.. | ||
cisco-snmp.md | ||
README.md | ||
snmp-rce.md |
161,162,10161,10162/udp - Pentesting SNMP
{% hint style="success" %}
Learn & practice AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE)
Learn & practice GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE)
Support HackTricks
- Check the subscription plans!
- Join the ð¬ Discord group or the telegram group or follow us on Twitter ðŠ @hacktricks_live.
- Share hacking tricks by submitting PRs to the HackTricks and HackTricks Cloud github repos.
If you are interested in hacking career and hack the unhackable - we are hiring! (æµæ¢ãªããŒã©ã³ãèªã®èªã¿æžããå¿ èŠ).
{% embed url="https://www.stmcyber.com/careers" %}
åºæ¬æ å ±
SNMP - ã·ã³ãã«ãããã¯ãŒã¯ç®¡çãããã³ã« ã¯ããããã¯ãŒã¯å ã®ããŸããŸãªããã€ã¹ïŒã«ãŒã¿ãŒãã¹ã€ãããããªã³ã¿ãŒãIoTãªã©ïŒãç£èŠããããã«äœ¿çšããããããã³ã«ã§ãã
PORT STATE SERVICE REASON VERSION
161/udp open snmp udp-response ttl 244 ciscoSystems SNMPv3 server (public)
{% hint style="info" %} SNMPã¯ã162/UDPããŒãããã©ããã«äœ¿çšããŸãããããã¯ãæ瀺çã«èŠæ±ãããããšãªãSNMPãµãŒããŒããã¯ã©ã€ã¢ã³ãã«éä¿¡ãããããŒã¿ãã±ããã§ãã {% endhint %}
MIB
SNMPã¢ã¯ã»ã¹ãç°ãªãã¡ãŒã«ãŒãã¯ã©ã€ã¢ã³ã-ãµãŒããŒã®çµã¿åããã§æ©èœããããšãä¿èšŒããããã«ã管çæ
å ±ããŒã¹ïŒMIBïŒãäœæãããŸãããMIBã¯ãããã€ã¹æ
å ±ãä¿åããããã®ç¬ç«ãããã©ãŒãããã§ããMIBã¯ãããã€ã¹ã®ãã¹ãŠã®ã¯ãšãªå¯èœãªSNMPãªããžã§ã¯ããæšæºåãããããªãŒéå±€ã«ãªã¹ããããŠããããã¹ããã¡ã€ã«ã§ããå°ãªããšã1ã€ã®ãªããžã§ã¯ãèå¥åïŒOIDïŒ
ãå«ãŸããŠãããå¿
èŠãªäžæã®ã¢ãã¬ã¹ãšååã«å ããŠãã¿ã€ããã¢ã¯ã»ã¹æš©ãããã³ããããã®ãªããžã§ã¯ãã®èª¬æã«é¢ããæ
å ±ãæäŸããŸãã
MIBãã¡ã€ã«ã¯ãæœè±¡æ§æèšæ³1ïŒASN.1ïŒ
ã«åºã¥ãASCIIããã¹ããã©ãŒãããã§èšè¿°ãããŠããŸããMIBã¯ããŒã¿ãå«ãŸãªãããã©ãã§ã©ã®æ
å ±ãèŠã€ãããããããã©ã®ããã«èŠããããç¹å®ã®OIDã«å¯ŸããŠè¿ãããå€ããŸãã¯äœ¿çšãããããŒã¿åã«ã€ããŠèª¬æããŸãã
OIDs
**ãªããžã§ã¯ãèå¥åïŒOIDsïŒ**ã¯éèŠãªåœ¹å²ãæãããŸãããããã®äžæã®èå¥åã¯ã**管çæ å ±ããŒã¹ïŒMIBïŒ**å ã®ãªããžã§ã¯ãã管çããããã«èšèšãããŠããŸãã
MIBãªããžã§ã¯ãIDããŸãã¯OIDã®æäžäœã¬ãã«ã¯ãããŸããŸãªæšæºèšå®æ©é¢ã«å²ãåœãŠãããŠããŸãããããã®äžäœã¬ãã«å ã§ãã°ããŒãã«ãªç®¡çæ £è¡ãšæšæºã®æ çµã¿ã確ç«ãããŸãã
ããã«ããã³ããŒã¯ãã©ã€ããŒããã©ã³ããèšç«ããèªç±ãäžããããŠããŸãããããã®ãã©ã³ãå ã§ã¯ãèªç€Ÿã®è£œåã©ã€ã³ã«é¢é£ãã管ç察象ãªããžã§ã¯ããå«ããèªäž»æ§ããããŸãããã®ã·ã¹ãã ã¯ãç°ãªããã³ããŒãæšæºéã§ã®ããŸããŸãªãªããžã§ã¯ããèå¥ã管çããããã®æ§é åãããæ¹æ³ã確ä¿ããŸãã
ããããOIDããªãŒãããã²ãŒãã§ããŸã: http://www.oid-info.com/cgi-bin/display?tree=#focus ãŸãã¯OIDã®æå³ã確èªã§ããŸãïŒäŸãã°1.3.6.1.2.1.1
ïŒ: http://oid-info.com/get/1.3.6.1.2.1.1.
ããç¥ãããOIDã«ã¯ãMIB-2ã§å®çŸ©ãããã·ã³ãã«ãããã¯ãŒã¯ç®¡çãããã³ã«ïŒSNMPïŒå€æ°ãåç
§ãã1.3.6.1.2.1å
ã®ãã®ããããŸãããããŠããã®OIDããä¿çäžã®OIDã䜿çšããŠãèå³æ·±ããã¹ãããŒã¿ïŒã·ã¹ãã ããŒã¿ããããã¯ãŒã¯ããŒã¿ãããã»ã¹ããŒã¿ãªã©ïŒãååŸã§ããŸãã
OIDã®äŸ
1 . 3 . 6 . 1 . 4 . 1 . 1452 . 1 . 2 . 5 . 1 . 3. 21 . 1 . 4 . 7
ãã®ã¢ãã¬ã¹ã®å èš³ã¯æ¬¡ã®ãšããã§ãã
- 1 â ããã¯ISOãšåŒã°ãããããOIDã§ããããšã瀺ããŸãããã¹ãŠã®OIDãã1ãã§å§ãŸãçç±ã§ãã
- 3 â ããã¯ORGãšåŒã°ããããã€ã¹ã補é ããçµç¹ãæå®ããããã«äœ¿çšãããŸãã
- 6 â ããã¯dodãŸãã¯åœé²ç·çã§ãæåã«ã€ã³ã¿ãŒãããã確ç«ããçµç¹ã§ãã
- 1 â ããã¯ã€ã³ã¿ãŒãããã®å€ã§ããã¹ãŠã®éä¿¡ãã€ã³ã¿ãŒããããéããŠè¡ãããããšã瀺ããŸãã
- 4 â ãã®å€ã¯ããã®ããã€ã¹ãæ¿åºã§ã¯ãªãæ°éçµç¹ã«ãã£ãŠè£œé ãããããšã瀺ããŸãã
- 1 â ãã®å€ã¯ãããã€ã¹ãäŒæ¥ãŸãã¯ããžãã¹ãšã³ãã£ãã£ã«ãã£ãŠè£œé ãããããšã瀺ããŸãã
ãããã®æåã®6ã€ã®å€ã¯ãã¹ãŠã®ããã€ã¹ã§åãåŸåããããåºæ¬çãªæ å ±ãæäŸããŸãããã®æ°ã®ã·ãŒã±ã³ã¹ã¯ãããã€ã¹ãæ¿åºã«ãã£ãŠè£œé ãããŠããªãéãããã¹ãŠã®OIDã§åãã«ãªããŸãã
次ã®æ°ã®ã»ããã«é²ã¿ãŸãã
- 1452 â ãã®ããã€ã¹ã補é ããçµç¹ã®ååã瀺ããŸãã
- 1 â ããã€ã¹ã®ã¿ã€ãã説æããŸãããã®å Žåãã¢ã©ãŒã æèšã§ãã
- 2 â ãã®ããã€ã¹ããªã¢ãŒãã¿ãŒããã«ãŠãããã§ããããšã瀺ããŸãã
æ®ãã®å€ã¯ããã€ã¹ã«é¢ããç¹å®ã®æ å ±ãæäŸããŸãã
- 5 â é¢æ£ã¢ã©ãŒã ãã€ã³ãã瀺ããŸãã
- 1 â ããã€ã¹å ã®ç¹å®ã®ãã€ã³ã
- 3 â ããŒã
- 21 â ããŒãã®ã¢ãã¬ã¹
- 1 â ããŒãã®è¡šç€º
- 4 â ãã€ã³ãçªå·
- 7 â ãã€ã³ãã®ç¶æ
SNMPããŒãžã§ã³
SNMPã«ã¯2ã€ã®éèŠãªããŒãžã§ã³ããããŸãïŒ
- SNMPv1: äž»ãªãã®ã§ãæãé »ç¹ã«äœ¿çšãããŠãããèªèšŒã¯æååïŒã³ãã¥ããã£æååïŒã«åºã¥ããŠãããå¹³æã§éä¿¡ãããŸãïŒãã¹ãŠã®æ å ±ãå¹³æã§éä¿¡ãããŸãïŒãããŒãžã§ã³2ããã³2cãå¹³æã§ãã©ãã£ãã¯ãéä¿¡ããã³ãã¥ããã£æååãèªèšŒãšããŠäœ¿çšããŸãã
- SNMPv3: ããè¯ãèªèšŒåœ¢åŒã䜿çšããæ å ±ã¯æå·åãããŠéä¿¡ãããŸãïŒèŸæžæ»æã¯å®è¡å¯èœã§ãããSNMPv1ããã³v2ãããæ£ããã¯ã¬ãã³ã·ã£ã«ãèŠã€ããã®ãã¯ããã«é£ãããªããŸãïŒã
ã³ãã¥ããã£æåå
åè¿°ã®ããã«ãMIBã«ä¿åãããæ
å ±ã«ã¢ã¯ã»ã¹ããã«ã¯ãããŒãžã§ã³1ããã³2/2cã§ã¯ã³ãã¥ããã£æååãç¥ã£ãŠããå¿
èŠããããããŒãžã§ã³3ã§ã¯è³æ Œæ
å ±ãå¿
èŠã§ãã
2çš®é¡ã®ã³ãã¥ããã£æååããããŸãïŒ
public
äž»ã«èªã¿åãå°çšæ©èœprivate
èªã¿æžãäžè¬
OIDã®æžã蟌ã¿å¯èœæ§ã¯äœ¿çšãããã³ãã¥ããã£æååã«äŸåãããããããšããpublicãã䜿çšãããŠããå Žåã§ããããã€ãã®å€ãæžã蟌ãããšãã§ãããããããŸããããŸããåžžã«ãèªã¿åãå°çšãã®ãªããžã§ã¯ããååšããå¯èœæ§ããããŸãã
ãªããžã§ã¯ãã«æžã蟌ãããšãããšãnoSuchName
ãŸãã¯readOnly
ãšã©ãŒ**ãåä¿¡ãããŸã**.**
ããŒãžã§ã³1ããã³2/2cã§ã¯ãæªãã³ãã¥ããã£æååã䜿çšãããšããµãŒããŒã¯å¿çããŸããããããã£ãŠãå¿çãããå Žåã¯ãæå¹ãªã³ãã¥ããã£æååã䜿çšãããããšã«ãªããŸãã
ããŒã
- SNMPãšãŒãžã§ã³ãã¯UDPããŒã161ã§ãªã¯ãšã¹ããåä¿¡ããŸãã
- ãããŒãžã£ãŒã¯ããŒã162ã§éç¥ïŒãã©ããããã³InformRequestsïŒãåä¿¡ããŸãã
- ãã©ã³ã¹ããŒãå±€ã»ãã¥ãªãã£ãŸãã¯ããŒã¿ã°ã©ã ãã©ã³ã¹ããŒãå±€ã»ãã¥ãªãã£ã䜿çšããå Žåããªã¯ãšã¹ãã¯ããŒã10161ã§åä¿¡ãããéç¥ã¯ããŒã10162ã«éä¿¡ãããŸãã
ãã«ãŒããã©ãŒã¹ã³ãã¥ããã£æååïŒv1ããã³v2cïŒ
ã³ãã¥ããã£æååãæšæž¬ããããã«ãèŸæžæ»æãå®è¡ããããšãã§ããŸããSNMPã«å¯Ÿãããã«ãŒããã©ãŒã¹æ»æãå®è¡ããããŸããŸãªæ¹æ³ã«ã€ããŠã¯ãã¡ãã確èªããŠãã ããããã䜿çšãããã³ãã¥ããã£æååã¯public
ã§ãã
SNMPã®åæ
ããã€ã¹ããåéããåOIDã®æå³ã確èªããããã«ã以äžãã€ã³ã¹ããŒã«ããããšããå§ãããŸãïŒ
apt-get install snmp-mibs-downloader
download-mibs
# Finally comment the line saying "mibs :" in /etc/snmp/snmp.conf
sudo vi /etc/snmp/snmp.conf
æå¹ãªã³ãã¥ããã£æååãããã£ãŠããã°ãSNMPWalkãŸãã¯SNMP-Checkã䜿çšããŠããŒã¿ã«ã¢ã¯ã»ã¹ã§ããŸãïŒ
snmpbulkwalk -c [COMM_STRING] -v [VERSION] [IP] . #Don't forget the final dot
snmpbulkwalk -c public -v2c 10.10.11.136 .
snmpwalk -v [VERSION_SNMP] -c [COMM_STRING] [DIR_IP]
snmpwalk -v [VERSION_SNMP] -c [COMM_STRING] [DIR_IP] 1.3.6.1.2.1.4.34.1.3 #Get IPv6, needed dec2hex
snmpwalk -v [VERSION_SNMP] -c [COMM_STRING] [DIR_IP] NET-SNMP-EXTEND-MIB::nsExtendObjects #get extended
snmpwalk -v [VERSION_SNMP] -c [COMM_STRING] [DIR_IP] .1 #Enum all
snmp-check [DIR_IP] -p [PORT] -c [COMM_STRING]
nmap --script "snmp* and not snmp-brute" <target>
braa <community string>@<IP>:.1.3.6.* #Bruteforce specific OID
extended queriesïŒdownload-mibsïŒã®ãããã§ã次ã®ã³ãã³ãã䜿çšããŠã·ã¹ãã ã«ã€ããŠããã«å€ãã®æ å ±ãåæããããšãå¯èœã§ãïŒ
snmpwalk -v X -c public <IP> NET-SNMP-EXTEND-MIB::nsExtendOutputFull
SNMP ã¯ãã¹ãã«é¢ããå€ãã®æ å ±ãæã£ãŠãããèå³æ·±ããã®ã«ã¯æ¬¡ã®ãããªãã®ããããŸã: ãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ãŒã¹ïŒIPv4ããã³IPv6ã¢ãã¬ã¹ïŒããŠãŒã¶ãŒåã皌åæéããµãŒããŒ/OSããŒãžã§ã³ãããã³ããã»ã¹
å®è¡äžïŒãã¹ã¯ãŒããå«ãå¯èœæ§ããããŸãïŒ....
å±éºãªèšå®
ãããã¯ãŒã¯ç®¡çã®é åã§ã¯ãç¹å®ã®æ§æãšãã©ã¡ãŒã¿ãå æ¬çãªç£èŠãšå¶åŸ¡ã確ä¿ããããã®éµãšãªããŸãã
ã¢ã¯ã»ã¹èšå®
å®å šOIDããªãŒãžã®ã¢ã¯ã»ã¹ãå¯èœã«ãã2ã€ã®äž»èŠãªèšå®ããããŸããããã¯ãããã¯ãŒã¯ç®¡çã«ãããŠéèŠãªèŠçŽ ã§ãïŒ
rwuser noauth
ã¯ãèªèšŒãªãã§OIDããªãŒãžã®å®å šã¢ã¯ã»ã¹ãèš±å¯ããããã«èšå®ãããŠããŸãããã®èšå®ã¯ç°¡åã§ãå¶éã®ãªãã¢ã¯ã»ã¹ãå¯èœã«ããŸãã- ããå ·äœçãªå¶åŸ¡ã®ããã«ã次ã®ããã«ã¢ã¯ã»ã¹ãä»äžã§ããŸãïŒ
rwcommunity
ã¯IPv4ã¢ãã¬ã¹çšããããŠrwcommunity6
ã¯IPv6ã¢ãã¬ã¹çšã§ãã
äž¡æ¹ã®ã³ãã³ãã¯ã³ãã¥ããã£æååãšé¢é£ããIPã¢ãã¬ã¹ãå¿ èŠãšãããªã¯ãšã¹ãã®èµ·æºã«é¢ä¿ãªãå®å šãªã¢ã¯ã»ã¹ãæäŸããŸãã
Microsoft Windowsã®SNMPãã©ã¡ãŒã¿
äžé£ã®ç®¡çæ å ±ããŒã¹ïŒMIBïŒå€ããSNMPãéããŠWindowsã·ã¹ãã ã®ããŸããŸãªåŽé¢ãç£èŠããããã«å©çšãããŸãïŒ
- ã·ã¹ãã ããã»ã¹:
1.3.6.1.2.1.25.1.6.0
ãä»ããŠã¢ã¯ã»ã¹ããããã®ãã©ã¡ãŒã¿ã¯ã·ã¹ãã å ã®ã¢ã¯ãã£ããªããã»ã¹ã®ç£èŠãå¯èœã«ããŸãã - å®è¡äžã®ããã°ã©ã :
1.3.6.1.2.1.25.4.2.1.2
ã®å€ã¯ãçŸåšå®è¡äžã®ããã°ã©ã ã远跡ããããã«æå®ãããŠããŸãã - ããã»ã¹ãã¹: ããã»ã¹ãã©ãããå®è¡ãããŠããããç¹å®ããããã«ã
1.3.6.1.2.1.25.4.2.1.4
ã®MIBå€ã䜿çšãããŸãã - ã¹ãã¬ãŒãžãŠããã: ã¹ãã¬ãŒãžãŠãããã®ç£èŠã¯
1.3.6.1.2.1.25.2.3.1.4
ã«ãã£ãŠä¿é²ãããŸãã - ãœãããŠã§ã¢å: ã·ã¹ãã ã«ã€ã³ã¹ããŒã«ãããŠãããœãããŠã§ã¢ãç¹å®ããããã«ã
1.3.6.1.2.1.25.6.3.1.2
ã䜿çšãããŸãã - ãŠãŒã¶ãŒã¢ã«ãŠã³ã:
1.3.6.1.4.1.77.1.2.25
ã®å€ã¯ããŠãŒã¶ãŒã¢ã«ãŠã³ãã®è¿œè·¡ãå¯èœã«ããŸãã - TCPããŒã«ã«ããŒã: æåŸã«ã
1.3.6.1.2.1.6.13.1.3
ã¯TCPããŒã«ã«ããŒãã®ç£èŠã«æå®ãããŠãããã¢ã¯ãã£ããªãããã¯ãŒã¯æ¥ç¶ã«é¢ããæŽå¯ãæäŸããŸãã
Cisco
Ciscoæ©åšã䜿çšããŠããå Žåã¯ããã®ããŒãžãåç §ããŠãã ããïŒ
{% content-ref url="cisco-snmp.md" %} cisco-snmp.md {% endcontent-ref %}
SNMPããRCEãž
SNMPãµãŒãã¹å ã§å€ãæžã蟌ãããšãèš±å¯ããæååãæã£ãŠããå ŽåããããæªçšããŠã³ãã³ããå®è¡ã§ãããããããŸããïŒ
{% content-ref url="snmp-rce.md" %} snmp-rce.md {% endcontent-ref %}
倧èŠæš¡SNMP
Braaã¯ã倧èŠæš¡SNMPã¹ãã£ããŒã§ãããã®ãããªããŒã«ã®æå³ããã䜿çšæ³ã¯ãã¡ãããSNMPã¯ãšãªãè¡ãããšã§ãããnet-snmpã®snmpwalkãšã¯ç°ãªããæ°åãŸãã¯æ°çŸã®ãã¹ãã«åæã«ããã€åäžã®ããã»ã¹ã§ã¯ãšãªãè¡ãããšãã§ããŸãããããã£ãŠãéåžžã«å°ãªãã·ã¹ãã ãªãœãŒã¹ãæ¶è²»ããã¹ãã£ã³ãéåžžã«éãè¡ããŸãã
Braaã¯ç¬èªã®SNMPã¹ã¿ãã¯ãå®è£ ããŠãããããnet-snmpã®ãããªSNMPã©ã€ãã©ãªã¯å¿ èŠãããŸããã
æ§æ: braa [ã³ãã¥ããã£æåå]@[[SNMPãµãŒããŒã®IP]:[iso id]
braa ignite123@192.168.1.125:.1.3.6.*
ããã¯æåã§åŠçã§ããªãå€ãã®MBã®æ å ±ãæœåºã§ããŸãã
ã§ã¯ãæãèå³æ·±ãæ å ±ãèŠãŠã¿ãŸãããïŒhttps://blog.rapid7.com/2016/05/05/snmp-data-harvesting-during-penetration-testing/ïŒ:
ããã€ã¹
ããã»ã¹ã¯ãåãã¡ã€ã«ããããã€ã¹ãç¹å®ããããã«sysDesc MIBããŒã¿ïŒ1.3.6.1.2.1.1.1.0ïŒãæœåºããããšããå§ãŸããŸããããã¯grepã³ãã³ãã䜿çšããŠå®è¡ãããŸã:
grep ".1.3.6.1.2.1.1.1.0" *.snmp
ãã©ã€ããŒãæååã®ç¹å®
éèŠãªã¹ãããã¯ãç¹ã«Cisco IOSã«ãŒã¿ãŒã§äœ¿çšããããã©ã€ããŒãã³ãã¥ããã£æååãç¹å®ããããšã§ãããã®æååã¯ãã«ãŒã¿ãŒããå®è¡äžã®èšå®ãæœåºããããšãå¯èœã«ããŸããç¹å®ã¯ãgrepã³ãã³ãã䜿çšããŠãtrapããšããåèªãå«ãSNMPãã©ããããŒã¿ãåæããããšã«äŸåããããšãå€ãã§ãã
grep -i "trap" *.snmp
ãŠãŒã¶ãŒå/ãã¹ã¯ãŒã
MIBããŒãã«ã«ä¿åããããã°ã¯ããã°ãªã³è©Šè¡ã®å€±æã調ã¹ãããã«æ€æ»ãããããã«ã¯ãŠãŒã¶ãŒåãšããŠå ¥åããããã¹ã¯ãŒããå¶ç¶å«ãŸããããšããããŸããfailãfailedããŸã㯠login ãªã©ã®ããŒã¯ãŒããã貎éãªããŒã¿ãèŠã€ããããã«æ€çŽ¢ãããŸã:
grep -i "login\|fail" *.snmp
Emails
æåŸã«ãããŒã¿ããã¡ãŒã«ã¢ãã¬ã¹ãæœåºããããã«ãgrepã³ãã³ãã䜿çšããã¡ãŒã«åœ¢åŒã«äžèŽãããã¿ãŒã³ã«çŠç¹ãåœãŠãæ£èŠè¡šçŸã䜿çšããŸãïŒ
grep -E -o "\b[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Za-z]{2,6}\b" *.snmp
SNMPå€ã®å€æŽ
NetScanTools ã䜿çšã㊠å€ãå€æŽ ã§ããŸãããã®ããã«ã¯ ãã©ã€ããŒãæåå ãç¥ã£ãŠããå¿ èŠããããŸãã
ã¹ããŒãã£ã³ã°
ACLãç¹å®ã®IPã®ã¿ãSNMPãµãŒãã¹ãã¯ãšãªã§ããããã«å¶éããŠããå ŽåãUDPãã±ããå ã§ãããã®ã¢ãã¬ã¹ã®1ã€ãã¹ããŒãã£ã³ã°ãããã©ãã£ãã¯ãã¹ãããã£ã³ã°ã§ããŸãã
SNMPèšå®ãã¡ã€ã«ã®ç¢ºèª
- snmp.conf
- snmpd.conf
- snmp-config.xml
ãããã³ã°ãã£ãªã¢ã«èå³ãããããããã³ã°äžå¯èœãªãã®ãããã¯ãããæ¹ - ç§ãã¡ã¯æ¡çšããŠããŸãïŒ (æµæ¢ãªããŒã©ã³ãèªã®èªã¿æžããå¿ èŠã§ã)ã
{% embed url="https://www.stmcyber.com/careers" %}
HackTricksèªåã³ãã³ã
Protocol_Name: SNMP #Protocol Abbreviation if there is one.
Port_Number: 161 #Comma separated if there is more than one.
Protocol_Description: Simple Network Managment Protocol #Protocol Abbreviation Spelled out
Entry_1:
Name: Notes
Description: Notes for SNMP
Note: |
SNMP - Simple Network Management Protocol is a protocol used to monitor different devices in the network (like routers, switches, printers, IoTs...).
https://book.hacktricks.xyz/pentesting/pentesting-snmp
Entry_2:
Name: SNMP Check
Description: Enumerate SNMP
Command: snmp-check {IP}
Entry_3:
Name: OneSixtyOne
Description: Crack SNMP passwords
Command: onesixtyone -c /usr/share/seclists/Discovery/SNMP/common-snmp-community-strings-onesixtyone.txt {IP} -w 100
Entry_4:
Name: Nmap
Description: Nmap snmp (no brute)
Command: nmap --script "snmp* and not snmp-brute" {IP}
Entry_5:
Name: Hydra Brute Force
Description: Need Nothing
Command: hydra -P {Big_Passwordlist} -v {IP} snmp
{% hint style="success" %}
AWSãããã³ã°ãåŠã³ãå®è·µããïŒHackTricks Training AWS Red Team Expert (ARTE)
GCPãããã³ã°ãåŠã³ãå®è·µããïŒHackTricks Training GCP Red Team Expert (GRTE)
HackTricksããµããŒããã
- ãµãã¹ã¯ãªãã·ã§ã³ãã©ã³ã確èªããŠãã ããïŒ
- **ð¬ Discordã°ã«ãŒããŸãã¯ãã¬ã°ã©ã ã°ã«ãŒãã«åå ããããTwitter ðŠ @hacktricks_liveããã©ããŒããŠãã ããã
- ãããã³ã°ã®ããªãã¯ãå ±æããã«ã¯ãHackTricksãšHackTricks Cloudã®GitHubãªããžããªã«PRãéä¿¡ããŠãã ããã