Brain-Dead Security

[prev] [thread] [next] [lurker] [Date index for 2004/01/09]

From: Phil!Gregory
Subject: Brain-Dead Security
Date: 22:14 on 09 Jan 2004
Network device.  Uses SNMPv1 (which we'll accept for the moment; that
would be a different hate).  Has separate get and set community names;
let's say they're "public" and "private".

$ snmpget -v1 -c public <device> <MIB>::writeCommunity.0
<MIB>::writeCommunity.0 = STRING: "private"

This has apparently been fixed in a later firmware revision, but this
particular device is already at it's highest possible firmware revision.
Whee.

This has been a low-effort hate.  Enjoy your day.

-- 
...computer contrarian of the first order... / http://aperiodic.net/phil/
PGP: 026A27F2  print: D200 5BDB FC4B B24A 9248  9F7A 4322 2D22 026A 27F2
--- --
To find a rhyme for silver,
A seemingly rhymeless rhyme,
Requires only will, ver-
bosity and time.
                       -- W. P. Espy
---- --- --

Generated at 14:02 on 01 Jul 2004 by mariachi 0.52