-
Notifications
You must be signed in to change notification settings - Fork 365
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Question about SNMP detections #227
Comments
Thanks for getting in touch with us. Looking at those OIDs, I'd agree with you that some software on that host is probing your Opencanary host with SNMP requests regarding an HP printer status. If you have anymore information, I'd be happy to try figure out what is happening. |
Thanks @jayjb This is about all of the information I have. In the grand scheme of things, it's like 2 or 3 computers out of 3,000+ that trigger this alert randomly. I was hoping to try to understand these alerts from the other side. That is, what sort of attack is the canary trying to detect by listening on port 161? Why would a printer or printer software indiscriminately be spamming the network with traffic for 161? |
Check what printers are configured on the machine - it's usually part of the driver software itself, not any external utilities. You could also just ask those employees what printers they have at home, and if they've used it with their work computer :)
It just happens that some printers send status commands (among other things) over SNMP - in this case it's probably trying to scan the network for printers so it can offer configuring them for the user, or configure things automatically. It sends out a couple, to avoid missing a printer due to packet loss. An attacker trying to scan the network could also send a request to broadcast for, say, |
Thanks for the explanation @ChlorideCull. That was what I was looking for. I did remove the Epson driver via appwiz.cpl and re-installed the printer through Windows Metro settings for one specific user. It is sporadic, but I don't think we've picked up any more detections from that specific computer since. I am trying to follow up with other detections as they arise and seeing if I there is a driver listed in appwiz.cpl and if I can re-install the printer using native Windows drivers. |
Hi,
We occasionally receive detections in groups of three like this:
I looked up the OIDs and they appear to map to a printer of some sort, but the src_host is a computer that is configured similar to hundreds of other computers. I've removed all proprietary printer (Epson) software from this device, but still receive these SNMP detections.
Is my understanding correct that something on this computer is trying to broadcast its SNMP information to an SNMP trap and it just so happened to hit my canary? Has anyone else picked up random SNMP detections like this?
The text was updated successfully, but these errors were encountered: