<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>SNMP on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/snmp/</link>
    <description>Recent content in SNMP on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 31 Jul 2013 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/snmp/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>SNMP Reflected Amplification DDoS Attacks</title>
      <link>https://insinuator.net/2013/07/snmp-reflected-amplification-ddos-attacks/</link>
      <pubDate>Wed, 31 Jul 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/07/snmp-reflected-amplification-ddos-attacks/</guid>
      <description>&lt;p&gt;Just recently on the NANOG mailing list a discussion popped up titled “&lt;a href=&#34;http://mailman.nanog.org/pipermail/nanog/2013-July/060094.html&#34;&gt;SNMP DDoS: the vulnerability you might not know you have&lt;/a&gt;“.&lt;br&gt;&#xA;There’s a couple of points here:&lt;/p&gt;&#xA;&lt;p&gt;a) if you’re interested in the technical details of these attacks (and mitigation advice), pls see &lt;a href=&#34;http://www.bitag.org/documents/SNMP-Reflected-Amplification-DDoS-Attack-Mitigation.pdf&#34;&gt;this excellent technical&lt;/a&gt; report the Broadband Internet Technical Advisory Group published last year (apparently Comcast &lt;a href=&#34;ttp://corporate.comcast.com/comcast-voices/taking-steps-to-prevent-unintentional-network-abuse&#34;&gt;had observed&lt;/a&gt; such attacks before).&lt;/p&gt;&#xA;&lt;p&gt;b) Daniel and I gave a &lt;a href=&#34;https://www.ernw.de/download/ERNW_HITB_Dubai_2007_Attacking_SNMP.pdf&#34;&gt;talk on attacking SNMP&lt;/a&gt; at HITB Dubai 2007 (&lt;a href=&#34;http://conference.hitb.org/&#34;&gt;Hi Amy &amp;amp; Dhillon! 😉&lt;/a&gt;) laying out the basic idea for that type of attack and we later described it in a bit more detail at &lt;a href=&#34;http://www.shmoocon.org/shmoocon_2009&#34;&gt;ShmooCon 2009&lt;/a&gt; where we even demoed it publicly (camera recording stopped at that point, for obvious reasons). We used (a slightly modified version of) &lt;a href=&#34;https://www.ernw.de/download/snmpattack.pl&#34;&gt;this tool&lt;/a&gt;.&lt;br&gt;&#xA;From the research we did at the time we can confirm this was/presumably still is a huge problem, at least for European carriers’ broadband segments (acting as amplifiers).&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
