Skip to content
Silverfern

We Need to Talk About Open/Exposed Ports

By Zoe Montague · · 20 min read

  • Cybersecurity
  • Network Security
  • Risk Assessment
  • Technical Analysis

There is a disturbing amount of devices that are connected to the internet and have ports open to the world that should not be open. We are at a time where the world is the most connected it has ever been.

You can jump on the internet and play a game with someone from the opposite site of the world. You can watch a YouTube series that was made in a small town in Ontario, Canada while on a boat in the middle of the ocean. You can meet people online that you relate to or have common interests with, even though you may live in an area that isn’t friendly to who you are.

This makes me think of a song called “Welcome to the Internet” by Bo Burnham from his musical/documentary “Inside”: “Could I interest you in everything? All of the time? A little bit of everything, all of the time”

What Are Ports?

Non-Technical Explanation

Imagine your computer is like a large office building. Each room in the building has a specific function, like a bedroom, a kitchen, or an office. Ports are like the doors to these rooms. They allow different types of communication to happen between your computer and other devices.

For example, one door might be for sending emails, another for browsing the internet, and another for printing documents. When these doors (ports) are left open, anyone can potentially walk in and access the room, which can be risky if not properly managed.

Technical Explanation

A port is a logical construct that identifies a specific process or type of network service. Ports are used by the Transport Layer protocols TCP (Transmission Control Protocol) and UDP (User Datagram Protocol) to direct packets to the appropriate application or service running on a device.

HTTP (Port 80): The foundation of data communication on the web

HTTPS/SSL (Port 443): Secure version of HTTP with encryption. Also commonly used for encrypted VPN traffic

SMTP (Port 25): Simple Mail Transfer Protocol for sending emails

SMB (Port 445): Server Message Block for file sharing. Used by Windows PCs, NAS devices, and printers

RDP (Port 3389): Remote Desktop Protocol for remote access to Windows computers

SSH (Port 22): Secure Shell for secure remote login to Linux devices, networking equipment, and IoT devices

Risks Associated with Open/Exposed Ports

Now that I’ve explained what a port is, and given some examples of what types of services and what ports they use, why is it an issue if some of these are open to the internet? Let me breakdown some of the ways these open ports could be exploited.

Unauthorized Access

Open ports can serve as entry points for hackers to infiltrate your network. For example, an open RDP (port 3389) can allow attackers to gain remote access to a computer, potentially leading to unauthorized control and data theft.

Malware Infections

Exposed ports increase the likelihood of malware entering your network. For example, SMB (port 445) was exploited by the WannaCry ransomware to spread across networks, causing widespread disruption.

Denial of Service (DoS) Attacks

Attackers can target open ports to overwhelm your network with traffic, rendering it unavailable to legitimate users. An open HTTP (port 80) can be used to launch DoS attacks on web servers.

Data Exfiltration

If an attacker gains access through an open port, they can easily exfiltrate sensitive data without your knowledge. An open SMTP (port 25) can be exploited to send out large volumes of sensitive information via email.

Increased Attack Surface

Every open port expands the attack surface of your network, increasing the chances of a breach. Reducing the number of open ports minimizes potential entry points for attackers.

Case Studies, Examples, and Statistics

Shodan is a search engine that scans the internet for connected devices and services. Unlike traditional search engines that index web pages, Shodan indexes information about devices such as desktops, laptops, servers, network devices, and more. It collects data on open ports, services running on those ports, and various other details about the devices it finds.

Using Shodan, I have gathered statistics on open ports to illustrate the prevalence and risks associated with exposed ports.

Heartbleed Vulnerability (April 2014)

The Heartbleed bug was a critical vulnerability in the OpenSSL cryptographic software library, discovered in April 2014. It allowed attackers to read sensitive data from the memory of affected servers, including usernames, passwords, and private keys.

17% of all SSL servers affected at discovery

11/10 severity rating by security expert Bruce Schneier

WannaCry (May 2017)

The WannaCry ransomware attack was a significant global cyberattack that occurred in May 2017. It targeted computers running the Microsoft Windows operating system by encrypting data and demanding ransom payments in Bitcoin. The attack spread using an exploit called EternalBlue, which targeted an exploit in SMB on port 445.

200,000+ systems affected globally

150+ countries impacted

$Billions in estimated damages

Maritime Cybersecurity Incident (April 2024)

In April 2024, a coordinated cyberattack targeted several key maritime ports and vessels worldwide, causing widespread disruption. The attackers exploited vulnerabilities in the Automatic Identification Systems (AIS), which often have open ports for communication.

1,800+ vessels targeted

$500M+ in financial losses

$3.2M average ransom demand

IoT Device Exploitation (May 2024)

In May 2024, Microsoft uncovered a significant cyberattack targeting internet-facing IoT devices and Linux-based systems. The attackers leveraged custom and open source tools to exploit open ports, particularly SSH (port 22), to gain unauthorized access and deploy malicious software.

136% increase in IoT vulnerabilities from previous year

Statistics from Shodan Research

Using Shodan, I gathered data on the prevalence of open ports across various devices connected to the internet. These numbers can only indicate how many devices Shodan has found with these ports, so we cannot use these as definite numbers. These numbers could be higher, we just don’t have proof of that.

Remote Desktop Protocol (Port 3389)

3,454,773 instances

Top 5 Countries:
  • United States: 986,492
  • China: 885,012
  • Singapore: 210,271
  • Germany: 181,166
  • United Kingdom: 107,941

Server Message Block (Port 445)

1,496,708 instances

Top 5 Countries:
  • United States: 600,158
  • Pakistan: 90,225
  • Russia: 71,899
  • Hong Kong: 70,232
  • Germany: 70,122

209,083 instances with authentication disabled

178,264 running insecure SMB version 1

Example Shodan search results showing SMBv1 with authentication disabled:

SMB with authentication disabled - Example 1
Shodan search result showing SMBv1 with disabled authentication
SMB with authentication disabled - Example 2
Another instance of vulnerable SMB configuration
SMB with authentication disabled - Example 3
SMBv1 exposed device with critical vulnerabilities
SMB with authentication disabled - Example 4
Real-world example of insecure SMB configuration

These screenshots show real devices found on Shodan with SMBv1 and disabled authentication - a critical security vulnerability that leaves systems wide open to attack. Click any image to enlarge.

Geographic Distribution

977,890 Kansas City

224,092 Mountain View

101,959 Redwood City

91,010 San Jose

Regional distribution of exposed ports:

United States exposed ports dashboard
Distribution of exposed ports across the United States
Canada exposed ports dashboard
Distribution of exposed ports across Canada

Real-World Exposure Examples

The following images demonstrate actual exposed devices found through Shodan, including firewall login interfaces and security cameras with public access. These represent real security vulnerabilities that could be exploited by malicious actors.

Exposed Sonicwall firewall login screen
SonicWall firewall login exposed to the internet - a critical security risk
Public security camera feeds accessible online
Security cameras with public access - privacy and security concerns

These examples illustrate how critical infrastructure can be inadvertently exposed to the internet, creating significant security risks. Click images to see full details.

Organizations with Most Open Ports

  • Google LLC 1,195,911
  • Incapsula Inc 106,219
  • Microsoft Corporation 71,733
  • Amazon Technologies Inc 18,919

Note: Microsoft and Amazon numbers include Azure and AWS services deployed by businesses, meaning many individual businesses should be on this list but aren’t due to platform ownership.

Common Vulnerabilities Found

SMBv3 Remote Code Execution (CVE-2020-0796)

40,851 vulnerable instances

BlueKeep 2,398 vulnerable instances in RDP

EternalBlue 330 vulnerable instances in SMB

Common Tags & Risk Indicators

1,128,386 Cloud-hosted instances with exposed ports

51,075 Devices running end-of-life operating systems

Top Operating Systems with Open Ports

  • Windows Server 2022 121,576
  • Windows 10 (build 17763) 88,993
  • Windows Server 2012 R2 (EOL) 63,699

Conclusion

Open ports on internet-connected devices present significant security risks that cannot be ignored. As we have seen through various case studies and statistics, these vulnerabilities can lead to unauthorized access, malware infections, denial of service attacks, data exfiltration, and compromised devices.

High-profile incidents like the WannaCry ransomware attack, the Heartbleed vulnerability, the IoT device exploitation, and the Maritime Cybersecurity Incident highlight the critical need for increased security measures.

By understanding the nature of ports and the risks associated with leaving them exposed, IT professionals and organizations can take proactive steps to secure their networks. Regular port scanning, proper firewall configuration, timely patch management, and network segmentation are essential practices to mitigate these risks.

The data gathered from Shodan underscores the prevalence of open ports and the potential vulnerabilities they introduce. With millions of devices exposed, it is imperative to prioritize cybersecurity and protect against potential threats.

As technology continues to evolve, so too must our approach to cybersecurity. It is crucial to stay informed and vigilant, ensuring that our devices and networks are safeguarded against potential threats.

If you have any questions, need assistance, or want to schedule a security assessment, feel free to reach out.

Stay safe and secure!

More from Fern Talk

Not sure where to start? Let’s talk it through.

A free 15 or 30 minute call to understand what’s going on and whether I’m the right fit. If I’m not, I’ll tell you, and point you to someone who is. After that, it’s $80/hour with no retainer.