Cert warns of web meltdown

SMNP holes threaten global infrastructure

Written by John Geralds in Silicon Valley

The Computer Emergency Response Team (Cert) has warned that numerous security holes in the Simple Network Management Protocol (SNMP) could shut down or cut off routers, PCs and other devices from the internet. It has already notified more than 200 manufacturers about the flaws.

Caldera, 3Com, Cisco Systems, Compaq, Hewlett Packard, IBM, Juniper Networks, Sun Microsystems, Microsoft, Lucent, Nokia and Network Associates are among the vendors that have either reported or are working on fixes for software flaws that could leave the web's basic infrastructure in danger of disruption.

The vulnerabilities involve the way in which SNMP implementations, which enable network administrators to remotely monitor and configure routers, switches, operating systems and network management systems, handle warning and error messages and requests.

If exploited, the vulnerabilities could allow attackers to disable the networked devices, cause denial of service interruptions to websites and even gain administrative control over the devices, according to Cert.

The flaws were first discovered by the Secure Programming Group at Finland's Oulu University. The team found multiple vulnerabilities in the way SNMP version one is implemented in many vendors' products.

Cert said that hundreds of vendors use the internet protocol found to be at risk and recommended that administrators disable SNMP on any machine that does not need it for normal operations.

"Large scale outages of these devices could disable significant portions of the global network," Cert said in its alert.

The group also warned that the problem is most serious for internet service providers which use routers to manage the flow of messages across computer networks and the web.

More information about the vulnerabilities is available at www.cert.org/advisories/CA-2002-03.html.

Tags:

Further reading

Cert warns of automated attacks

Hacking tools are becoming increasingly sophisticated   More...

SNMP vulnerability poses major threat

Biggest security problem in internet history, say experts   More...

Hackers switch to routers

Less secure systems attract rogue crackers   More...

Solaris flaw being 'actively exploited'

Cert alert highlights 'credible reports'   More...

Related articles

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

22 Jul 2008

3.22 MBSat-nav crashes, open source security and female gamers More...

21 Jul 2008

3.12 MBGlobal internet reach, online spending and the space race More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Security

Major DNS flaw revealed

Experts sound alarms over early disclosure   More...

Nintendo DS

Dodgy Chinese Nintendo chargers recalled

Experience could shock some users   More...

Advertisement

Houses of Parliament

Official 'spying' requests top 500,000

Information includes web records and itemised phone bills   More...

Hacking

Small firms naïve about security

SMBs remain prone to attack, says study   More...

Advertisement