Service Report
Global TCP/23 (telnet)
-
Top Attacks (past 24 hours)
Key Description Attacks per subnet Change from yesterday CVE Percentage EXPLOIT Solaris telnet USER environment vuln Attack inbound 4.68 -14.7 %
32.6%Solaris telnet USER environment variable login authentication bypass attempt 4.68 -14.7 %
CVE-2007-0882 32.6%EXPLOIT Solaris telnet USER environment vuln Attack outbound 4.68 -14.7 %
32.6%SCAN Behavioral Unusually fast outbound Telnet Connections, Potential Scan or Brute Force 0.31 -6.1 %
2.2% -
Sources (past 24 hours)
By Country
Key Country 
Bytes per subnet 
Percentage 
EG (Egypt)5.67 kB 16.3%
RU (Russian Federation)4.15 kB 11.9%
ES (Spain)2.89 kB 8.3%
GB (Great Britain)2.33 kB 6.7%
BE (Belgium)1.99 kB 5.7%
FR (France)1.95 kB 5.6%
IT (Italy)1.88 kB 5.4%
CZ (Czech Republic)1.71 kB 4.9%
KW (Kuwait)1.69 kB 4.8%
US (United States)1.22 kB 3.5%Other 9.33 kB 26.8%By ASN
Key ASN 
Bytes per subnet 
Percentage 
AS24863 (LINKdotNET-AS) 3.85 kB 11.1%AS21479 (ROSTOV-TELEGRAF-AS) 2.71 kB 7.8%AS3215 (AS3215) 1.72 kB 4.9%AS3352 (TELEFONICA-DATA-ESPANA) 1.63 kB 4.7%AS5432 (BELGACOM-SKYNET-AS) 1.52 kB 4.4%AS3225 (GULFNET-KUWAIT) 1.40 kB 4.0%AS3269 (ASN-IBSNAZ) 995.50 B 2.9%AS4788 (TMNET-AS-AP) 967.23 B 2.8%AS8452 (TEDATA) 907.24 B 2.6%AS6713 (IAM-AS) 777.61 B 2.2%Other 18.32 kB 52.6%By Host
Key Host 
Bytes per subnet 
Percentage 
89.204.6.252 557.10 B 1.6%212.160.195.134 497.19 B 1.4%91.165.238.64 (91-165-238-64.rev.libertysurf.net) 413.46 B 1.2%91.140.128.145 392.63 B 1.1%91.140.151.14 390.11 B 1.1%91.140.149.205 388.87 B 1.1%91.124.214.4 (4-214-124-91.pool.ukrtel.net) 376.07 B 1.1%196.205.226.19 (host-196-205-226-19.static.link.com.eg) 359.54 B 1.0%41.249.70.219 346.93 B 1.0%84.9.95.130 331.07 B 1.0%Other 30.74 kB 88.4%By Country
Key Country 
Attacks per subnet 
Percentage 
CN (China)3.56 24.8%
US (United States)2.98 20.7%
KR (South Korea)2.22 15.5%
IN (India)0.49 3.4%
MX (Mexico)0.42 2.9%
JP (Japan)0.39 2.7%
CA (Canada)0.29 2.0%
PK (Pakistan)0.26 1.8%
IL (Israel)0.25 1.7%
ES (Spain)0.25 1.7%Other 3.24 22.6%By ASN
Key ASN 
Attacks per subnet 
Percentage 
AS4134 (CHINANET-BACKBONE) 1.07 7.5%AS4766 (KIXS-AS-KR) 0.98 6.8%AS4837 (CHINA169-BACKBONE) 0.96 6.7%AS9318 (HANARO-AS) 0.39 2.7%AS9812 (CNNIC-CN-COLNET) 0.38 2.6%AS4538 (ERX-CERNET-BKB) 0.33 2.3%AS209 (ASN-QWEST) 0.32 2.3%AS9808 (CMNET-GD) 0.29 2.0%AS10933 (Unknown) 0.20 1.4%AS17557 (Unknown) 0.20 1.4%Other 9.23 64.3%By Host
Key Host 
Attacks per subnet 
Percentage 
218.242.212.18 0.38 2.6%121.135.179.245 0.34 2.3%67.135.29.143 (67-135-29-143.dia.static.qwest.net) 0.30 2.1%210.94.44.1 0.17 1.2%219.158.64.57 0.15 1.1%220.128.58.51 0.13 0.9%61.178.120.143 0.13 0.9%216.41.24.2 0.12 0.9%192.116.236.130 0.12 0.9%221.132.82.70 0.12 0.9%Other 12.38 86.3%
Background
| Vendors: | Conectiva, OpenBSD, Sun, rPath, SGI, APC, Cisco |
Vulnerabilities
CVE-2007-0956
The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning with a '-' character, a similar issue to CVE-2007-0882. |
|||
CVE-2007-0882
Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account. |
|||
CVE-2004-0311
American Power Conversion (APC) Web/SNMP Management SmartSlot Card 3.0 through 3.0.3 and 3.21 are shipped with a default password of TENmanUFactOryPOWER, which allows remote attackers to gain unauthorized access. |
|||
CVE-2001-0797
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin. |
|||
CVE-2001-0554
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function. |
|||
CVE-2001-0170
glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variables when executing setuid/setgid programs, which could allow local users to read arbitrary files. |
|||
CVE-2001-0041
Memory leak in Cisco Catalyst 4000, 5000, and 6000 series switches allows remote attackers to cause a denial of service via a series of failed telnet authentication attempts. |
|||
CVE-2000-0733
Telnetd telnet server in IRIX 5.2 through 6.1 does not properly cleans user-injected format strings, which allows remote attackers to execute arbitrary commands via a long RLD variable in the IAC-SB-TELOPT_ENVIRON request. |
|||
CVE-1999-0501
A Unix account has a guessable password. |
|||
CVE-1999-0073
Telnet allows a remote client to specify environment variables including LD_LIBRARY_PATH, allowing an attacker to bypass the normal system libraries and gain root access. |