Skip to Content
Practical Internet of Things Security - Second Edition
book

Practical Internet of Things Security - Second Edition

by Brian Russell, Drew Van Duren
November 2018
Intermediate to advanced
382 pages
11h 20m
English
Packt Publishing
Content preview from Practical Internet of Things Security - Second Edition

Ports, protocols, and services

Many of the IoT-based botnets we have seen in the past few years use telnet to spread. These botnets often attempt a dictionary attack against the telnet service, opened on either TCP port 23 or port 2323. Disabling the telnet service and closing these ports will mitigate a substantial attack vector and force botnets and other attackers to attempt access via other means. A list of additional ports to lock down is provided here. In some cases, such as HTTP, it is not practical to close the ports so monitor for signs of malicious activity:

Port  Use Malware type Reference
21 Dictionary attacks on FTP service Various
23 Dictionary attacks on telnet service Mirai, others https://isc.sans.edu/forums/diary/What+is+happening+on+2323TCP/21563/ ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Practical Industrial Internet of Things Security

Practical Industrial Internet of Things Security

Sravani Bhattacharjee
Core Software Security

Core Software Security

James Ransome, Anmol Misra
IoT Security

IoT Security

Madhusanka Liyanage, An Braeken, Pardeep Kumar, Mika Ylianttila

Publisher Resources

ISBN: 9781788625821Other