this post<br />
Tags: hacking cisco call manager 6x, how to get root access to ccm ccm6x ccm7x, logging in as a root in cisco call manager</p>
<p>———————————————————————————————-<br />
Duh… its 42 degree outside here in Sydney and it is also a long weekend &#8211; this sounds boreing… nothing to do outdoor.<br />
My mind got crazy and then I thought to play with my new toy &#8211; CCM  version 6.x.<br />
Note: before you read this please note, do not try to apply it on your production server.<br />
Quite often, when we are working on the production server and we need access to call manager 5x 6x 7x root shell (penguin shell), we had to call bloody TAC and do wait for ages before we get access to the root shell.<br />
Last week this happend to my friend and he told me that is there anyway to get access to the call manager root shell. He upgraded his CCM from v5 to 6x and the disk space got on ccm server got full. So he had to delete some files from ccm using LINUX shell. Somehow cisco has managed to lock it down so that no root access to the ccm appliance. I given my old method to my friend and he got access to the root shell [grub /lilo breakin method like we do to recover root password].</p>
<p>Today I got some time to do some research on this and found out a less effort method which you can safely apply to your production server without breaking anything related to Cisco’s software.</p>
<p>So using below method you would be able to access your call manager in the same fashion like TAC guys do. You don’t have to call them and wait…hehhe…</p>
<p>download fedora9, redhat linux 4 or above or centos disk1. burn it on a CD or dvd. this disk iwll be used in the step #3</p>
<p>STEP#1: Create remote account on your CUCM.<br />
———————————————————–<br />
ssh to your CUCM box. I use Ubuntu as a desktop, if you are billy fane you can use ssh or secureCRT.</p>
<p>frog# ssh <a href="mailto:administrator@142.2.64.254">administrator@142.2.64.254</a></p>
<p>you’ll get below prompt:</p>
<p>admin:</p>
<p>create a account and enable remote account to this box:</p>
<p>admin:utils remote_account create frog  100<br />
admin:utils remote_account enable</p>
<p>noticed 100 in the above is number of days ‘frog’ username / account will be valid. If you want it forever, then just type 0</p>
<p>STEP#2: reboot the server:<br />
———————————-<br />
admin:utils system restart</p>
<p>STEP#3: create password for ‘frog’ remote user<br />
———————————————————-</p>
<p>While server reboots, pop-in a linux booteble disk (downloaded centos or redhat first disk) to MCS server or your lab toy. When you see boot prompt type ‘linux rescue:</p>
<p>boot:linux rescue</p>
<p>That will give you the root shell access of root#</p>
<p>initblah#</p>
<p>Rescue disk mounts the CCM hard disk image as a /mnt/sysimage. Now chroot to this image to change in the /etc/ files or passwords:</p>
<p>#chroot /mnt/sysimage</p>
<p>[root#ccm-] #</p>
<p>Note1: if you dont’ see the root prompt and /etc/pass file, then you may need to mount your sysimage.</p>
<p>Note2: If you are Opensource folk and know how to penguinworks u can jump direct to step#4. Actually adding user here vs adding them when u get root# shell using a booteble CD, is that u don’t have to apply all admin groups to remote user.</p>
<p>according to the one of the hacker wesite, remote user must be a member of the following groups in CCM BOX:</p>
<p>disk, sys, adm, bin, wheel and root</p>
<p>STEP#4: change attribute of /etc files and create ‘frog’ user’s password:<br />
—————————————————————————————<br />
Cisco have locked the attribute to read only to all /etc/passwd /etc/group /etc/shadow and /etc/gshadow file to protect those files.</p>
<p>Make all of below files attribute from read only to read/write. So when you change ‘frog’ users password the system will let you change it.</p>
<p>root#chattr -i /etc/passwd<br />
root#chattr -i /etc/shadow<br />
root#chattr -i /etc/group<br />
root#chattr -i /etc/gshadow</p>
<p>root#passwd frog </p>
<p>Now restart the server: use reboot command</p>
<p>Dont’ forget to remove your DVD/CD from MCS server.<br />
Once that is done, access to the ccm from your favourite ssh client. mine is ubuntu these days.</p>
<p>frog# ssh <a href="mailto:frog@142.2.64.254">frog@142.2.64.254</a></p>
<p>Welcome to Remote Support</p>
<p>[root@CUCM6~]#<br />
[root@CUCM6~]#<br />
[root@CUCM6~]#</p>
<p>hehe… its your little linux box now. Do with it whatever you like. I will install freeRADIUS and some other cool tool like NMAP on this Cisco box.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

