<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; snmp</title>
	<atom:link href="http://www.darknet.org.uk/tag/snmp/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>GFI EventsManager &#8211; Event Monitoring, Archiving &amp; Management</title>
		<link>http://www.darknet.org.uk/2010/01/gfi-eventsmanager-event-monitoring-archiving-management/</link>
		<comments>http://www.darknet.org.uk/2010/01/gfi-eventsmanager-event-monitoring-archiving-management/#comments</comments>
		<pubDate>Wed, 13 Jan 2010 09:34:39 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[bi]]></category>
		<category><![CDATA[business intelligence]]></category>
		<category><![CDATA[event archiving]]></category>
		<category><![CDATA[event management]]></category>
		<category><![CDATA[event monitoring]]></category>
		<category><![CDATA[eventsmanager]]></category>
		<category><![CDATA[gfi]]></category>
		<category><![CDATA[gfi events manager]]></category>
		<category><![CDATA[gfi eventsmanager]]></category>
		<category><![CDATA[gfi software]]></category>
		<category><![CDATA[hipaa]]></category>
		<category><![CDATA[log management]]></category>
		<category><![CDATA[pci dss]]></category>
		<category><![CDATA[snmp]]></category>
		<category><![CDATA[snmp traps]]></category>
		<category><![CDATA[sox]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2363</guid>
		<description><![CDATA[You may remember a while back we reviewed the latest update of GFI LANguard 9, another powerful product developed by GFI is EventsManager. Managing, archiving and monitoring logs and SNMP traps for a whole network can be a bit of a logistical nightmare, that&#8217;s where products like this come in. Commonly they are known under [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>You may remember a while back we reviewed the latest update of <a href="http://www.darknet.org.uk/2009/07/gfi-languard-9-review-network-security-scanner-vulnerability-management-tool/">GFI LANguard 9</a>, another powerful product developed by GFI is <a href="http://www.gfi.com/eventsmanager">EventsManager</a>.</p>
<p>Managing, archiving and monitoring logs and SNMP traps for a whole network can be a bit of a logistical nightmare, that&#8217;s where products like this come in. Commonly they are known under the umbrella term Business Intelligence Systems or more specifically Log/Event Management.</p>
<p>Installation is easy enough as per usual with GFI software, configuration will be a little more complex depending on the architecture of your network. If you have any problems however you can download the user manual here &#8211; <a href="http://www.gfi.com/esm/esm8manual.pdf">esm8manual.pdf</a> [PDF]. Do note you will require a local or remote instance of MS-SQL for events archiving. You can download and use <a href="http://www.microsoft.com/Sqlserver/2005/en/us/express.aspx">MS-SQL 2005 Express Edition</a> (which is free).</p>
<p>You can find an overview of the software <a href="http://www.gfi.com/eventsmanager">here</a> and a full features list <a href="http://www.gfi.com/eventsmanager/esmfeatures.htm">here</a>.</p>
<p>Once you get started you&#8217;ll need to setup the MS-SQL database before you can do anything else, so either put the details for your remote server or install the free express edition then set up the database.</p>
<p align="center"><img src="http://farm3.static.flickr.com/2769/4271339498_32d2769622.jpg" alt="GFI EventsManager" /></p>
<p>After that you can select if you wish to process local computer events, selected machines or setup custom config (snmp traps/syslog). There are a lot of options in the configuration management and allows you to easily aggregate the logs/SNMP output from a whole network. It allows logging from a plethora of devices including Windows and Linux servers, Cisco devices, Juniper devices, laptops, desktops and databases.</p>
<p align="center"><img src="http://farm5.static.flickr.com/4053/4271339726_08fda6e466.jpg" alt="Config Manager" /></p>
<p>The main screen gives you a very simple overview that the services are running correctly and the global events count with a break-down by type.</p>
<p align="center"><img src="http://farm5.static.flickr.com/4022/4271339554_b28af09ac3.jpg" alt="Status Screen" /></p>
<p>The graphing view allows you to visually see by source or globally by event classification and volume flow by hour.</p>
<p align="center"><img src="http://farm5.static.flickr.com/4028/4271339642_45b105285a.jpg" alt="Graph View" /></p>
<p>The Event Browser allows you to view individual events, drill down to the details captured and sort them by status allowing you to track down problems easily and diagnose which application is causing the problem.</p>
<p align="center"><img src="http://farm5.static.flickr.com/4003/4270594451_384403b941.jpg" alt="Event Browser" /></p>
<p>You can also add the free <a href="http://www.gfi.com/eventsmanager/esmreportpack.htm">GFI EventsManager ReportPack</a>, which enables you to generate graphical IT-level, technical and management reports based on the hardware and software events processed by GFI EventsManager.</p>
<p><a href="http://www.gfi.com/products/gfi-eventsmanager/pricing">Pricing</a> runs as low as $45.00 per node for Servers and $4.50 per node for Workstations if you buy in bulk.</p>
<p>You can download the free trial here:</p>
<p><a href="http://www.gfi.com/downloads/register.aspx?pid=esm">http://www.gfi.com/downloads/register.aspx?pid=esm</a></p>
<p>You can find the full details on GFI EventsManager here:</p>
<p></p>
<p><a href="http://www.gfi.com/eventsmanager">http://www.gfi.com/eventsmanager</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=GFI+EventsManager+%E2%80%93+Event+Monitoring%2C+Archiving+%26+Management+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2363+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/01/gfi-eventsmanager-event-monitoring-archiving-management/&amp;t=GFI+EventsManager+%E2%80%93+Event+Monitoring%2C+Archiving+%26+Management" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/01/gfi-eventsmanager-event-monitoring-archiving-management/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/01/gfi-eventsmanager-event-monitoring-archiving-management/&amp;title=GFI+EventsManager+%E2%80%93+Event+Monitoring%2C+Archiving+%26+Management" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/01/gfi-eventsmanager-event-monitoring-archiving-management/&amp;title=GFI+EventsManager+%E2%80%93+Event+Monitoring%2C+Archiving+%26+Management" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/01/gfi-eventsmanager-event-monitoring-archiving-management/&amp;title=GFI+EventsManager+%E2%80%93+Event+Monitoring%2C+Archiving+%26+Management" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/01/gfi-eventsmanager-event-monitoring-archiving-management/&amp;title=GFI+EventsManager+%E2%80%93+Event+Monitoring%2C+Archiving+%26+Management" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F01%2Fgfi-eventsmanager-event-monitoring-archiving-management%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/01/gfi-eventsmanager-event-monitoring-archiving-management/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>onesixtyone 0.3.2 &#8211; An Efficient SNMP Scanner</title>
		<link>http://www.darknet.org.uk/2008/09/onesixtyone-032-an-efficient-snmp-scanner/</link>
		<comments>http://www.darknet.org.uk/2008/09/onesixtyone-032-an-efficient-snmp-scanner/#comments</comments>
		<pubDate>Mon, 08 Sep 2008 09:55:45 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[161]]></category>
		<category><![CDATA[network scanning]]></category>
		<category><![CDATA[network-security]]></category>
		<category><![CDATA[onesixtyone]]></category>
		<category><![CDATA[snmp]]></category>
		<category><![CDATA[snmp hacking]]></category>
		<category><![CDATA[snmp scanner]]></category>
		<category><![CDATA[snmp scanning]]></category>
		<category><![CDATA[snmp security]]></category>
		<category><![CDATA[udp]]></category>
		<category><![CDATA[udp hacking]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1041</guid>
		<description><![CDATA[The SNMP protocol is a stateless, datagram oriented protocol. An SNMP scanner is a program that sends SNMP requests to multiple IP addresses, trying different community strings and waiting for a reply. Unfortunately SNMP servers don&#8217;t respond to requests with invalid community strings and the underlying UDP protocol does not reliably report closed UDP ports. [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>The SNMP protocol is a stateless, datagram oriented protocol. An SNMP scanner is a program that sends SNMP requests to multiple IP addresses, trying different community strings and waiting for a reply. Unfortunately SNMP servers don&#8217;t respond to requests with invalid community strings and the underlying UDP protocol does not reliably report closed UDP ports. This means that &#8216;no response&#8217; from the probed IP address can mean either of the following:</p>
<ul>
<li>machine unreachable</li>
<li>SNMP server not running</li>
<li>invalid community string</li>
<li>the response datagram has not yet arrived</li>
</ul>
<p>The approach taken by most SNMP scanners is to send the request, wait for n seconds and assume that the community string is invalid. If only 1 of every hundred scanned IP addresses responds to the SNMP request, the scanner will spend 99*n seconds waiting for replies that will never come.</p>
<p>This makes traditional SNMP scanners very inefficient.</p>
<p>onesixtyone takes a different approach to SNMP scanning. It takes advantage of the fact that SNMP is a connectionless protocol and sends all SNMP requests as fast as it can. Then the scanner waits for responses to come back and logs them, in a fashion similar to Nmap ping sweeps. By default onesixtyone waits for 10 milliseconds between sending packets, which is adequate for 100Mbs switched networks. The user can adjust this value via the -w command line option. If set to 0, the scanner will send packets as fast as the kernel would accept them, which may lead to packet drop.</p>
<p>Running onesixtyone on a class B network (switched 100Mbs with 1Gbs backbone) with -w 10 gives us a performance of 3 seconds per class C, with no dropped packets. All 65536 IP addresses were scanned in less than 13 minutes.</p>
<p>You can download onesixtyone here:</p>
<p><a href="http://www.phreedom.org/solar/onesixtyone/onesixtyone-0.3.2.tar.gz">onesixtyone-0.3.2.tar.gz</a></p>
<p></p>
<p>Or read more <a href="http://www.phreedom.org/solar/onesixtyone/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=onesixtyone+0.3.2+%E2%80%93+An+Efficient+SNMP+Scanner+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1041+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2008/09/onesixtyone-032-an-efficient-snmp-scanner/&amp;t=onesixtyone+0.3.2+%E2%80%93+An+Efficient+SNMP+Scanner" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2008/09/onesixtyone-032-an-efficient-snmp-scanner/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2008/09/onesixtyone-032-an-efficient-snmp-scanner/&amp;title=onesixtyone+0.3.2+%E2%80%93+An+Efficient+SNMP+Scanner" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2008/09/onesixtyone-032-an-efficient-snmp-scanner/&amp;title=onesixtyone+0.3.2+%E2%80%93+An+Efficient+SNMP+Scanner" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2008/09/onesixtyone-032-an-efficient-snmp-scanner/&amp;title=onesixtyone+0.3.2+%E2%80%93+An+Efficient+SNMP+Scanner" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2008/09/onesixtyone-032-an-efficient-snmp-scanner/&amp;title=onesixtyone+0.3.2+%E2%80%93+An+Efficient+SNMP+Scanner" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2008%2F09%2Fonesixtyone-032-an-efficient-snmp-scanner%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2008/09/onesixtyone-032-an-efficient-snmp-scanner/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

