SNMP's three versions differ fundamentally in security, so identifying which an agent speaks decides the whole attack. SNMPv1 and v2c share the same weak model: the community string is the only credential, it is sent in cleartext, and nothing is encrypted, so the string is captured by sniffing and everything is exposed to anyone who has it. SNMPv3 is a different protocol with user-based security, optional authentication and privacy (encryption), which removes the cleartext-string weakness, but it still discloses usernames during the engine-discovery handshake and is subject to offline cracking of captured authentication and to downgrade where weaker versions remain enabled. Many agents answer multiple versions at once.
Subtopics#
- Version detection: determining which versions an agent accepts.
- SNMPv1 and v2c cleartext: the cleartext community-string weakness.
- SNMPv3 attacks: username enumeration, offline cracking, and downgrade.