I legit laughed out loud.
I legit laughed out loud.
It's also very popular for ISPs to drop traffic on the windows file sharing ports, because it's almost all either malicious or at least unintentional.
Phew.
gets back to trying to convince his bank to send his data over plain FTP
Bob: A big round of applause to Fred and Jane for setting up that XZ back door! Boy that got us so much intel!
A round of polite clapping.
Bob: What’s your status, Igor?
Igor: Bah, my target is running web server on MS-DOS. I finally managed to hand craft 16 bit 8086 machine code exploit last night (mind you during Hacker News Hug of Death) and gain remote access to A: drive but it turns out secrets are actually hosted on Amiga 2000 on private LAN which I can ping but I don’t know 68k.
Bob: Fortunately we’re a state sponsored hacking organization so we have considerable resources. R.J., do you think you can help Igor?
R.J.: Sure! Igor, do you know if it has an OCS or ECS chipset? …
There is no botnet targeting web services running on DOS, because no one is running web services on DOS.
What exactly is the difference?
Bots, instead, throw shit at a wall and see what sticks. Move your SSH server with credentials root:root on port 1234 and notice how many bots get utterly defeated (only for sake of argument, because OpenSSH has a banner which makes it easy to identify wherever it's running)
And once it sticks, an insecure server has been found. A bot is just a tool someone is using.
Security through obscurity is an overused concept: it doesn't work against determined humans, but on the greater internet, when your adversary are bots, it is extremely effective.