[87854] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Is my router owned? How would I know?

daemon@ATHENA.MIT.EDU (Mikael Abrahamsson)
Thu Jan 12 17:10:25 2006

Date: Thu, 12 Jan 2006 23:09:53 +0100 (CET)
From: Mikael Abrahamsson <swmike@swm.pp.se>
To: NANOG <nanog@merit.edu>
In-Reply-To: <Pine.GSO.4.62.0601121056280.20115@qentba.nf23028.arg>
Errors-To: owner-nanog@merit.edu


On Thu, 12 Jan 2006, Rob Thomas wrote:

> If there are new or changed SNMP RW community strings, look out!

If you have any SNMP v1/v2 RW communities what so ever, you're likely to 
be owned, at least if they're common to several units in your network and 
you don't limit what part of the tree the RW communities can access.

Seems like a common attack vector is to send SNMP WRITE and upload the 
router configuration to a hacked tftp server, and then iterate thru the 
network as a lot of people have a single SNMP WRITE community in their 
network.

-- 
Mikael Abrahamsson    email: swmike@swm.pp.se

home help back first fref pref prev next nref lref last post