Because SNMP has no concept of an account or lockout and the community string is the sole credential, brute forcing it is straightforward and fast. onesixtyone is purpose-built: it fires UDP SNMP requests across a list of community strings (and a list of hosts) at high rate and reports which strings elicit a response, making it practical to sweep a whole subnet against a community wordlist in seconds. A recovered string is then confirmed and used with the net-snmp tools. The lack of lockout and the connectionless UDP transport mean the only real limit is packet loss, so retries matter.
# sweep community strings (and optionally many hosts) with onesixtyone
onesixtyone -c /usr/share/seclists/Discovery/SNMP/common-snmp-community-strings.txt <target>
onesixtyone -c comm.txt -i hosts.txt # many hosts at once
# confirm a hit and start reading
snmp-check -c <found> <target>
# hydra also brute-forces SNMP (slower, but integrates with other services)
hydra -P comm.txt -s 161 <target> snmp
Exploitation notes#
onesixtyoneis the fast path: it is UDP-rate-driven and sweeps both strings and hosts, so it is ideal for finding every weakly-stringed agent on a subnet in one pass.- Account for UDP loss: use retries and reasonable rate; a missed response is not a failed string, so re-test apparent misses before concluding.
- There is no lockout to trip, so a large wordlist is viable, but a device may still rate-limit or drop under flood; tune the rate if responses dry up.
- A found string drives enumeration; separately brute-force for a read-write string, as it is often different and enables write access.