Probe to 161

Probe to 161

Post by Ron Parke » Thu, 13 Apr 2000 04:00:00



What is the potential danger here?  These have been occuring all day,
from the same IP to a variety to hosts on my network.  Thanks for any
info.

Apr 11 16:13:27 shelia kernel: Packet log: input DENY eth0 PROTO=17
206.77.145.97:2200 x.x.x.x:161 L=265 S=0x00 I=44728 F=0x0000
T=102 (#1)
Apr 11 16:59:07 shelia kernel: Packet log: input DENY eth0 PROTO=17
206.77.145.97:2200 x.x.x.x:161 L=265 S=0x00 I=10087 F=0x0000
T=102 (#1)

--
Ron Parker
Software Creations            http://www.scbbs.com
TradeWinds Publishing         http://www.intl-trade.com
TradePoint Los Angeles        http://www.tradepointla.org
SiteDirector Security Server  http://livepublish.scbbs.com
Civil War Online Library      http://civilwar.scbbs.com

 
 
 

Probe to 161

Post by jc » Thu, 13 Apr 2000 04:00:00


snmp            161/tcp    SNMP
snmp            161/udp    SNMP

SNMP == Simple Network Managment Protocal.

It's a service used for remote adminstration of  hosts.

Not a big concern if you don't have snmp running.
If you do, block it or consider killing your snmp service.


> What is the potential danger here?  These have been occuring all day,
> from the same IP to a variety to hosts on my network.  Thanks for any
> info.

> Apr 11 16:13:27 shelia kernel: Packet log: input DENY eth0 PROTO=17
> 206.77.145.97:2200 x.x.x.x:161 L=265 S=0x00 I=44728 F=0x0000
> T=102 (#1)
> Apr 11 16:59:07 shelia kernel: Packet log: input DENY eth0 PROTO=17
> 206.77.145.97:2200 x.x.x.x:161 L=265 S=0x00 I=10087 F=0x0000
> T=102 (#1)

> --
> Ron Parker
> Software Creations            http://www.scbbs.com
> TradeWinds Publishing         http://www.intl-trade.com
> TradePoint Los Angeles        http://www.tradepointla.org
> SiteDirector Security Server  http://livepublish.scbbs.com
> Civil War Online Library      http://civilwar.scbbs.com


 
 
 

Probe to 161

Post by Ron Parke » Thu, 13 Apr 2000 04:00:00


Yes, thanks for the reply.  I know what the port is.  What I don't understand, like
so much of this security stuff, is why another machine outside my network would want
to send udp packets to this port on several of my machines, one machine at a time,
every couple hours or so.

I would imagine that if the daemon is not running, no harm done.  But, WHY, what
normal reason would someone outside my network would have to test to see if it is
running?

Thanks.

-ron


> snmp            161/tcp    SNMP
> snmp            161/udp    SNMP

> SNMP == Simple Network Managment Protocal.

> It's a service used for remote adminstration of  hosts.

> Not a big concern if you don't have snmp running.
> If you do, block it or consider killing your snmp service.


> > What is the potential danger here?  These have been occuring all day,
> > from the same IP to a variety to hosts on my network.  Thanks for any
> > info.

> > Apr 11 16:13:27 shelia kernel: Packet log: input DENY eth0 PROTO=17
> > 206.77.145.97:2200 x.x.x.x:161 L=265 S=0x00 I=44728 F=0x0000
> > T=102 (#1)
> > Apr 11 16:59:07 shelia kernel: Packet log: input DENY eth0 PROTO=17
> > 206.77.145.97:2200 x.x.x.x:161 L=265 S=0x00 I=10087 F=0x0000
> > T=102 (#1)

> > --
> > Ron Parker
> > Software Creations            http://www.scbbs.com
> > TradeWinds Publishing         http://www.intl-trade.com
> > TradePoint Los Angeles        http://www.tradepointla.org
> > SiteDirector Security Server  http://livepublish.scbbs.com
> > Civil War Online Library      http://civilwar.scbbs.com

--
Ron Parker
Software Creations            http://www.scbbs.com
TradeWinds Publishing         http://www.intl-trade.com
TradePoint Los Angeles        http://www.tradepointla.org
SiteDirector Security Server  http://livepublish.scbbs.com
Civil War Online Library      http://civilwar.scbbs.com
 
 
 

Probe to 161

Post by Amit Muth » Thu, 13 Apr 2000 04:00:00



> Not a big concern if you don't have snmp running.
> If you do, block it or consider killing your snmp service.

Beware - 'manageable' hubs and switches (whether you know they are
manageable or not) are liable to be using SNMP... someone who wanted to
break in to your network would *love* to control your switches and hubs...
 
 
 

Probe to 161

Post by Dictator for Li » Thu, 13 Apr 2000 04:00:00



>Yes, thanks for the reply.  I know what the port is.  What I don't understand, like
>so much of this security stuff, is why another machine outside my network would want
>to send udp packets to this port on several of my machines, one machine at a time,
>every couple hours or so.

>I would imagine that if the daemon is not running, no harm done.  But, WHY, what
>normal reason would someone outside my network would have to test to see if it is
>running?

>Thanks.

>-ron

There have been some reports of security problems with some snmp implementations
lately. See bugtraq archives.
 
 
 

Probe to 161

Post by Birger Toedtman » Thu, 13 Apr 2000 04:00:00




> > Not a big concern if you don't have snmp running.
> > If you do, block it or consider killing your snmp service.

> Beware - 'manageable' hubs and switches (whether you know they are
> manageable or not) are liable to be using SNMP... someone who wanted to
> break in to your network would *love* to control your switches and hubs...

Which is also the answer to the "why is someone trying them every now
and then (e.g. hourly)?"-question:

Image you install a new Server, HUB, Switch - almost ALL companies ship
their products with snmp servers preinstalled and preconfigured with
community "public" or the like. You just switch them on for some testing,
and...
....BINGO! nosy people now know things they shouldn't, uh?

Never insert a peace of hardware into your network before not having some
security measures done to them.

Regards,

Birger

 
 
 

1. getting bash to run on netbsd 161/sparc

newbie question

I recently installed NetBSD 1.6.1 on my Sparc 5
After downloading and compiling pkgsrc, I ran 'make' and 'make install'
from the /usr/pkgsrc/shells directory.
BASH 2.0.5 appears to be a part of 'shells' installed , however, it does not
appear to run once installed.

Anyone know how to get bash to run? ksh & tcsh appear to run just fine (as a
result of  running 'make' & 'make install')
Any tricks or advice is appreciated.

Thanks

2. Any command to bring back an rm-ed file ?

3. test 161

4. Connecting to Online Imformation Systems Provider with Linux.

5. Port 161

6. [RFT] port of Lockmeter on i386 2.5.64 Patch

7. Sample tests for 161

8. ifconfig: walras: bad address le0

9. NetATalk atalkd[161]: addmulti: invalid argument????

10. SNMP daemon not active on port 161 (or anywhere); daemon loaded.

11. aix Test 161

12. What is device with major 161 ?

13. Sample tests for 161