★ wanayoo — archive 1999 http://www.linuxsecurity.com/articles/network_security_article-4443.htmlNouvelle recherche | Portail wanayoo
Advertise Here

   
Documentation
Security Sources
Forums
Firewalls
Host Security
Cryptography
Network Security
Intrusion Detection
Organizations/Events
Server Security
Vendors/Products
Projects
General
Privacy
Government
Hacks/Cracks
 
News: Network Security 2/14/2002 8:18

The SNMP fiasco: steps you need to take

TheRegister.co.uk
Posted By: Benjamin D. Thomas
2/14/2002

Obviously, your quickest and surest fix is going to be disabling SNMP if you don't have to run it. Indeed, disabling unnecessary network services is a normal part of system hygeine, so this is a good opportunity to take the time and do a thorough job of it.

If you're stuck with it, then you can filter ports 7/udp 161/udp 161/tcp 162/udp 162/tcp 199/udp 199/tcp 391/udp 391/tcp 705/tcp 1993/udp and 1993/tcp. Obviously, if you need to keep any of these open you'll leave a vulnerability, but by shutting off the ones you don't need you'll make it easier to monitor for suspicious activity.

Meanwhile, check with your vendor for specific advice and patch availability relevant to your router/switch/hub/server/OS/etc. All the vendors are currently working on patches, and it may be only a matter of hours before yours makes one available if it hasn't yet. The most comprehensive single source of general information and workaround suggestions is the CERT Advisory.


Click here to go to this article.

Disclosure Guidelines For Bug-Spotters Proposed
Feb 24

Biatchux Bootable CD Forensics/Incident-Response/Recovery/Virus Scanning/Pen-Tester
Feb 23

Bug-reporting standards proposed to IETF
Feb 22

FBI Says It's Monitoring Web Vulnerability
Feb 22

Group to set bug-reporting standards
Feb 22

Most SNMP vulns quietly lurking
Feb 22

Linux Advisory Watch - February 22nd 2002
Feb 22

Contact Us | Legal Notice | About Our Site
© Guardian Digital, Inc., 2000