Multiple Vendor SNMP World Writeable Community Vulnerability
BID:986
Info
Multiple Vendor SNMP World Writeable Community Vulnerability
| Bugtraq ID: | 986 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 15 2000 12:00AM |
| Updated: | Apr 16 2008 12:29AM |
| Credit: | This was posted to Bugtraq by Michal Zalewski on Feb 15, 2000. Alhambra wrote an article about this for issue 50 of Phrack. It is linked to below. Information regarding default communities for Brocade fabric switches was provided by Jonathan Clemens <j |
| Vulnerable: |
Xyplex Router 6.1.1 Sun Solaris 2.6 Microsoft Windows NT 4.0 Microsoft Windows 98 Cray MatchBox Router 2.0.1 Cisco IOS 11.2 Brocade Fabric OS 2.1.2 Ascom COLTSOHO 2.0.21 |
| Not Vulnerable: |
Sun Solaris 7.0 Microsoft Windows NT 4.0 SP4 |
Discussion
Multiple Vendor SNMP World Writeable Community Vulnerability
In a number of network devices/operating systems, some default communites are world-writeable and therefore allow remote users to configure properties of the device/OS without any authorization (other than knowledge of the community name).
Some of the common default communities/vendors are:
public (ascend,cisco,bay networks (nortel),microsoft,sun,3com, aix)
private (cisco,bay networks (nortel),microsoft,3com, brocade, aix, netapp)
write (ascend, very common)
"all private" (sun)
monitor (3com)
manager (3com)
security (3com)
OrigEquipMfr (brocade)
"Secret C0de" (brocade)
admin
default
password
tivoli
openview
community
snmp
snmpd
system (aix, others)
the name of the router (ie, 'gate')
The attacks can include manipulating routing tables and corrupting ARP caches, which can lead to further compromise. This type of vulnerability has been seen for quite some time; more information on it is listed in the credit section.
NOTE: There may be more products shipping with default read/writeable communities. If you have any more information on what may be vulnerable (more specific firmware versions or corrections), email <[email protected]>.
In a number of network devices/operating systems, some default communites are world-writeable and therefore allow remote users to configure properties of the device/OS without any authorization (other than knowledge of the community name).
Some of the common default communities/vendors are:
public (ascend,cisco,bay networks (nortel),microsoft,sun,3com, aix)
private (cisco,bay networks (nortel),microsoft,3com, brocade, aix, netapp)
write (ascend, very common)
"all private" (sun)
monitor (3com)
manager (3com)
security (3com)
OrigEquipMfr (brocade)
"Secret C0de" (brocade)
admin
default
password
tivoli
openview
community
snmp
snmpd
system (aix, others)
the name of the router (ie, 'gate')
The attacks can include manipulating routing tables and corrupting ARP caches, which can lead to further compromise. This type of vulnerability has been seen for quite some time; more information on it is listed in the credit section.
NOTE: There may be more products shipping with default read/writeable communities. If you have any more information on what may be vulnerable (more specific firmware versions or corrections), email <[email protected]>.
Exploit / POC
Multiple Vendor SNMP World Writeable Community Vulnerability
Michal Zalewski wrote the following exploit example in his post to Bugtraq regarding this issue:
snmpset hostname {private|public} interfaces.ifTable.ifEntry.ifAdminStatus.1 i 2
This will make the primary interface on the target host (with a default community of public or private) change state to two, which is "down".
Michal Zalewski wrote the following exploit example in his post to Bugtraq regarding this issue:
snmpset hostname {private|public} interfaces.ifTable.ifEntry.ifAdminStatus.1 i 2
This will make the primary interface on the target host (with a default community of public or private) change state to two, which is "down".
Solution / Fix
Multiple Vendor SNMP World Writeable Community Vulnerability
Solution:
A permanent fix is to change or remove the default communities. Please see the references for more information.
Sun Solaris 2.6
Solution:
A permanent fix is to change or remove the default communities. Please see the references for more information.
Sun Solaris 2.6
References
Multiple Vendor SNMP World Writeable Community Vulnerability
References:
References: