SNMPCHECK
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
snmpcheck enumerates information from SNMP-enabled devices. It provides a clean, readable output of system information, network interfaces, routing, services, storage, and more via SNMP queries.
BASIC USAGE#
snmpcheck -t <target> # Basic SNMP enumeration snmpcheck -t <target> -c public # Specify community string
OPTIONS#
snmpcheck -t <target> # Target IP address snmpcheck -c <community> # Community string (default: public) snmpcheck -v 1 # SNMP version 1 snmpcheck -v 2c # SNMP version 2c snmpcheck -p <port> # SNMP port (default: 161) snmpcheck -d # Disable TCP connections check snmpcheck -r # Enable reverse DNS lookups snmpcheck -w # Detect write access (SNMP SET)
EXAMPLES#
# Basic enumeration with default community string snmpcheck -t 192.168.1.1 # Custom community string snmpcheck -t 192.168.1.1 -c private # SNMP v2c with write detection snmpcheck -t 192.168.1.1 -v 2c -c public -w # Enumeration with DNS resolution snmpcheck -t 192.168.1.1 -r # Non-standard SNMP port snmpcheck -t 192.168.1.1 -p 1161
ENUMERATED INFORMATION#
# System Information: # - Hostname, OS version, system description # - System uptime, system contact, location # - Domain name # Network Information: # - Network interfaces and IPs # - Interface speeds and status # - Routing table # - ARP table # - TCP/UDP listening ports # - Network statistics # User Information: # - User accounts (Windows) # - Running processes # - Installed software # - System services # Storage Information: # - Disk partitions and usage # - Memory usage # - Device list # Additional: # - IIS web server info (if applicable) # - Shares (Windows) # - Installed hotfixes
COMMON COMMUNITY STRINGS#
public # Default read-only (most common) private # Default read-write community # Alternative default manager # Management access admin # Administrative access snmp # Generic SNMP string monitor # Monitoring access
COMMON SNMP OIDs#
1.3.6.1.2.1.1.1.0 # System description 1.3.6.1.2.1.1.3.0 # System uptime 1.3.6.1.2.1.1.4.0 # System contact 1.3.6.1.2.1.1.5.0 # System hostname 1.3.6.1.2.1.1.6.0 # System location 1.3.6.1.2.1.2.2 # Network interfaces 1.3.6.1.2.1.25.4.2.1.2 # Running processes (hrSW)
ALTERNATIVE TOOLS#
snmpwalk -v2c -c public <target> # Walk full SNMP tree
snmpget -v2c -c public <target> <OID>
# Get specific OID value
onesixtyone -c strings.txt <target>
# Brute force community strings
NOTES#
- SNMP v1/v2c sends community strings in cleartext - Default "public" community string is very common - SNMP can expose significant system information - Write access can allow system modification - Ruby-based tool - Try multiple community strings if default fails - SNMP v3 adds authentication and encryption - Pair with onesixtyone for community string brute forcing