SNMP Is Dead (2018) [video]
youtube.com
youtube.com
With the reports I provide, they give me refunds. Death before dishonor.
SNMP Concepts are not only excellent but essential:
* A curated listed of universal codes for monitoring common attributes
* Some sort of standardized plug/play protocol that can allow things from one thing to monitor things from another thing
* Oh and it's UDP
It ticks all the boxes except for security.
I'm not sure how to get past that one without pushing a private key or a shared secret onto each managed device (maybe with SNMP SET?).
A common scenario is that a satellite-connected terminal loses uplink connectivity with the ground network, so the ground network issues a reset to the terminal via SNMP, which has a high likelyhood of going through (since downlink is simpler/more stable than uplink). I suppose you could also use UDP, but when I worked for the telecom industry, SNMP was a common use-case for this problem of one-way communication.
My knowledge is a little rusty, but aren't SNMP packets enclosed in a UDP datagram?
I like the idea of what's being proposed, I'm just not sure I'll be able to use it with my networking hardware any time soon.
An absolute gold mine, and (for some reason) it's one of the last things people think about when securing their networks.
If you use SNMP, consider it a sensitive system and protect it accordingly.
Even if it's read-only, SNMP can contain all the info you need to build a network map: IPs, hostnames, and even a description (like "accounting-printer" :-D). In one I looked at, it even had information on when the configuration was last updated, so I was able to see which devices were recently given attention by the sys admin, and which devices weren't. I found a few hosts that had slipped through the cracks and were running really old kernels that were exploitable.
If you're defending a network, I definitely recommend scanning for any SNMP listeners, especially on anything that routes packets. If you're trying to compromise a network, I give the same advice.
With a good IT dept, SNMP running on close loop networks and such, it's good enough.
Other than SNMP, what would I use to figure out which device MAC is on which port or if the port is even active or not?
I'm working on a system now that uses a query language, bearer tokens with delegation and presents a tabular model ala sql. probably better?
Have you got a link? I'm very interested in a tiny (less than 2KB) replacement for SNMP. A minimum implementation size larger than 2KB is probably a non-starter.
The draw of SNMP is that the agent is available on almost every tiny router or networked device there is, even those that don't have a user interface. This means that a protocol over http(s) is too heavy for most devices[1].
Additionally, because network monitoring tools are using this pretty much constantly, even a few bytes of overhead adds up pretty quickly, so using http(s) is again out of the question.
Same for supporting a query language, or even tabular data.
[1] Yes, even today.
But maybe the last people that DO run a network use it. (AWS, Google, others?)