solarwinds  |  thwack
in
Search 44,769 posts and 623 resources contributed by 21,547 members or post a topic.

Already Joined? Sign in
View Configurations from Orion Website

rated by 0 users
Not Answered This post has 0 verified answers | 34 Replies | 10 Followers


443 Posts
Points 2,234
Moderator
SolarWinds Employee
Haley posted on 05-30-2007 6:37 PM
rated by 0 users

We commonly receive requests to be able to view configurations, config change reports, and inventory reports from the Cirrus Configuration Manager from the Orion web console. 

This feature has been available in the Additional Components section of the Customer Area for quite some time but many users were not aware of its existence.  To make it easier, I have included links to the two additional components below. 

View Configs from the Orion Website:

 ftp://ftp.solarwinds.net/cmb03/cirrus/ConfigListing.zip

View Cirrus Reports from the Orion Website:

 ftp://ftp.solarwinds.net/cmb03/cirrus/Cirrus-Reports-View.zip

     

Haley Oyler Project Manager SolarWinds
  • | Post Points: 7

All Replies


829 Posts
Points 2,649
BryanBecker replied on 06-05-2007 12:11 PM
rated by 0 users

How does this work when your Cirrus server and Orion server are separate boxes?  Furthermore in our design the server running the Orion web site is in a DMZ.

TIA.

BB

 

(1) Orion V9.1 SLX running Web Site
(4) Orion V9.1 SLX remote pollers
(2) NCM (Cirrus) V5.0 SLX MS SQL2005 x64 EE
VoIP Monitor
NetFlow Traffic Analysis
13000+ elements

  • | Post Points: 3

895 Posts
Points 2,445
aLTeReGo replied on 06-05-2007 3:31 PM
rated by 0 users

This may not be as cool, or it might be ever cooler, depending on your point of view. You can create a custom link in Orion to view the running or startup configuration of any Cisco device running the http daemon with the following links, no Cirrus needed

 

https://${nodename}/level/15/exec/-/show/running-config/CR

https://${nodename}/level/15/exec/-/show/startup-config/CR

  • | Post Points: 5

392 Posts
Points 4,042
Mithrilhall replied on 06-06-2007 7:35 AM
rated by 0 users
Nice aLTeReGo.
--------------------------------------------------------------------- :::MasterShaper::: - Network Traffic Under Control
  • | Post Points: 3

1,385 Posts
Points 3,033
Network_Guru replied on 06-06-2007 8:41 PM
rated by 0 users

 Have a look here for more info on configuring your Cisco devices to allow HTTP(S) uploads & downloads.
You can even configure your devices using this method.
 

-=Cheers=-
NG

---Orion V8.1 SLX, SLX secondary poller, SQL2005 x64 SE, 14GB Ram, 12k+ elements and counting---
---Orion V9.1 SP2 SL2000, SQL2005 Express 866 elements and counting---

  • | Post Points: 3

392 Posts
Points 4,042
Mithrilhall replied on 06-12-2007 8:46 AM
rated by 0 users
So, can this work if Cirrus & Orion are on different boxes?
--------------------------------------------------------------------- :::MasterShaper::: - Network Traffic Under Control
  • | Post Points: 5

829 Posts
Points 2,649
BryanBecker replied on 06-14-2007 8:28 PM
rated by 0 users

Mithrilhall:
So, can this work if Cirrus & Orion are on different boxes?
 

That's what I want to know.  We have 2 Cirrus boxes, 1 Orion NPM and 4 Orion pollers.  All of them connect to 1 DB server but they have seperate DBs.

BB
 

(1) Orion V9.1 SLX running Web Site
(4) Orion V9.1 SLX remote pollers
(2) NCM (Cirrus) V5.0 SLX MS SQL2005 x64 EE
VoIP Monitor
NetFlow Traffic Analysis
13000+ elements

  • | Post Points: 1

443 Posts
Points 2,234
Moderator
SolarWinds Employee
Haley replied on 06-21-2007 12:49 PM
rated by 0 users
The ability to view Cirrus Configs and Reports from the Orion website currently works as long as the Orion server has a mapped drive to the Cirrus server and vice versa. The integration pulls the configs that are saved using the Config Archive feature and reports that are exported as html.
Haley Oyler Project Manager SolarWinds
  • | Post Points: 5

83 Posts
Points 224
Malvado replied on 06-21-2007 3:00 PM
rated by 0 users

Is there any way to get the reports to show up without having to download the files everyday? We only download the files when there is a change.

  • | Post Points: 3

443 Posts
Points 2,234
Moderator
SolarWinds Employee
Haley replied on 06-21-2007 3:15 PM
rated by 0 users
The resources currently display the config download for the day. However, config listing resource is editable so you change which configs are displayed by default.
Haley Oyler Project Manager SolarWinds
  • | Post Points: 3

83 Posts
Points 224
Malvado replied on 06-21-2007 3:36 PM
rated by 0 users

Great News...

How would you do that so it shows the last downloaded config?

  • | Post Points: 3

443 Posts
Points 2,234
Moderator
SolarWinds Employee
Haley replied on 06-21-2007 5:27 PM
rated by 0 users
Unfortunately, these resources are not documented so we do not have instructions for modifying the resources. They are like the other Orion resources in that users that are familiar with SQL and ASP should be able to make changes. The default location for resource files is C:\Inetpub\SolarWinds\NetPerfMon\Resources. Each resource file can be opened with a text editor. I recommend making a copy of the resource file before editing.
Haley Oyler Project Manager SolarWinds
  • | Post Points: 1

34 Posts
Points 81
rdeprez replied on 07-02-2007 6:12 PM
rated by 0 users

Haley:

We commonly receive requests to be able to view configurations, config change reports, and inventory reports from the Cirrus Configuration Manager from the Orion web console. 

This feature has been available in the Additional Components section of the Customer Area for quite some time but many users were not aware of its existence.  To make it easier, I have included links to the two additional components below. 

View Configs from the Orion Website:

 ftp://ftp.solarwinds.net/cmb03/cirrus/ConfigListing.zip

View Cirrus Reports from the Orion Website:

 ftp://ftp.solarwinds.net/cmb03/cirrus/Cirrus-Reports-View.zip

     

 

I downloaded the Config listing enhancement and followed the install instructions. It was working fine and then I noticed that adding this code creates an ENORMOUS security hole in Orion. I hope the Solarwinds engineers take notice of this and fix it immediately.

First off, the page accepts un-validated strings to display files on the local server using the permissions of the user running IIS. This allows you to trivially modify the path to the config to something more interesting like the Windows SAM, the hosts file, or any number of XSS vulnerabilites. The page will happily display it.

EVEN WORSE, there is no validation being done that the user is even logged into ORION. So esentially it opens up annonymous file browsing of the entire server and all of the configs you have stored on it.

I have made some changes to the ConfigListing.asp that will validate that the user is logged in and validate the input at least matches the first 5 levels of the directory tree where the configs exist. As you read the code please keep in mind I am not a developer so this is probably very ugly, and may itself have it's own flaws but it at least addresses the problems I outlined above.(not 100% sure this resolves all XSS though) 

 

Save this text into ConfigListing.asp and use it instead of the one provided by SolarWinds. Alter the variables used in the "vpath" array to match the first 5 levels of where you are storing your configs. In this it will expect the configs to be in d:\Program Files\SolarWinds\Configuration Management\Config-Archive

<!--#include Virtual=/NetPerfMon/scripts/NetPerfMon.asp -->

<html>

<head>

<meta http-equiv="Content-Type" content="text/html; charset=windows-1252">

<title>Cirrus Device Configuration</title>

</head>

<body>

<pre>

<%

dim fs,f,ts,passedstring,pathArray,vpath(5)

set fs=Server.CreateObject("Scripting.FileSystemObject")

passedstring=(request.querystring)

pathArray=Split(passedstring,"\")

vpath(0)="file=D:"

vpath(1)="Program%20Files"

vpath(2)="SolarWinds"

vpath(3)="Configuration%20Management"

vpath(4)="Config-Archive"

SelectWeb("NetPerfMon")

If pathArray(0)<>vpath(0) Then

Response.Write("Invalid Filename!")

Else

If pathArray(1)<>vpath(1) Then

Response.Write("Invalid Filename!")

Else

If pathArray(2)<>vpath(2) Then

Response.Write("Invalid Filename!")

Else

If pathArray(3)<>vpath(3) Then

Response.Write("Invalid Filename!")

Else

If pathArray(4)<>vpath(4) Then

Response.Write("Invalid Filename!")

Else

If Not NetPerfMon.IsLoggedIn Then

If Not NetPerfMon.AutoLogin Then

Response.Redirect "/NetPerfMon/Login.asp"

End If

Else

If (fs.FileExists(request.querystring("file")))=true Then

Set f=fs.GetFile(request.querystring("file"))

Set ts=f.OpenAsTextStream(1)

Response.Write(ts.ReadAll)

ts.Close

set ts=nothing

set f=nothing

Else

Response.Write("File does not Exist.")

End If

End If

End If

End If

End If

End If

End If

Response.End

set fs=nothing

%>

</pre>

</body>

</html>

 


34 Posts
Points 81
rdeprez replied on 07-03-2007 2:50 PM
rated by 0 users

Haley:

We commonly receive requests to be able to view configurations, config change reports, and inventory reports from the Cirrus Configuration Manager from the Orion web console. 

This feature has been available in the Additional Components section of the Customer Area for quite some time but many users were not aware of its existence.  To make it easier, I have included links to the two additional components below. 

View Configs from the Orion Website:

 ftp://ftp.solarwinds.net/cmb03/cirrus/ConfigListing.zip

View Cirrus Reports from the Orion Website:

 ftp://ftp.solarwinds.net/cmb03/cirrus/Cirrus-Reports-View.zip

     

I just tried out the Cirrus Report viewer that is being distributed by Solarwinds and found the same issues in it as in the Config viewer which are detailed in my above post. The Changes I used to fix it are below. I hope Solarwinds notices this thread and fixes the packages they are distributing.

To ensure the user is logged in and to perform input validation to the page follow the steps provided by SolarWinds to setup viewing Cirrus Reports. Once that is complete replace the CirrusReportAction.asp file with the text below. It assumes that the path for the reports is d:\InetPub\SolarWinds\NetPerfMon\Reports. If that is not how it is in your environemnt alter the variables loaded into the vpath array to match your path.(it is case sensitive)

 

<!--#include Virtual=/NetPerfMon/scripts/NetPerfMon.asp -->

<html>

<head>

<meta http-equiv="Content-Type" content="text/html; charset=windows-1252">

<title>Cirrus Report</title>

</head>

<body>

<%

dim fs,f,ts,passedstring,pathArray,vpath(5)

set fs=Server.CreateObject("Scripting.FileSystemObject")

set re=Server.CreateObject("VBScript.RegExp")

passedstring=(request.querystring)

pathArray=Split(passedstring,"\")

vpath(0)="file=D:"

vpath(1)="InetPub"

vpath(2)="SolarWinds"

vpath(3)="NetPerfMon"

vpath(4)="Reports"

SelectWeb("NetPerfMon")

If pathArray(0)<>vpath(0) Then

Response.Write("Invalid Filename!")

Else

If pathArray(1)<>vpath(1) Then

Response.Write("Invalid Filename!")

Else

If pathArray(2)<>vpath(2) Then

Response.Write("Invalid Filename!")

Else

If pathArray(3)<>vpath(3) Then

Response.Write("Invalid Filename!")

Else

If pathArray(4)<>vpath(4) Then

Response.Write("Invalid Filename!")

Else

If Not NetPerfMon.IsLoggedIn Then

If Not NetPerfMon.AutoLogin Then

Response.Redirect "/NetPerfMon/Login.asp"

End If

Else

If (fs.FileExists(request.querystring("file")))=true Then

Set f=fs.GetFile(request.querystring("file"))

Set ts=f.OpenAsTextStream(1)

Response.Write(ts.ReadAll)

ts.Close

set ts=nothing

set f=nothing

set fs=nothing

Else

Response.Write("File does not Exist.")

End If

End If

End If

End If

End If

End If

End If

%>

</body>

</html>

 


443 Posts
Points 2,234
Moderator
SolarWinds Employee