SNMP security hole

Cougar

Golden Member
Feb 26, 2000
1,761
0
0
I barely know anything about networking, but I was reading at gotapex that there is some sort of hole in SNMP and they say it's pretty serious. Here's a clip:

"In a few minutes wire services and other news sources will begin breaking a story about widespread vulnerabilities in SNMP (Simple Network Management Protocol). Exploits of the vulnerability cause systems to fail or to be taken over. The vulnerability can be found in more than a hundred manufacturers' systems and is very widespread - millions of routers and other systems are involved.

As one of the SANS alumni, your leadership is needed in making sure that all systems for which you have any responsibility are protected. To do that, first ensure that SNMP is turned off. If you absolutely must run SNMP, get the patch from your hardware or software vendor. They are all working on patches right now. It also makes sense for you to filter traffic destined for SNMP ports (assuming the system doing the filtering is patched).

To block SNMP access, block traffic to ports 161 and 162 for tcp and udp. In addition, if you are using Cisco, block udp for port 1993.

The problems were caused by programming errors that have been in the SNMP implementations for a long time, but only recently discovered."

Here's another
link

Hope this isn't a repost (or some hoax).
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
and remember gang that all those NT/2000 servers and XP machines run snmp. many times without you knowing about it.