SNMPv3 does not provide any protection against brute force attacks.

Prankur Chauhan <[email protected]> Thu, 13 Jun 2024 06:41:11 +0200
Newsgroups gmane.network.net-snmp.devel
Message-ID <CAEgXv57xBHQjnbiv848ZGguNc1h9jCG_hEvbkg=5HnuTe-eNdA@mail.gmail.com>
--===============0611777752304995393==
Content-Type: multipart/alternative; boundary="000000000000594827061abe1e41"

--000000000000594827061abe1e41
Content-Type: text/plain; charset="UTF-8"

Dear SNMP Development Team,

I have identified that the authentication requests are not Rate limited and
there are no lockout policies in the SNMPD (Master Agent).

Is it possible to identify a malicious IP who is trying multiple times
authentication requests with wrong credentials and increase the response
time for each subsequent auth request, consequently also lock him/her out
for some duration?

Do you guys know if snmpd can be configured to work with tools such as
fail2ban?

Your advice/help is much appreciated.

-- 
Cheers
Prankur

--000000000000594827061abe1e41
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Dear SNMP Development Team,</div><div><br></div><div>=
I have identified that the authentication requests are not Rate limited and=
 there are no lockout policies in the SNMPD (Master Agent).<br><br></div><d=
iv>Is it possible to identify a malicious IP who is trying multiple times a=
uthentication requests with wrong credentials and increase the response tim=
e for each subsequent auth request, consequently also lock him/her out for =
some duration?</div><div><br></div><div>Do you guys know if snmpd can be co=
nfigured to work with tools such as fail2ban?</div><div><br></div><div>Your=
 advice/help is much appreciated.<br></div><div><br><span class=3D"gmail_si=
gnature_prefix">-- </span><br><div dir=3D"ltr" class=3D"gmail_signature" da=
ta-smartmail=3D"gmail_signature"><div dir=3D"ltr"><div><div dir=3D"ltr"><di=
v>Cheers<br></div>Prankur <br></div></div></div></div></div></div>

--000000000000594827061abe1e41--


--===============0611777752304995393==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============0611777752304995393==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Net-snmp-coders mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/net-snmp-coders

--===============0611777752304995393==--