EC-Council Certified Ethical Hacker (CEH) v12Reconnaissance TechniquesMedium
A security auditor is performing an internal network scan. They are concerned about potential misconfigurations in network devices that might allow unauthorized access. Specifically, they want to identify devices that respond to SNMP (Simple Network Management Protocol) requests and determine their community strings. Which port and associated tool would be most effective for this task?
- APort 23 (Telnet) with Hydra
- BPort 3389 (RDP) with Metasploit
- CPort 161 (SNMP) with snmpwalk
- DPort 21 (FTP) with Nmap
Show answer & explanationAnswer & explanation
Correct answer: C. Port 161 (SNMP) with snmpwalk
SNMP operates primarily on UDP port 161. The 'snmpwalk' tool is specifically designed to query SNMP agents and retrieve information, including attempting to guess or use known community strings to enumerate network device details.
Why the other options are wrong
- A. Port 23 is for Telnet, not SNMP, and Hydra is typically used for brute-forcing login credentials.
- B. Port 3389 is for RDP, not SNMP, and Metasploit is a framework for exploitation, not primarily for initial SNMP enumeration.
- D. Port 21 is for FTP, not SNMP, and Nmap is a scanner, not a dedicated SNMP enumerator.
SNMP Enumeration
The process of querying network devices using the Simple Network Management Protocol (SNMP) to gather information, often by guessing or exploiting weak community strings.
- Uses UDP port 161 (agent) and 162 (manager)
- Relies on community strings for authentication (e.g., 'public', 'private')
- Can reveal sensitive network topology and device configuration
Memory trick: SNMP at 161 helps you walk the network's secrets.