https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

Security


5.5 Million Devices Operating with WannaCry Port Open

  • Written by WeathersfieldTM
  • June 21, 2017
By now you'd think everyone would have battened down the hatches and locked down potentially dangerous ports vulnerable to WannaCry, but that's not the case.

Brought to you by Data Center Knowledge

With all of the press the WannaCry ransomware exploit received last month, you might be excused for thinking that by now everyone would have battened down the hatches and locked down potentially dangerous ports — at least those that are vulnerable to this exploit. According to two separate reports, that's not the case. And while it's true that many of the vulnerable devices are in the hands of consumers who don't know any better, it's a good bet that the majority are servers running in data centers, under the care of sysadmins who should know better.

Last week, security firm Rapid7 issued its annual National Exposure Index report, the result of scans of over 3 billion IP-addressable, public internet devices, checking for exposed services on 30 different ports. It found 160 million devices with open ports that generally should't be exposed to the internet. For file-sharing SMB port 445, the port associated with WannaCry, it found 5.5 million devices operating with the port exposed. About 800,000 of those were on Windows' systems — meaning they're directly vulnerable to the cryptoworm that targets Windows machines. Oddly, given the WannaCry panic, this is a higher number than last year when Rapid7 found only 4.6 million devices running with port 445 open.

This follows another set of numbers released last week from John Matherly, the founder the Shodan search engine which allows users to search the internet by device type. He reported finding more than 2,300,000 online devices with open SMB ports. More disturbingly, 42 percent of these — almost 970,000 devices — were configured for "guest access," making the data shared by way of the SMB file-sharing protocol available to anyone, with no authentication required. This also makes them vulnerable to simpler exploits than WannaCry.

Of the devices running with guest access enabled, Matherly said 90 percent were running Samba, the Linux file-sharing application that enables Linux servers to interface with Windows' clients. In both Windows and Samba, guest access is disabled by default, meaning admins have intentionally enabled the feature. Half of those were located on the network of Etisalat, a UAE-based ISP that operates in 17 countries across Asia, the Middle East and Africa, which Matherly sees as good news, but only because they're confined to a single network.

Although the Linux machines running Samba can't be targeted by EternalBlue, the exploit believed to have been developed by the NSA upon which WannaCry is based, they're not entirely safe either. Since late May, all versions of Samba released since 2010 have been vulnerable to an exploit called SambaCry in which a hacker can upload a shared library to a writable share and then cause the server to load and execute it.

There are now patched versions of Samba available to deal with the SambaCry exploit, but with everything else going on, it's likely that a considerable number of vulnerable Samba instances are still running.

If I ran a data center, I think I'd be sending a security advisory out to my customers right about now. Obviously, not everyone is paying attention.

Tags: Agents Cloud Service Providers MSPs VARs/SIs Security

Most Recent


  • SMB
    New Comcast Business SD-WAN Solutions Put Focus on SMBs
    The solutions appeal to smaller businesses that don't necessarily need site-to-site connectivity.
  • Cybersecurity research
    ConnectWise MSP Report: Cybercriminals to Heavily Target MSPs in 2023
    MSPs will remain the target of supply chain and critical infrastructure attacks.
  • online survey
    Kaseya MSP Survey: Growing Importance of Automation, Cybersecurity Remains Top Challenge
    MSPs will need to be up to speed on their security offerings to meet SMB demand.
  • Cloud Roundup
    Google Cloud Lashes Out at Microsoft, New Hurdle for Broadcom-VMware
    This cloud computing wrap-up showcases some big news and happenings at more under-the-radar cloud firms.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • Conflict Boxing Gloves
    Channel Conflict, Controversy: SolarWinds Hack, Racism, Layoffs, Zoom-RingCentral
  • Paying ransomware
    Sophos: Avaddon Ransomware Becoming More Prominent, Aggressive
  • Data management platform
    IBM Acquires Catalogic Software's Copy Data Management Business
  • security
    The Mounting Need for an Integrated Security Platform

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

HP’s Head of Global Channel Strategy Talks Program Changes, Poly Opportunity

March 31, 2023

National Women’s History Month: Channel Women’s Advice for Newbies

March 31, 2023

Is the Gap Widening Between Superagents and Mom-and-Pop Shops?

March 31, 2023

Industry Perspectives

View all

Co-innovation Is Needed to Effect Energy Transformation

March 31, 2023

AI Spells the End of End User Security

March 30, 2023

Why You Should Include Audiovisual Solutions in Your UC Services

March 28, 2023

Webinars

View all

Give Customers the Power: How MSPs Can Leverage Cloud Choice

April 4, 2023

DE&I Dialogue: How the Right DE&I Initiatives Can Propel Your Business

April 5, 2023

Meet the 2023 Channel Futures Channel Influencers

April 13, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Kaseya, Post-Acquisition, Expanding ‘Well-Regarded’ Datto Partner Program

Aryaka ‘Driving Value to the Channel Community’ with Throttle

March 24, 2023

Coffee with Craig and James Episode 121: Hewlett Packard Enterprise

March 23, 2023

Real-Life M&A: Advice for a Successful Channel Deal

March 13, 2023

Twitter

ChannelFutures

Learn about @comcastbusiness and some of the trends partners are seeing with #SMB customers. @craigschlagbaum… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

🤔 Interested in expanding on your brand or building a business from square one? @SkySwitchSays explains everythin… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

Energy transformation and climate change calls for innovation now @VMware #channelpartners #energycrisis #technews… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

Predictions are important when shaping your 2023 expectations & goals. #ChannelFutures is here to help out. We aske… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

Mary Beth Walker on @HP adapting its partner program in response to partner feedback, and what latest launches mean… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

.@ConnectWise report shows cybercriminals will continue heavily targeting #MSPs in 2023. dlvr.it/Slnlrj https://t.co/eEY0pMLJaQ

March 31, 2023
ChannelFutures

CP Expo preview: The "State of the Agent Market" panel will feature four rockstar partner speakers. Read a preview… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

.@Dell launches #DellLatitude and OptiPlex PCs, and Precision #workstations, adds Apex Managed Device Service.… twitter.com/i/web/status/1…

March 30, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X