Quantcast
Channel: Information Security News
Viewing all articles
Browse latest Browse all 9687

What is happening on 2323/TCP?, (Fri, Oct 7th)

$
0
0

A number of sources, including DShield, have noticed an uptick on port 2323 TCP beginning around 3 weeks ago.

This is the scanner portion of the Mirai botnetscanning for IoT devices on both 23/TCP and 2323/TCP. There are a number of IoT devices that use port 2323/TCP as an alternate port for Telnet. Those who have setup listeners on port 2323 are seeing brute force credential attacks utilizing a small dictionary.

The Miraibotnet iwas used to attempt to DDOSBrian Krebs websiteiand ifor the nearly 1 TbpsDDOS against OVHin late September

-- Rick Wanner MSISE - rwanner at isc dot sans dot edu - http://namedeplume.blogspot.com/ - Twitter:namedeplume (Protected)

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Viewing all articles
Browse latest Browse all 9687

Trending Articles