NRPE/NSCA replacement thoughts?

Kevin Keane subscription at kkeane.com
Fri Feb 19 17:05:24 CET 2010


> -----Original Message-----
> From: Marc Powell [mailto:marc at ena.com]
> 
> On Feb 19, 2010, at 5:05 AM, Michael Schwartzkopff wrote:
> 
> >> Quite secure ? With UDP (spoofing) and a community not encrypted ?
> >> SNMP : Security Not My Problem ;-)
> >
> > OK. With ip spoofing you cen send packages. But if you do not the
> routing back
> > you will never receive the answer. So what.
> 
> If the write community is known, that 'So what' can be quite a big
> deal.

You don't even need the community. CERT has a very long list of vulnerabilities, many of whom apply before the community string is ever evaluated.


------------------------------------------------------------------------------
Download Intel® Parallel Studio Eval
Try the new software tools for yourself. Speed compiling, find bugs
proactively, and fine-tune applications for parallel performance.
See why Intel Parallel Studio got high marks during beta.
http://p.sf.net/sfu/intel-sw-dev
_______________________________________________
Nagios-users mailing list
Nagios-users at lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/nagios-users
::: Please include Nagios version, plugin version (-v) and OS when reporting any issue. 
::: Messages without supporting info will risk being sent to /dev/null





More information about the Users mailing list