On Fri, Jul 25, 2003 at 02:31:49PM -0500, Omernik, John wrote:
> I understand. What about writing it into the plugin to dump those extra
> packets in so that it can be detected for sure? Is it common practice
> to have SNMP open on routers?
These "extra packets" must go through the router, not aim it directly.
So you have to figure out who the router is routing for, something which
is risky to do from an automated scanner point of view.
Finally, crashing your routers during each scan is not really useful.
It's like shooting oneself in the foot.
I recommend people let SNMP r/o on their router and set up ACLs so
that it can not be accessed by everyone, but only the relevant people
(and scanners). And of course, change the community "public" to
something else, and give it to Nessus.
-- Renaud