iTnews
  • Home
  • News
  • Technology
  • Security

Aussies leaving lots of insecure ports open to attackers

By Juha Saarinen on Jun 16, 2017 11:05AM
Aussies leaving lots of insecure ports open to attackers

Firewall off those SMB and database servers.

Australian sysadmins continue to live dangerously and expose insecure network services to a hostile internet, putting themselves at risk of compromise and information theft.

Security vendor Rapid7 scanned much of the IPv4 internet [pdf] to check the extent of networked computer systems exposing services to the world.

The scans ranked Australia ninth globally for offering more exposed services relative to its total size on the internet than most other developed nations.

In total, Rapid7 scanned close to 48.5 million IPv4 addresses allocated to Australia for its report.

Unnecessary exposure of specific services to the internet can be abused by attackers to compromise computer systems and steal information.

For instance, the WannaCry ransomware worm that ripped through hundreds of thousands of systems scanned for internet-connected computers that ran vulnerable versions of Microsoft's System Message Block file sharing protocol.

Despite the widespread publicity around WannaCry, Rapid7 found over one million systems still offering SMB file sharing services to the internet.

Likewise, distributed denial of service botnets like Mirai scan for internet of things (IoT) devices that listen on the clear-text telnet remote access port 23 for takeover opportunities.

Many admins also leave information at risk of being stolen or ransomed by carelessly exposing database servers to the internet.

"For example, we surveyed the internet for the database service ports associated with Microsoft SQL Server (port 1433) and MySQL (port 3306)," Rapid7 said.

"Both of these database systems offer perfectly adequate authentication protocols and encryption guarantees, but the services offer direct access to random strangers when, in practice, there is no earthly reason to do so."

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
rapid7securitywannacry

Partner Content

The Great Resignation has intensified insider security threats
Promoted Content The Great Resignation has intensified insider security threats
Digital signatures propel Australian Unity with rapid time to value
Digital signatures propel Australian Unity with rapid time to value
Accenture and Google Cloud team up to create a loveable, Australian-first, renewable energy product
Promoted Content Accenture and Google Cloud team up to create a loveable, Australian-first, renewable energy product
Security "mindset shift" needed to protect organisations
Promoted Content Security "mindset shift" needed to protect organisations

Sponsored Whitepapers

Free eBook: Digital Transformation 101 – for banks
Free eBook: Digital Transformation 101 – for banks
Why financial services need to tackle their Middle Office
Why financial services need to tackle their Middle Office
Learn: The latest way to transfer files between customers
Learn: The latest way to transfer files between customers
Extracting the value of data using Unified Observability
Extracting the value of data using Unified Observability
Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see

Events

  • Forrester Technology & Innovation Asia Pacific 2022
By Juha Saarinen
Jun 16 2017
11:05AM
0 Comments

Related Articles

  • Zyxel firewalls vulnerable to remote code execution
  • Apple drops iOS and iPadOS 15.6.1 to fix two exploited zero days
  • Twilio phish sees Signal users' numbers at risk of re-registering
  • ACCC greenlights Google's buy of Mandiant
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Services Australia sets changeover date for myGov

Services Australia sets changeover date for myGov

Google Cloud IoT Core goes on the end-of-life list

Google Cloud IoT Core goes on the end-of-life list

NBN Co proposes to axe CVC across all plans by mid-2026

NBN Co proposes to axe CVC across all plans by mid-2026

NSW Police dumps Bezos-backed Mark43 from core systems overhaul

NSW Police dumps Bezos-backed Mark43 from core systems overhaul

Digital Nation

Stakes are higher for cybersecurity in Web3: Gal Tal-Hochberg, CTO at Team8
Stakes are higher for cybersecurity in Web3: Gal Tal-Hochberg, CTO at Team8
Edge and IoT critical to Web3 infrastructure
Edge and IoT critical to Web3 infrastructure
Crypto losses to crime surge to $1.9 B in first half of 2022: Chainalysis
Crypto losses to crime surge to $1.9 B in first half of 2022: Chainalysis
Save the Date — Digital Nation Live launches on October 25
Save the Date — Digital Nation Live launches on October 25
CommBank’s mobile banking app beats ANZ, NAB, Suncorp and Westpac: Forrester
CommBank’s mobile banking app beats ANZ, NAB, Suncorp and Westpac: Forrester
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.