You will notice that
this application has a lot to offer, which is probably why it costs a substantial
amount of money. I can tell you from personal use that this product is worth
every cent.
388 Practical Hacking Techniques and Countermeasures
Continue to scroll through each section. You will see even more options.
Vulnerability Scanning 389
Click the Security section. Click on SNMP Brute Force Attack.
The SNMP Brute Force Attack utility will start. Click the Settings button.
390 Practical Hacking Techniques and Countermeasures
Click on the Character Set button.
From the Character Set, select which set of characters to use.
From the Community Strings, specify the Starting Community String.
Click OK.
Vulnerability Scanning 391
Enter the target IP address, select the Attack Speed, and click Attack.
With this tool the community string will eventually be discovered. The
demo version is limited to a few seconds so the results of this example are
simulated. The full version of Solar Winds Engineering Edition at the time of
this writing is $1,390.
*Note: When attackers discover the read-only community string, they are able to
perform an SNMP walk, which discovers various amounts of information
about the network. When the read/write string name is found an attacker
can then read the values of the managed device, make configuration changes,
and even shut down or reboot the system.
392 Practical Hacking Techniques and Countermeasures
Lab 63: Target Assessment
Assessment of Target Security: Retina
Prerequisites: None
Countermeasures: Secure ACLs, Bastion computers
Description: The Retina application is another commercial application.
Pages:
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151