[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Updating the MIB security guidelines



>>>>> Wijnen, Bert (Bert) writes:

Bert> Some of the readable objects in this MIB module (that is all
Bert> objects with a MAX-ACCESS other than not-accessible) may be
Bert> considered

Juergen respondes:

>>  And even valus of not-accessible index objects can be retrieved by
>> reading some column and unpacking the index...

Bert> I understand that, but that is implicit if you get access to an
Bert> accessible column.

I guess the point I was trying to make is that the MAX-ACCESS clause
only tells you part of the story. Basically all variables exists so
that values can be shipped over the network to other boxes in one or
several different ways and the mechanism an attacker uses to get the
value really does not matter as long as he can get the value.

/js

-- 
Juergen Schoenwaelder    <http://www.informatik.uni-osnabrueck.de/schoenw/>