Threat Level: green Handler on Duty: Rob VandenBrink

SANS ISC: Port 23 (tcp/udp) Attack Activity - SANS Internet Storm Center Port 23 (tcp/udp) Attack Activity


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Loading...
[get complete service list]
Port Information
Protocol Service Name
tcp telnet Telnet
udp telnet Telnet
tcp ADMworm [trojan] ADM worm
tcp FireHacKer [trojan] Fire HacKer
tcp MyVeryOwntrojan [trojan] My Very Own trojan
tcp RTB666 [trojan] RTB 666
tcp TelnetPro [trojan] Telnet Pro
tcp TinyTelnetServer [trojan] Tiny Telnet Server - TTS
tcp TruvaAtl [trojan] Truva Atl
Top IPs Scanning
TodayYesterday
45.134.174.234 (5578)149.57.210.215 (12642)
176.113.115.82 (5172)103.99.150.43 (7222)
103.99.150.43 (3865)194.31.98.17 (5873)
37.44.238.168 (3352)156.96.151.228 (4201)
198.12.90.146 (3256)45.61.186.75 (3909)
45.61.186.75 (2560)45.95.55.16 (3099)
156.96.151.228 (2479)31.220.3.140 (3007)
43.155.112.7 (2406)198.12.90.146 (2085)
89.37.95.164 (1155)49.142.188.6 (1913)
142.93.204.250 (1111)142.93.204.250 (1872)
Port diary mentions
URL
Distributed FTPPort 21 scan follow-up; Port 23 scan increases;
Something new on Telnet?
Solaris worm?
America's Got Telnet !
Increase in Port 23 (telnet) scanning
What is happening on 2323TCP?
Ongoing Scans Below the Radar
WTF tcp port 81
User Comments
Submitted By Date
Comment
2015-12-27 03:19:02
say, another thought, there's a "Snort" rule that appears to alert if a Juniper Network backdoor password attempt was made. (https://gist.github.com/fox-srt/ca94b350f2a91bd8ed3f) does that mean that, with all these port 23 hits happening, that the Juniper backdoor could have been found years ago by pretty much anyone on the Internet who just monitored the actual packets they were being probed with? if any of them were actually such attempts. maybe they'd have to use it to do some scanning themselves to find what it was for though. does anyone do that?
2015-12-27 03:18:55
Gee, activity on this ssl port became really strong around the middle of 2012, and the Juniper Networks ssl backdoor showed up around the middle of 2012. Only nobody knew it then. How did that happen?
Add a comment
CVE Links
CVE # Description
CVE-2001-0797 Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin.
CVE-2015-0014