Re: SNMPv3 does not provide any protection against brute force attacks.

Prankur Chauhan <[email protected]> Thu, 27 Jun 2024 12:32:32 +0200
Newsgroups gmane.network.net-snmp.devel
Message-ID <CAEgXv56LOmycEa2kpu_4oET0GbYHK4S6Sa2r2wo0rkFh-QQJJA@mail.gmail.com>
--===============0968882404528303800==
Content-Type: multipart/alternative; boundary="000000000000a1963b061bdca84e"

--000000000000a1963b061bdca84e
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Dear Wes,

Thankyou for your input. Indeed I checked it before this post that "-Dusm"
can capture some Unknown user, bad Auth/Priv password.
such logs then can be filtered in the fail2ban.

It also makes sense about what you say regarding setting up a firewall.

Incase someone is wondering about the fail2ban filters and jail, feel free
to check out the fail2ban issue 3767 (
https://github.com/fail2ban/fail2ban/issues/3767)

Cheers

On Fri, Jun 21, 2024 at 4:41=E2=80=AFPM Wes Hardaker <[email protected]=
forge.net>
wrote:

> Prankur Chauhan <[email protected]> writes:
>
> > Is it possible to identify a malicious IP who is trying multiple times
> > authentication requests with wrong credentials and increase the
> > response time for each subsequent auth request, consequently also lock
> > him/her out for some duration?
> >
> > Do you guys know if snmpd can be configured to work with tools such as
> fail2ban?
>
> A few things:
>
> 1. With the right debugging flags turned on (try -Dusm) you might be
>    able to watch for failures and create a fail2ban hook to provide
>    fail2ban with new jail entries.
>
> 2. But my importantly, you should never ever have an snmp agent (of any
>    kind) connected to the internet without a firewall in front of it that
>    restricts access to only trusted IP addresses.  This generally is true
>    for any SNMP or other management control protocol -- they should be
>    accessible only from internal networks.
>
> --
> Wes Hardaker
> Please mail all replies to [email protected]
>


--=20
Cheers
Prankur

--000000000000a1963b061bdca84e
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div><div>Dear Wes,<br><br></div>Thankyou for your input. =
Indeed I checked it before this post that &quot;-Dusm&quot; can capture som=
e Unknown user, bad Auth/Priv password. <br>such logs then can be filtered =
in the fail2ban.<br></div><div><br></div><div>It also makes sense about wha=
t you say regarding setting up a firewall.<br><br></div><div>Incase someone=
 is wondering about the fail2ban filters and jail, feel free to check out t=
he fail2ban issue 3767 (<a href=3D"https://github.com/fail2ban/fail2ban/iss=
ues/3767">https://github.com/fail2ban/fail2ban/issues/3767</a>)</div><div><=
br></div><div>Cheers<br></div></div><br><div class=3D"gmail_quote"><div dir=
=3D"ltr" class=3D"gmail_attr">On Fri, Jun 21, 2024 at 4:41=E2=80=AFPM Wes H=
ardaker &lt;<a href=3D"mailto:[email protected]">hardaker@user=
s.sourceforge.net</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote"=
 style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);p=
adding-left:1ex">Prankur Chauhan &lt;<a href=3D"mailto:prankur.chauhan89@gm=
ail.com" target=3D"_blank">[email protected]</a>&gt; writes:<br>
<br>
&gt; Is it possible to identify a malicious IP who is trying multiple times=
<br>
&gt; authentication requests with wrong credentials and increase the<br>
&gt; response time for each subsequent auth request, consequently also lock=
<br>
&gt; him/her out for some duration?<br>
&gt; <br>
&gt; Do you guys know if snmpd can be configured to work with tools such as=
 fail2ban?<br>
<br>
A few things:<br>
<br>
1. With the right debugging flags turned on (try -Dusm) you might be<br>
=C2=A0 =C2=A0able to watch for failures and create a fail2ban hook to provi=
de<br>
=C2=A0 =C2=A0fail2ban with new jail entries.<br>
<br>
2. But my importantly, you should never ever have an snmp agent (of any<br>
=C2=A0 =C2=A0kind) connected to the internet without a firewall in front of=
 it that<br>
=C2=A0 =C2=A0restricts access to only trusted IP addresses.=C2=A0 This gene=
rally is true<br>
=C2=A0 =C2=A0for any SNMP or other management control protocol -- they shou=
ld be<br>
=C2=A0 =C2=A0accessible only from internal networks.<br>
<br>
-- <br>
Wes Hardaker<br>
Please mail all replies to <a href=3D"mailto:[email protected]=
rge.net" target=3D"_blank">[email protected]</a><br>
</blockquote></div><br clear=3D"all"><br><span class=3D"gmail_signature_pre=
fix">-- </span><br><div dir=3D"ltr" class=3D"gmail_signature"><div dir=3D"l=
tr"><div><div dir=3D"ltr"><div>Cheers<br></div>Prankur <br></div></div></di=
v></div>

--000000000000a1963b061bdca84e--


--===============0968882404528303800==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============0968882404528303800==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Net-snmp-coders mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/net-snmp-coders

--===============0968882404528303800==--