Hackers turn back the clock with Telnet attacks
networkworld.com
networkworld.com
http://isc.sans.edu/reports.html
Only one of their 3 top ten ports even lists telnet, it doesn't show in the total volume one.
Top 10 Ports by Targets
Port Targets
22 83923
1433 69095
445 44441
1434 43076
3389 30991
80 17262
139 12637
137 8677
4559 8246
23 6562 <- telnet port, total: 0.02% of top ten
That 0.02% seems to jibe with what I expected based on seing my own deny logs. I'm not sure what's up with the akamai report because I didn't feel like giving them my email just to let me read something that sounds wildly inaccurate, but I'm calling BS.Perhaps akamai themselves often leaves telnet open (on some network hardware they use?) and are being targeted specifically.
4559 is apparently "hylafax", but I have no idea what that is.
(22 is of course ssh, 445 is SMB, 80 is HTTP, 137 and 139 are netbios name and session service, respectively.)
Man, I can't even remember when I last used telnet to actually access a host rather than to use it to test if some text protocol worked as expected.
What's next? rsh?
I'd like to know which OS in recent memory installed with telnetd running by default? None I'm familiar with.