RE: SNMP worm?

From: Frank Knobbe (frank_at_knobbe.us)
Date: 10/27/05

  • Next message: hein_at_blubber.com: "Re: RE: SNMP worm?"
    To: gillettdavid@fhda.edu, incidents@securityfocus.com
    Date: Thu, 27 Oct 2005 03:07:01 -0500
    
    
    

    On Wed, 2005-10-26 at 21:52 -0400, Robert MacDonald wrote:
    > None here (yet). Possible a contractor or vendor showing off network
    > solution-wares? Does it appear to be polling sequentially or
    > randomly? Is it looking through particular subnets? Is it possibly a
    > new printer(s) that have been plugged in or gone wild?

    Another possibility is a misconfigured network management station. I
    remember one incident in the past where a certain subnet got routinely
    scanned from one particular box, which was named like
    "netmon.noc.company.com". We notified the contact of that domain and
    kept an eye on it. Eventually the flood stopped, so perhaps someone
    noticed that a netmask was entered wrong :)

    What was that saying about not attributing malice to something that can
    be explained with stupidity? :)

    Cheers,
    Frank

    
    



  • Next message: hein_at_blubber.com: "Re: RE: SNMP worm?"

    Relevant Pages

    • Re: Anonymizing Packets yet ensuring 0 % packet loss
      ... exercise of mine is to by pass the security systems in place & prove ... you need anything that needs a reply from the network, ... We do not want the administration to say that " we could have stopped ... enumerate the services, administration subnets, department subnets, ...
      (Pen-Test)
    • Re: Anonymizing Packets yet ensuring 0 % packet loss
      ... exercise of mine is to by pass the security systems in place & prove ... you need anything that needs a reply from the network, ... We do not want the administration to say that " we could have stopped ... enumerate the services, administration subnets, department subnets, ...
      (Security-Basics)
    • Re: Multi NIC Windows 2003 routing problem
      ... You cannot use two IP#s from different subnets on the same NIC unless it is ... > All network traffic destined for the 192.168.20.x and 192.168.90.x should ... (still does, but that server has to go, for obvious reasons). ... >> Microsoft Windows XP - Multihoming Considerations ...
      (microsoft.public.win2000.networking)
    • Re: Anonymizing Packets yet ensuring 0 % packet loss
      ... exercise of mine is to by pass the security systems in place & prove ... you need anything that needs a reply from the network, ... We do not want the administration to say that " we could have stopped ... enumerate the services, administration subnets, department subnets, ...
      (Pen-Test)
    • Re: Anonymizing Packets yet ensuring 0 % packet loss
      ... exercise of mine is to by pass the security systems in place & prove ... you need anything that needs a reply from the network, ... We do not want the administration to say that " we could have stopped ... enumerate the services, administration subnets, department subnets, ...
      (Security-Basics)