SNMP (Simple Network Management Protocol) runs on UDP 161 and exposes a managed device's state as a tree of object identifiers (OIDs) organized in MIBs. On the still-dominant SNMPv1 and v2c, the only access control is a community string sent in cleartext, a read string (conventionally public) for querying and a read-write string (conventionally private) for changing settings. That weak model makes SNMP one of the most productive reconnaissance and credential-exposure surfaces on a network: routers, switches, firewalls, printers, servers, and appliances all answer it, and what they return includes the system inventory, the network topology, and frequently credentials and whole device configurations. With a read-write string, SNMP also reconfigures the device.
# detect and version the agent
nmap -sU -p161 -sV --script snmp-info <target>
snmpwalk -v2c -c public <target> 2>/dev/null | head # does a read string work?
Subtopics#
- Enumeration: walking the agent and reading device data.
- Community strings: obtaining read and read-write strings.
- Information disclosure: system, topology, config, and credential exposure.
- Versions: v1/v2c cleartext weaknesses and attacking v3.
- Write access: reconfiguring the device with a read-write string.