Re: SNMPv3 does not provide any protection against brute force attacks.
Prankur Chauhan <[email protected]> Thu, 27 Jun 2024 12:32:32 +0200
| Newsgroups | gmane.network.net-snmp.devel |
|---|---|
| Message-ID | <CAEgXv56LOmycEa2kpu_4oET0GbYHK4S6Sa2r2wo0rkFh-QQJJA@mail.gmail.com> |
--===============0968882404528303800== Content-Type: multipart/alternative; boundary="000000000000a1963b061bdca84e" --000000000000a1963b061bdca84e Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Dear Wes, Thankyou for your input. Indeed I checked it before this post that "-Dusm" can capture some Unknown user, bad Auth/Priv password. such logs then can be filtered in the fail2ban. It also makes sense about what you say regarding setting up a firewall. Incase someone is wondering about the fail2ban filters and jail, feel free to check out the fail2ban issue 3767 ( https://github.com/fail2ban/fail2ban/issues/3767) Cheers On Fri, Jun 21, 2024 at 4:41=E2=80=AFPM Wes Hardaker <[email protected]= forge.net> wrote: > Prankur Chauhan <[email protected]> writes: > > > Is it possible to identify a malicious IP who is trying multiple times > > authentication requests with wrong credentials and increase the > > response time for each subsequent auth request, consequently also lock > > him/her out for some duration? > > > > Do you guys know if snmpd can be configured to work with tools such as > fail2ban? > > A few things: > > 1. With the right debugging flags turned on (try -Dusm) you might be > able to watch for failures and create a fail2ban hook to provide > fail2ban with new jail entries. > > 2. But my importantly, you should never ever have an snmp agent (of any > kind) connected to the internet without a firewall in front of it that > restricts access to only trusted IP addresses. This generally is true > for any SNMP or other management control protocol -- they should be > accessible only from internal networks. > > -- > Wes Hardaker > Please mail all replies to [email protected] > --=20 Cheers Prankur --000000000000a1963b061bdca84e Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div><div>Dear Wes,<br><br></div>Thankyou for your input. = Indeed I checked it before this post that "-Dusm" can capture som= e Unknown user, bad Auth/Priv password. <br>such logs then can be filtered = in the fail2ban.<br></div><div><br></div><div>It also makes sense about wha= t you say regarding setting up a firewall.<br><br></div><div>Incase someone= is wondering about the fail2ban filters and jail, feel free to check out t= he fail2ban issue 3767 (<a href=3D"https://github.com/fail2ban/fail2ban/iss= ues/3767">https://github.com/fail2ban/fail2ban/issues/3767</a>)</div><div><= br></div><div>Cheers<br></div></div><br><div class=3D"gmail_quote"><div dir= =3D"ltr" class=3D"gmail_attr">On Fri, Jun 21, 2024 at 4:41=E2=80=AFPM Wes H= ardaker <<a href=3D"mailto:[email protected]">hardaker@user= s.sourceforge.net</a>> wrote:<br></div><blockquote class=3D"gmail_quote"= style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);p= adding-left:1ex">Prankur Chauhan <<a href=3D"mailto:prankur.chauhan89@gm= ail.com" target=3D"_blank">[email protected]</a>> writes:<br> <br> > Is it possible to identify a malicious IP who is trying multiple times= <br> > authentication requests with wrong credentials and increase the<br> > response time for each subsequent auth request, consequently also lock= <br> > him/her out for some duration?<br> > <br> > Do you guys know if snmpd can be configured to work with tools such as= fail2ban?<br> <br> A few things:<br> <br> 1. With the right debugging flags turned on (try -Dusm) you might be<br> =C2=A0 =C2=A0able to watch for failures and create a fail2ban hook to provi= de<br> =C2=A0 =C2=A0fail2ban with new jail entries.<br> <br> 2. But my importantly, you should never ever have an snmp agent (of any<br> =C2=A0 =C2=A0kind) connected to the internet without a firewall in front of= it that<br> =C2=A0 =C2=A0restricts access to only trusted IP addresses.=C2=A0 This gene= rally is true<br> =C2=A0 =C2=A0for any SNMP or other management control protocol -- they shou= ld be<br> =C2=A0 =C2=A0accessible only from internal networks.<br> <br> -- <br> Wes Hardaker<br> Please mail all replies to <a href=3D"mailto:[email protected]= rge.net" target=3D"_blank">[email protected]</a><br> </blockquote></div><br clear=3D"all"><br><span class=3D"gmail_signature_pre= fix">-- </span><br><div dir=3D"ltr" class=3D"gmail_signature"><div dir=3D"l= tr"><div><div dir=3D"ltr"><div>Cheers<br></div>Prankur <br></div></div></di= v></div> --000000000000a1963b061bdca84e-- --===============0968882404528303800== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============0968882404528303800== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Net-snmp-coders mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/net-snmp-coders --===============0968882404528303800==--