Enumeration is the mechanism; disclosure is the payoff. What an SNMP agent returns to a read string is frequently sensitive and sometimes catastrophic. The network tables reconstruct the internal topology, who is connected, routing, and ARP mappings, mapping the environment from a single device. On network gear, the running configuration itself can be pulled over SNMP, exposing every credential and key in it. On Windows hosts, extended MIBs enumerate users, processes, installed software, and shares. And credentials and secrets, other community strings, wireless and VPN keys, and application data, turn up in standard and vendor OIDs. This section covers turning read access into that loot.
Subtopics#
- System and topology disclosure: mapping the network from the device tables.
- Cisco configuration exfiltration: pulling the running config over SNMP and TFTP.
- Windows host information: users, processes, software, and shares.
- Credential and secret exposure: keys and credentials in OIDs.