Re: SNMP



Mauroreggio@xxxxxxxxx writes:

Hi all.
I try read many about this protocol, but i've one simple question for
all the expert that desire help me:
What do you think about the use of SNMP protocol in READONLY MODE for
monitor distributed geographic network with one single point (Zenoss
box, in this case).
I mean, is really so bad for security, in your experience, have
packets that go around the network that give me the state of the
machine that i monitor?

There are a couple of concerns. One is that SNMP mibs can reveal an
awful lot of information about the internal network that might not
otherwise be available. Are you comfortable with giving attackers
that information?

Also, suppose there is something allowing read/write mode to that
snmpd... its password goes across in the clear.

Are you logging or acting on brute force attacks against the daemon?

Are you willing to trust that the daemon on that box won't end up
having some sort of vulnerbaility for which an exploit could be
developed leading to the root compromise of the device?

If you can get comfortable on those fronts, then it's acceptable
risk... but generally speaking, it's a bad idea to allow snmp from
unauthenticated anonymous internet hosts.


--
Todd H.
http://www.toddh.net/
.



Relevant Pages

  • Re: 2503/WS-1103 intermittant ping
    ... blade installed on my network. ... The router seems to perform OK except ... when I ping the ethernet connection, I only get back every other ping. ... BRI0 is administratively down, line protocol is down ...
    (comp.dcom.sys.cisco)
  • 2503/WS-1103 intermittant ping
    ... I installed a 2503/WS-1103 which is a catalyst 3200 with a router ... blade installed on my network. ... BRI0 is administratively down, line protocol is down ... IP fast switching on the same interface is disabled ...
    (comp.dcom.sys.cisco)
  • CERT Advisory CA-2002-03 Multiple Vulnerabilities in Many Implementations
    ... Products from a very wide variety of vendors may be affected. ... Many other systems making use of SNMP may also be vulnerable but were ... Numerous vulnerabilities have been reported in multiple vendors' SNMP ... The Simple Network Management Protocol is a widely deployed ...
    (Cert)
  • CERT Advisory CA-2002-03 Multiple Vulnerabilities in Many Implementations
    ... Products from a very wide variety of vendors may be affected. ... Many other systems making use of SNMP may also be vulnerable but were ... Numerous vulnerabilities have been reported in multiple vendors' SNMP ... The Simple Network Management Protocol is a widely deployed ...
    (Cert)
  • CERT Advisory CA-2002-03 Multiple Vulnerabilities in Many Implementations (fwd)
    ... CERT Advisory CA-2002-03 Multiple Vulnerabilities in Many ... Products from a very wide variety of vendors may be affected. ... Many other systems making use of SNMP may also be vulnerable but were ... The Simple Network Management Protocol is a widely deployed ...
    (Focus-Microsoft)