← All cheat sheets

SNMPCHECK

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

snmpcheck enumerates information from SNMP-enabled devices. It
provides a clean, readable output of system information, network
interfaces, routing, services, storage, and more via SNMP queries.

BASIC USAGE#

snmpcheck -t <target>            # Basic SNMP enumeration
snmpcheck -t <target> -c public  # Specify community string

OPTIONS#

snmpcheck -t <target>            # Target IP address
snmpcheck -c <community>         # Community string (default: public)
snmpcheck -v 1                   # SNMP version 1
snmpcheck -v 2c                  # SNMP version 2c
snmpcheck -p <port>              # SNMP port (default: 161)
snmpcheck -d                     # Disable TCP connections check
snmpcheck -r                     # Enable reverse DNS lookups
snmpcheck -w                     # Detect write access (SNMP SET)

EXAMPLES#

# Basic enumeration with default community string
snmpcheck -t 192.168.1.1

# Custom community string
snmpcheck -t 192.168.1.1 -c private

# SNMP v2c with write detection
snmpcheck -t 192.168.1.1 -v 2c -c public -w

# Enumeration with DNS resolution
snmpcheck -t 192.168.1.1 -r

# Non-standard SNMP port
snmpcheck -t 192.168.1.1 -p 1161

ENUMERATED INFORMATION#

# System Information:
# - Hostname, OS version, system description
# - System uptime, system contact, location
# - Domain name

# Network Information:
# - Network interfaces and IPs
# - Interface speeds and status
# - Routing table
# - ARP table
# - TCP/UDP listening ports
# - Network statistics

# User Information:
# - User accounts (Windows)
# - Running processes
# - Installed software
# - System services

# Storage Information:
# - Disk partitions and usage
# - Memory usage
# - Device list

# Additional:
# - IIS web server info (if applicable)
# - Shares (Windows)
# - Installed hotfixes

COMMON COMMUNITY STRINGS#

public                           # Default read-only (most common)
private                          # Default read-write
community                        # Alternative default
manager                          # Management access
admin                            # Administrative access
snmp                             # Generic SNMP string
monitor                          # Monitoring access

COMMON SNMP OIDs#

1.3.6.1.2.1.1.1.0               # System description
1.3.6.1.2.1.1.3.0               # System uptime
1.3.6.1.2.1.1.4.0               # System contact
1.3.6.1.2.1.1.5.0               # System hostname
1.3.6.1.2.1.1.6.0               # System location
1.3.6.1.2.1.2.2                 # Network interfaces
1.3.6.1.2.1.25.4.2.1.2          # Running processes (hrSW)

ALTERNATIVE TOOLS#

snmpwalk -v2c -c public <target> # Walk full SNMP tree
snmpget -v2c -c public <target> <OID>
                                 # Get specific OID value
onesixtyone -c strings.txt <target>
                                 # Brute force community strings

NOTES#

- SNMP v1/v2c sends community strings in cleartext
- Default "public" community string is very common
- SNMP can expose significant system information
- Write access can allow system modification
- Ruby-based tool
- Try multiple community strings if default fails
- SNMP v3 adds authentication and encryption
- Pair with onesixtyone for community string brute forcing