Re: snmp & security

From: Steffen Dettmer (steffen@dett.de)
Date: 11/15/01


Date: Thu, 15 Nov 2001 11:43:34 +0100
From: Steffen Dettmer <steffen@dett.de>
To: focus-linux@securityfocus.com
Subject: Re: snmp & security
Message-ID: <20011115114334.C12933@dx.net.de>


* tenfingers@ifrance.com wrote on Sat, Nov 10, 2001 at 19:24 +0100:
 [...]
> so i would like to know the risks of having snmpd started
> is it possible to secure it ?

I've read a lot of insecurities. Of course firewall it as much
as possible and allow only one IP to connect. Some people
suggested to use cryptic community names to make scanner not
work. Maybe something like

[ucd-snmpd.conf]
com2sec xqsss2 192.168.1.123/32 public
group ROxqsss2 v1 monitor
group ROxqsss2 v2c monitor
group ROxqsss2 usm monitor
view v_xqsss2 included .1 80

access ROxqsss2 "" any noauth exact v_monitor none none

With xqsss2 as community. But I never found if this is secure or
not. Instead of ".1" you should specify as much of the MIB you
can, in that case no other MIBs should be requestable.

oki,

Steffen

-- 
Dieses Schreiben wurde maschinell erstellt,
es trägt daher weder Unterschrift noch Siegel.



Relevant Pages

  • Re: [fw-wiz] Re: Firewalls breaking stuff: [Was re: fwtk]
    ... > access to the mail server's private keys and thus the monitor can follow the ... > in a way that's more secure rather than less secure. ... for service level encryption versus VPN access. ... >> reducing bugs reduces the number of sever bugs. ...
    (Firewall-Wizards)
  • at last Copleys orthodox leaf
    ... but don't monitor the protestant ... accuse me flowing in part your sympathetic neighbourhood. ... Ikram, still compiling, ... climate after we secure to it. ...
    (sci.crypt)
  • SUMMARY: security
    ... I have managed to keep the system quite secure until now help from ... Install a package that lets you monitor the MD5 checksums of all ... There are a lot of root kits. ... Worcester State College ...
    (SunManagers)
  • Re: Hacker
    ... the "element between the monitor and the chair" to be rendered useless. ... With the types of 'attempts' that I see daily on our FTP servers (and ... default to open vs secure is the mistake that is common in MS products. ... Calling an illegal alien an "undocumented worker" is like calling a ...
    (microsoft.public.windows.server.security)
  • Re: Stolen IP Address
    ... >> House was broken in Saturday and monitor was stolen. ... > address because otherwise the web site can't send the web page to your PC. ... > Home Windows PCs are far more difficult to secure than they should be. ... Thank you Jason! ...
    (comp.security.firewalls)