Hackers Bringing Telnet Back
alphadogg writes "A new report from Akamai Technologies (CT: Requires login) shows that hackers appear to be increasingly using the Telnet remote access protocol to attack corporate servers over mobile networks.
The report, which covers the third quarter of 2010, shows that 10 percent of attacks that came from mobile networks are directed at Port 23, which Telnet uses. That marks a somewhat unusual spike for the aging protocol used to log into remote servers but that has been gradually replaced by SSH."
I use telnet clients from time to time, in the lab. You can use it connect and send data to any old port, not just 23. I would never run the telnet daemon though, and seven times never on a box that's exposed to the public Internet.
[Sir Garlon] is the marvellest knight that is now living, for he destroyeth many good knights, for he goeth invisible.
You obviously don't work in a large enterprise that insists on using broken terminals that only do telnet. Its kinda like ftp. You want to get rid of it, but there are always some assholes who continue to use broken clients.
I have to post this anonymously for the safety of my job.
Lensmoor.org port 3500
Shameless plug. Fun place to hang ;)
This is the case with certain Cisco IOS versions. It has to be a crypto version of IOS to support SSH.
SSC