Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: RE: SNMP worm? |
|---|---|
| Date: | 27 Oct 2005 13:15:21 -0000 |
Are you lot sure that this SNMP traffic really originates from your networks? SNMP can easily be spoofed. So far we noticed nothing in our logs and the only scans come from myself. I would rather guess that a script kiddie is on the lose again and tries to play with SNMP. Well it can be rather fun to scan for SNMP. The amount of open devices one can find is scarey, not to talk about community names like public, private and ILMI. I would have a look at the community strings used to see if its a scan or if somebody tries a Dictionary attack. The best option is however to implement access lists accordingly and use very strong Community names.
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: SNMP worm?, Frank Knobbe |
|---|---|
| Next by Date: | AIM virus / worm, Michael Gargiullo |
| Previous by Thread: | RE: SNMP worm?, David Gillett |
| Next by Thread: | AIM virus / worm, Michael Gargiullo |
| Indexes: | [Date] [Thread] [Top] [All Lists] |