Malanta Uncovers Design Tradeoff in SNMPv3 That Hands Attackers a Pre-Login Roadmap
<p>The behavior is standards-compliant and confirmed as intentional by the IETF, yet it lets an unauthenticated attacker fingerprint devices and enumerate valid usernames before login — shrinking a brute-force problem of billions of combinations to a focused password guess. Validated across...</p>
Read original article ↗