RE: SNMP-COMMUNITY-MIB security question

2008-04-22 Thread Emi Yanagi
i -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Dave Shield Sent: Friday, April 18, 2008 4:56 PM To: Emi Yanagi Cc: [email protected] Subject: Re: SNMP-COMMUNITY-MIB security question On 18/04/2008, Emi Yanagi <[EMAIL PROTECTE

RE: SNMP-COMMUNITY-MIB security question

2008-04-21 Thread Emi Yanagi
Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Dave Shield Sent: Friday, April 18, 2008 4:56 PM To: Emi Yanagi Cc: [email protected] Subject: Re: SNMP-COMMUNITY-MIB security question On 18/04/2008, Emi Yanagi <[EMAIL PROTECTED]> wrot

Re: SNMP-COMMUNITY-MIB security question

2008-04-18 Thread Dave Shield
On 18/04/2008, Emi Yanagi <[EMAIL PROTECTED]> wrote: > What data structure(s) or field(s) I should look into? > Or are you talking about snmpd.conf configuration? Yes - I'm talking about the snmpd.conf access control settings. Define a view that excludes the snmpCommunityTable. Then configure "

RE: SNMP-COMMUNITY-MIB security question

2008-04-18 Thread Emi Yanagi
: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Dave Shield Sent: Friday, April 18, 2008 4:19 PM To: Emi Yanagi Cc: [email protected] Subject: Re: SNMP-COMMUNITY-MIB security question On 18/04/2008, Emi Yanagi <[EMAIL PROTECTED]> wrote: > It seems there could be a

Re: SNMP-COMMUNITY-MIB security question

2008-04-18 Thread Dave Shield
On 18/04/2008, Emi Yanagi <[EMAIL PROTECTED]> wrote: > It seems there could be a security hole in snmpCommunityTable. What if a > user who only has access to read-only community name "public", used it to > walk through snmpCommunityName, which would also populate the read-write > community name "p