Legacy May Kill – SANS Internet Storm Center

Date:

Share post:

Just saw something that I thought was long gone. The username “pop3user” is showing up in our telnet/ssh logs. I don’t know how long ago it was that I used POP3 to retrieve e-mail from one of my mail servers. IMAP and various webmail systems have long since replaced this classic email protocol. But at least this one attacker is counting on someone still having a “pop3user” configured.

The passwords attempted are the classics “pop3user” and “123456”. The sole IP address scanning for this username is 193.32.162.157. The IP address is part of AS47890, which is managed by Unmanaged (I am not making this up..)

route:          193.32.162.0/24

origin:         AS47890

mnt-by:         UNMANAGED

mnt-by:         ro-btel2-1-mnt

created:        2022-11-21T17:07:38Z

last-modified:  2022-11-21T17:07:38Z

source:         RIPE

The website for unmanaged.uk is blank, the network is probably unmanaged… not a fan of blocklists, but I would consider AS47890 a good candidate for a block.

pop3 still being used (maybe?), unmanaged networks… why are we wasting time trying to worry about 0-days?



Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu

Twitter|

Source link

spot_img

Related articles

Easy way to upload, transform and deliver files and images

Managing media is a really difficult task if you try to do all of it yourself, especially if...

Everything Apple Announced: iPhone Air, iPhone 17, Apple Watches, AirPods Pro 3

Another September, another Apple event. Today, Apple revealed its new iPhone 17 lineup in regular and Pro models,...

Troy Hunt: Weekly Update 468

I only just realised, as I...