Re: snmp & security

From: Seth Arnold (sarnold@marcelothewonderpenguin.com)
Date: 11/15/01


Date: Thu, 15 Nov 2001 11:34:23 -0800
From: Seth Arnold <sarnold@marcelothewonderpenguin.com>
To: focus-linux@securityfocus.com
Subject: Re: snmp & security
Message-ID: <20011115113423.V1108@wirex.com>


On Thu, Nov 15, 2001 at 11:43:34AM +0100, Steffen Dettmer wrote:
> With xqsss2 as community. But I never found if this is secure or
> not. Instead of ".1" you should specify as much of the MIB you
> can, in that case no other MIBs should be requestable.

It depends entirely upon your definition of 'secure'. :)

If all the data in the snmp system is readonly, and fine to be public
knowledge, this isn't so bad.

However, one still has those pesky bufferoverflows in snmp daemons. So,
be sure you don't mind people running arbitrary code as whatever user
runs your snmp daemons. Making sure there are no files writable to the
snmp daemon is a good first step. :)

Have fun

-- 
The Bill of Rights: 7 out of 10 rights haven't been sold yet! Contact
your congressman for details how *you* can buy one today!




Relevant Pages

  • Re: snmp & security
    ... > possible to secure it? ... snmp insecurities are numerous. ... IPsec makes a perfect choice here. ... security you'll need for safe SNMP on a live network. ...
    (Focus-Linux)
  • RE: SNMP security
    ... Subject: SNMP security ... using SNMP in a secure environment. ... but the SNMP communities are long and not easily ...
    (Security-Basics)
  • Re: SNMP configuration
    ... There do exist ubiquitously used default community strings for SNMP ... This only goes on devices and agents that support ... The easiest way to secure ...
    (comp.unix.bsd.freebsd.misc)
  • RE: Rights for SNMP service
    ... My problem is that I don't know how to access the settings of the SNMP ... public, Rights READ WRITE. ... I need to verify these values from my app and if the public community is ...
    (microsoft.public.dotnet.languages.csharp)