Re:snmp

From: Ghaith Nasrawi (libero_at_aucegypt.edu)
Date: 09/27/04

  • Next message: Rob Shein: "RE: Wireless Scanning"
    Date: Mon, 27 Sep 2004 00:11:16 +0000
    To: "pen-test" <pen-test@securityfocus.com>
    
    

    I'd suggest you start looking for some free MIB browsers which enable
    you to retrieve information from SNMP enabled devices with clear text
    community strings.

    quick search on goolge gave me this

    iReasoning MIB Browser V1.0
    (Freeware)
    http://www.ireasoning.com/mibbrowser.shtml

    There other licensed and free browsers you can use. A very interesting
    package to use would be MRTG
    http://people.ee.ethz.ch/~oetiker/webtools/mrtg/

    ---------- Initial Header -----------

    From : &quot;Juan B&quot; juanbabi@yahoo.com
    To : pen-test@securityfocus.com
    Cc :
    Date : Wed, 22 Sep 2004 15:07:03 -0700 (PDT)
    Subject : snmp

    > HI,
    >
    >
    >
    > I am responsible of the security in my company.
    >
    >
    >
    > One of the sysadmins told me that they use in one of
    > the networks Snmp and that the community is public.
    >
    >
    >
    > I want to pen test this issue meaning that I want to
    > find ways to retrieve from the devices info, and show
    > the IT manager that he must change the community.
    >
    >
    >
    > The reason that I want to do It my self is that I
    > don't believe in the way that is just going to him and
    > tell him..." its written in the internet that we must
    > change public community to something else.
    >
    >
    >
    > So how or from where do I start ?
    >
    >
    >
    > Thanks
    >
    >
    >
    > juan
    >
    > =====
    > Juan Fernandez.
    >
    > Security Engineer
    >
    > Tel: +972-52-4306781
    > Mcse Ccna Ccsa Scsa
    >
    >
    >
    >
    > __________________________________
    > Do you Yahoo!?
    > New and Improved Yahoo! Mail - 100MB free storage!
    > http://promotions.yahoo.com/new_mail
    >
    >
    ------------------------------------------------------------------------------
    > Ethical Hacking at the InfoSec Institute. All of our class sizes are
    > guaranteed to be 12 students or less to facilitate one-on-one
    interaction
    > with one of our expert instructors. Check out our Advanced Hacking
    course,
    > learn to write exploits and attack security infrastructure. Attend a
    course
    > taught by an expert instructor with years of in-the-field pen testing
    > experience in our state of the art hacking lab. Master the skills of an
    > Ethical Hacker to better assess the security of your organization.
    >
    > http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    >
    -------------------------------------------------------------------------------
    >
    >

    ------------------------------------------------------------------------------
    Ethical Hacking at the InfoSec Institute. All of our class sizes are
    guaranteed to be 12 students or less to facilitate one-on-one interaction
    with one of our expert instructors. Check out our Advanced Hacking course,
    learn to write exploits and attack security infrastructure. Attend a course
    taught by an expert instructor with years of in-the-field pen testing
    experience in our state of the art hacking lab. Master the skills of an
    Ethical Hacker to better assess the security of your organization.

    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    -------------------------------------------------------------------------------


  • Next message: Rob Shein: "RE: Wireless Scanning"

    Relevant Pages

    • [NEWS] D-Link DWL-1000AP can be Compromised Due to Insecure SNMP Configuration
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... allows an attacker to gain the administrative password using a simple SNMP ... A MIB walk using the read-only SNMP community of 'public' (default ... read-only community for most devices) can allow an attacker access to the ...
      (Securiteam)
    • Re: snmp
      ... if the devices support community name as ... > I am responsible of the security in my company. ... > Ethical Hacking at the InfoSec Institute. ... Check out our Advanced Hacking course, ...
      (Pen-Test)
    • RE: snmp
      ... There are SNMP Tools that will allow you to view data and with the ... I am responsible of the security in my company. ... Ethical Hacking at the InfoSec Institute. ... Hacking course, learn to write exploits and attack security ...
      (Pen-Test)
    • RE: snmp
      ... Subject: snmp ... though none of them will dare to join the security bizness unless they ... >> Ethical Hacking at the InfoSec Institute. ... Check out our Advanced Hacking ...
      (Pen-Test)
    • Re: SNMP security
      ... The S stands for simple not secure, especially when the community names ... with SNMP read-write doesn't justify to loosen the security on a harden ... If Micorosoft could have their SNMP conform to v3 standard it will be much ... the opinions expressed in this opinion do not necessarily ...
      (microsoft.public.windows.server.security)