IOS Crash Analysis and Rootkit Wiki

Edit

Creating a CIR Online Case

To create a case in CIR online and process a set core dump files, simply go to http://cir.recurity-labs.com and click on the Create new case button.sociology degree


On the following web page, you can upload your IOS image and the core file. You can also upload any coreiomem or corepci file if your version of IOS and your platform wrote them when dumping core.

Note: CIR Online currently runs version 1.0 of CIR. This version does not process PCI memory files yet.

Make sure you check the agreement check-box for the terms of use, as the case can only be processed if you do so.


Once your upload was successful, you will be presented with a confirmation page, similar to the one shown below.
Example acknowledgement for CIR online

Example acknowledgement for CIR online


Make sure you note down or print the case ID! Without the case ID, you will not be able to revisit your results.

Edit

Viewing your case

To view the results of your case, you can enter the case ID in the search field at http://cir.recurity.com/cir/View.aspx or simply reuse the link that was presented to you when you uploaded the case.


An example of a CIR report can be seen here:
http://cir.recurity.com/cir/case.ashx/80CEFD022D934BF363D9ABE43306607C094994C0/

Edit

Interpreting Results

For information on how to interpret CIR reports, please see Interpreting CIR Reports.

Powered by ScrewTurn Wiki, provided by Recurity Labs GmbH.