4 ms·
You're secure if you don't expose SNMP. Can't believe there are that many devices out there with that exposed though.
by Group_B 1y ago
You're secure if you don't expose SNMP. Can't believe there are that many devices out there with that exposed though.
- FuriouslyAdrift 1y agogood old SNMP v1 private/private
- duxup 1y agoIt's damned if you do damned if you don't. For smaller operations I think just disabling SNMP is safer due to constant bugs and issues. On the other hand bigger operations, you gotta monitor your devices. But now you’re open to the can of worms.
- EvanAnderson 1y ago> You're secure if you don't expose SNMP. Depends what you mean by "expose". Some people could read that as "exposed to the Internet". I'm reading it as "exposed to anything". This looks like a good fun for doing lateral movement inside a network. I know of lots of environments with SNMPv2 wide open for "internal" networks to access. Plus SNMP is UDP-based, so likely the exploit will work with a one-way path and spoofed source addresses.
- deleted 1y ago[deleted]
- wil421 1y agoThere’s no way ISPs can function without SNMP. I think network management is like a 1/3 of all traffic. We process billions and billions of traps daily. These are not on internet connected networks and some have dedicated channels. How did the attacker get the community string?
- commandersaki 1y ago1/3 is a absurd, more like 1/3000.
- ronsor 1y agoMost people never change it from "public" you know. Bonus: if the "private" community is exposed on Cisco IOS, you can read and write the router's configuration.