Loading...
[get complete service list]
Port Information
Protocol Service Name
tcp TR069 Router Remote Admin
tcp cwmp Broadband Forum CWMP
udp cwmp Broadband Forum CWMP
Top IPs Scanning
Today Yesterday
176.120.129.29 (2836)176.120.129.29 (10516)
209.10.64.188 (2208)209.10.64.188 (5744)
193.203.34.238 (1218)216.172.78.20 (4290)
216.172.78.20 (1200)67.199.235.229 (4254)
67.199.235.229 (1173)193.203.34.238 (4209)
37.26.231.116 (975)37.26.231.116 (3540)
74.119.117.164 (940)178.250.1.92 (2864)
74.119.117.165 (940)178.250.1.93 (2864)
67.199.224.4 (812)74.119.117.164 (2848)
185.19.160.24 (808)74.119.117.165 (2848)
Port diary mentions
URL
Port 7547 SOAP Remote Code Execution Attack Against DSL Modems
TR-069 NewNTPServer Exploits: What we know so far
Does it matter if iptables isn't running on my honeypot?
User Comments
Submitted By Date
Comment
2016-12-03 01:49:23
SOAP attack against some routers. See https://isc.sans.edu/forums/diary/Port+7547+SOAP+Remote+Code+Execution+Attack+Against+DSL+Modems/21759/
Johannes 2016-11-29 00:13:52
See article about Mirai variant exploiting this vulnerability: https://isc.sans.edu/forums/diary/Port+7547+SOAP+Remote+Code+Execution+Attack+Against+DSL+Modems/21759/1#38415
2016-11-29 00:12:00
The last 2 days, I've seen a tremendous increase of scans against 7547/tcp on 4 different and independent firewalls on 4 different ISPs. Those firewalls are strict and will quickly block offending IP addresses, so I can't say much about the persistence. But there are each day 200-400 hosts trying to connect to each of these firewalls each day now.
2016-11-29 00:11:56
Just seen a huge spike in scans on 7547 against my networks, commencing at exactly 261400Z Nov 26.
2016-11-29 00:11:51
Misfortune Cookie CVE-2014-9222 "A serious vulnerability in an embedded Web server used by many router models from different manufacturers allows remote attackers to take control of affected devices over the Internet." http://www.pcworld.com/article/2861232/vulnerability-in-embedded-web-server-exposes-millions-of-routers-to-hacking.html
CVE Links
CVE # Description