Metasploit mailing list archives

Re: SNMP testing


From: Hugo Vinicius Garcia Razera <hviniciusg () gmail com>
Date: Tue, 28 Sep 2010 08:40:29 -0400

On Tue, Sep 28, 2010 at 6:30 AM, Spring Systems <korund () hotmail com> wrote:

 Is there still possibility to exploit/test SNMP devices with Metasploit if
SNMP is disabled on target devices


If the SNMP service is disabled, then you could not exploit anithing


, or if community string changed from default "public" to another string?


If the community string is changed, there are several tools to "brute force"
the community string, but it makes a lot of noise, and there are some
devices that will block you when there are several failed attempts, but if
this is a last resort option, then i think you should doit, or leave this
test to the end of the audit process.

Regards,
Hugo Vinicius Garcia Razera
_______________________________________________
https://mail.metasploit.com/mailman/listinfo/framework

Current thread: