RE: SNMP worm?

From: Robert MacDonald (Robert.MacDonald_at_Haworth.com)
Date: 10/27/05

  • Next message: Mark Ryan del Moral Talabis: "Re: SNMP worm?"
    Date: Wed, 26 Oct 2005 21:52:26 -0400
    To: <gillettdavid@fhda.edu>
    
    

    David,
     
    None here (yet). Possible a contractor or vendor showing off network
    solution-wares? Does it appear to be polling sequentially or
    randomly? Is it looking through particular subnets? Is it possibly a
    new printer(s) that have been plugged in or gone wild?
     
    This is probably a duh question, but have you been able to
    hunt down the offending workstation(s) and check them out?
     
    I'll keep on the lookout.
     
    Best of Luck.
    Robert

    ________________________________

    From: David Gillett [mailto:gillettdavid@fhda.edu]
    Sent: Wed 10/26/2005 4:56 PM
    To: incidents@securityfocus.com
     
    We're suddenly seeing a lot of unauthorized SNMP traffic, including
    some to broadcast destinations, from stations on our network that have
    no business doing that. Anyone know of a new virus/worm with that
    behaviour? (Details are still sketchy here -- I'm hoping someone else
    has seen this and can provide clues of additional symptoms to look for.)

    David Gillett


  • Next message: Mark Ryan del Moral Talabis: "Re: SNMP worm?"

    Relevant Pages

    • Re: Anonymizing Packets yet ensuring 0 % packet loss
      ... exercise of mine is to by pass the security systems in place & prove ... you need anything that needs a reply from the network, ... We do not want the administration to say that " we could have stopped ... enumerate the services, administration subnets, department subnets, ...
      (Pen-Test)
    • Re: Anonymizing Packets yet ensuring 0 % packet loss
      ... exercise of mine is to by pass the security systems in place & prove ... you need anything that needs a reply from the network, ... We do not want the administration to say that " we could have stopped ... enumerate the services, administration subnets, department subnets, ...
      (Security-Basics)
    • Re: Multiple closed networks and UDP. Please help me.
      ... Note that it makes absolutely no sense to have three identical subnets connected to the ... protocol does not provide any capability for distinguishing network adapters. ... I have worked with TCP many times, but never UDP. ... I believe that the TCP connection will be assigned based on the IP ...
      (microsoft.public.vc.mfc)
    • Re: Anonymizing Packets yet ensuring 0 % packet loss
      ... exercise of mine is to by pass the security systems in place & prove ... you need anything that needs a reply from the network, ... We do not want the administration to say that " we could have stopped ... enumerate the services, administration subnets, department subnets, ...
      (Pen-Test)
    • Re: Multi NIC Windows 2003 routing problem
      ... You cannot use two IP#s from different subnets on the same NIC unless it is ... > All network traffic destined for the 192.168.20.x and 192.168.90.x should ... (still does, but that server has to go, for obvious reasons). ... >> Microsoft Windows XP - Multihoming Considerations ...
      (microsoft.public.win2000.networking)