One more 3Com SNMP vulnerability

From: Nerijus Krukauskas (nkrukauskasat_private)
Date: Mon Aug 30 1999 - 06:43:42 PDT

  • Next message: Malicious User: "ProFTPD 1.2.0pre4 available"

    Hi,
    
      It seems that 3Com does not pay much atention how its SNMP is
    implemented. In 3Com SuperStack II hubs MIB there's an OID:
    .1.3.6.1.4.1.43.10.4.2. Its name decodes to
    .iso.org.dod.internet.private.enterprises.a3Com.generic.security.securityUserTable.
    What You need to know that's read-only community and this OID will give you
    entire table of communities (read-write and read-only).
      If somebody knows how to contact 3Com with such reports forward this info
    to them. Half an hour exploring 3Com web site i found no e-mail's (not even
    supportat_private). Amazing...
    
    --
    Nerijus Krukauskas                   Bank of Lithuania
    Division head                        IT department, Networking division
    Tel. +370-2-680731                   Zirmunu 151
    nkrukauskasat_private                 2012 Vilnius, Lithuania
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:00:13 PDT