<?xml version="1.0" encoding="utf-8" standalone="yes" ?>
<rss version="2.0" 
  xmlns:content="http://purl.org/rss/1.0/modules/content/" 
  xmlns:dc="http://purl.org/dc/elements/1.1/" 
  xmlns:atom="http://www.w3.org/2005/Atom" 
  xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" 
  xmlns:media="http://search.yahoo.com/mrss/">
  <channel>
    <title>TLS on Untrusted Network</title>
    <link>https://untrustednetwork.net/en/tag/tls/</link>
    <description>Recent content in TLS on Untrusted Network</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <copyright>&amp;copy; Jan Kopriva 2015 - {year}</copyright>
    <lastBuildDate>Fri, 07 Feb 2025 11:45:00 +0100</lastBuildDate>
    <sy:updatePeriod>weekly</sy:updatePeriod>
    <sy:updateFrequency>weekly</sy:updateFrequency>
    
        <atom:link href="https://untrustednetwork.net/en/tag/tls/index.xml" rel="self" type="application/rss+xml" />
    
    
    

      
      <item>
        <title>SANS ISC Diary - SSL 2.0 turns 30 this Sunday... Perhaps the time has come to let it die?</title>
        <link>https://untrustednetwork.net/en/2025/02/07/ssl2-30-years/</link>
        <pubDate>Fri, 07 Feb 2025 11:45:00 +0100</pubDate>
        
        <atom:modified>Fri, 07 Feb 2025 11:45:00 +0100</atom:modified>
        <guid>https://untrustednetwork.net/en/2025/02/07/ssl2-30-years/</guid>
        <description>A new Diary of mine was published today on the SANS Internet Storm Center website. In this one, we&amp;rsquo;ll take a look at an upcoming 30-year anniversary of the publication of SSL 2.0, and on the number of internet-exposed systems that still support this protocol&amp;hellip;</description>
        <content:encoded>&lt;p&gt;A new &lt;a href=&#34;https://isc.sans.edu/diary/31664&#34;&gt;Diary&lt;/a&gt; of mine was published today on the &lt;a href=&#34;https://isc.sans.edu/&#34;&gt;SANS Internet Storm Center&lt;/a&gt; website. In this one, we&amp;rsquo;ll take a look at an upcoming 30-year anniversary of the publication of SSL 2.0, and on the number of internet-exposed systems that still support this protocol&amp;hellip;&lt;/p&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/isc/isc-diary.jpg&#34; alt=&#34;ISC diary&#34;&gt;</content:encoded>
        <dc:creator>Jan Kopriva</dc:creator>
        <media:content url="https://untrustednetwork.netimages/isc.png" medium="image"><media:title type="html">featured image</media:title></media:content>
        
        
        
          
            
              <category>SANS</category>
            
          
            
              <category>SSL</category>
            
          
            
              <category>TLS</category>
            
          
            
              <category>HTTPS</category>
            
          
        
        
          
            
              <category>News</category>
            
          
            
              <category>2025</category>
            
          
        
        
          
            
              <category>SANS ISC Diary</category>
            
          
        
      </item>
      
      <item>
        <title>SANS ISC Diary - Changes in SSL and TLS support in 2024</title>
        <link>https://untrustednetwork.net/en/2024/12/30/ssl-tls-2024/</link>
        <pubDate>Mon, 30 Dec 2024 12:25:00 +0100</pubDate>
        
        <atom:modified>Mon, 30 Dec 2024 12:25:00 +0100</atom:modified>
        <guid>https://untrustednetwork.net/en/2024/12/30/ssl-tls-2024/</guid>
        <description>A new Diary of mine was published today on the SANS Internet Storm Center website. In this one, we&amp;rsquo;ll take a look at changes in SSL/TLS support on web servers and e-mail servers during the 12 months of 2024&amp;hellip;</description>
        <content:encoded>&lt;p&gt;A new &lt;a href=&#34;https://isc.sans.edu/diary/31550&#34;&gt;Diary&lt;/a&gt; of mine was published today on the &lt;a href=&#34;https://isc.sans.edu/&#34;&gt;SANS Internet Storm Center&lt;/a&gt; website. In this one, we&amp;rsquo;ll take a look at changes in SSL/TLS support on web servers and e-mail servers during the 12 months of 2024&amp;hellip;&lt;/p&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/isc/isc-diary.jpg&#34; alt=&#34;ISC diary&#34;&gt;</content:encoded>
        <dc:creator>Jan Kopriva</dc:creator>
        <media:content url="https://untrustednetwork.netimages/isc.png" medium="image"><media:title type="html">featured image</media:title></media:content>
        
        
        
          
            
              <category>SANS</category>
            
          
            
              <category>SSL</category>
            
          
            
              <category>TLS</category>
            
          
            
              <category>HTTPS</category>
            
          
            
              <category>SMTP</category>
            
          
            
              <category>E-mail</category>
            
          
        
        
          
            
              <category>News</category>
            
          
            
              <category>2024</category>
            
          
        
        
          
            
              <category>SANS ISC Diary</category>
            
          
        
      </item>
      
      <item>
        <title>Open ports statistics for 2021</title>
        <link>https://untrustednetwork.net/en/2022/01/05/open_ports_2022/</link>
        <pubDate>Wed, 05 Jan 2022 07:30:00 +0200</pubDate>
        
        <atom:modified>Wed, 05 Jan 2022 07:30:00 +0200</atom:modified>
        <guid>https://untrustednetwork.net/en/2022/01/05/open_ports_2022/</guid>
        <description>The year 2021 is behind us which means that the time has come for us to take a look at how the internet changed over its 365 days.
As always, the data, on which the following charts are based, have been gathered using Shodan. Therefore bear in mind that although the charts should give us a good enough view of more significant changes, they may not be completely accurate (see the first post with quarterly statistics.</description>
        <content:encoded>&lt;p&gt;The year 2021 is behind us which means that the time has come for us to take a look at how the internet changed over its 365 days.&lt;/p&gt;
&lt;p&gt;As always, the data, on which the following charts are based, have been gathered using &lt;a href=&#34;https://www.shodan.io/&#34;&gt;Shodan&lt;/a&gt;. Therefore bear in mind that although the charts should give us a good enough view of more significant changes, they may not be completely accurate (see the &lt;a href=&#34;https://untrustednetwork.net/en/2020/09/30/open-ports-statistics-for-q3-2020/&#34;&gt;first post with quarterly statistics&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;It should be mentioned that since Shodan started offering a new service called &lt;a href=&#34;https://trends.shodan.io/&#34;&gt;Trends&lt;/a&gt; few months back, which enables one to quickly view similar charts as the ones bellow for arbitrary search queries, this may be the last post in the &amp;ldquo;Open port statistics&amp;rdquo; series, since these are somewhat superfluous given the new service&amp;hellip; Althoug, since Shodan Trends displays only &amp;ldquo;high-level&amp;rdquo; charts with significantly lower level of precission (it seems that it uses either an average or a median for each month, whereas the following charts show precise values returned by Shodan on each day in the year), maybe I&amp;rsquo;ll decide to keep posting these at least on a yearly basis - we&amp;rsquo;ll see&amp;hellip;&lt;/p&gt;
&lt;p&gt;Should you be interested in the port situation in the Czech Republic, you may find corresponding charts &lt;a href=&#34;https://untrustednetwork.net/cs/2022/01/05/open_ports_2022/&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Bellow, you may find charts for the following protocols and ports:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;#ssh&#34;&gt;SSH (port 22)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#telnet&#34;&gt;Telnet (port 23)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#dns&#34;&gt;DNS (port 53)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#ntp&#34;&gt;NTP (port 123)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#snmp&#34;&gt;SNMP (port 161)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#smb&#34;&gt;SMB (port 445)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#rdp&#34;&gt;RDP (port 3389)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&#34;a-hrefwebweba&#34;&gt;&lt;a href=&#34;#web&#34;&gt;Web&lt;/a&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;#web&#34;&gt;HTTP (port 80)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#https&#34;&gt;HTTPS (port 443)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#htls13&#34;&gt;TLS 1.3 (port 443)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#htls12&#34;&gt;TLS 1.2 (port 443)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#htls11&#34;&gt;TLS 1.1 (port 443)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#htls10&#34;&gt;TLS 1.0 (port 443)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#hssl3&#34;&gt;SSL 3.0 (port 443)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#hssl2&#34;&gt;SSL 2.0 (port 443)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&#34;a-hrefemaile-maila&#34;&gt;&lt;a href=&#34;#email&#34;&gt;E-mail&lt;/a&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;#smtp&#34;&gt;SMTP (port 25)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#smtps&#34;&gt;SMTPS (port 465)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#imap&#34;&gt;IMAP (port 143)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#imaps&#34;&gt;IMAPS (port 993)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#pop3&#34;&gt;POP3 (port 110)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#pop3s&#34;&gt;POP3S (port 995)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&#34;a-hreftlsssltlsa&#34;&gt;&lt;a href=&#34;#tls&#34;&gt;SSL/TLS&lt;/a&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;#tls13&#34;&gt;TLS 1.3 (all ports)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#tls12&#34;&gt;TLS 1.2 (all ports)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#tls11&#34;&gt;TLS 1.1 (all ports)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#tls10&#34;&gt;TLS 1.0 (all ports)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#ssl3&#34;&gt;SSL 3.0 (all ports)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#ssl2&#34;&gt;SSL 2.0 (all ports)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&#34;a-hreficsindustrial-control-systems-icsa&#34;&gt;&lt;a href=&#34;#ics&#34;&gt;Industrial Control Systems (ICS)&lt;/a&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;#ics_all&#34;&gt;All ICS protocols&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#modbus&#34;&gt;Modbus (port 502)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#eibnet&#34;&gt;EIBnet/IP (port 3671)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#bacnet&#34;&gt;BACnet/IP (port 47808)&lt;br /&gt;
&lt;br&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;h4 id=&#34;ssh&#34;&gt;SSH (port 22)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/ssh.png&#34; alt=&#34;SSH&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;telnet&#34;&gt;Telnet (port 23)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/telnet.png&#34; alt=&#34;Telnet&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;dns&#34;&gt;DNS (port 53)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/dns.png&#34; alt=&#34;DNS&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;ntp&#34;&gt;NTP (port 123)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/ntp.png&#34; alt=&#34;NTP&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;snmp&#34;&gt;SNMP (port 161)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/snmp.png&#34; alt=&#34;SNMP&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;smb&#34;&gt;SMB (port 445)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/smb.png&#34; alt=&#34;SMB&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;rdp&#34;&gt;RDP (port 3389)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/rdp.png&#34; alt=&#34;RDP&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;br&gt;
&lt;h2 id=&#34;web&#34;&gt;Web&lt;/h2&gt;
&lt;h4 id=&#34;http&#34;&gt;HTTP (port 80)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/http.png&#34; alt=&#34;HTTP&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;https&#34;&gt;HTTPS (port 443)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/https.png&#34; alt=&#34;HTTPS&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;htls13&#34;&gt;TLS 1.3 (port 443)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/htls13.png&#34; alt=&#34;HTTPS/TLS 1.3&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;htls12&#34;&gt;TLS 1.2 (port 443)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/htls12.png&#34; alt=&#34;HTTPS/TLS 1.2&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;htls11&#34;&gt;TLS 1.1 (port 443)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/htls11.png&#34; alt=&#34;HTTPS/TLS 1.1&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;htls10&#34;&gt;TLS 1.0 (port 443)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/htls10.png&#34; alt=&#34;HTTPS/TLS 1.0&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;hssl3&#34;&gt;SSL 3.0 (port 443)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/hssl3.png&#34; alt=&#34;HTTPS/SSL 3.0&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;hssl2&#34;&gt;SSL 2.0 (port 443)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/hssl2.png&#34; alt=&#34;HTTPS/SSL 2.0&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;br&gt;
&lt;h2 id=&#34;email&#34;&gt;E-mail&lt;/h2&gt;
&lt;h4 id=&#34;smtp&#34;&gt;SMTP (port 25)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/smtp.png&#34; alt=&#34;SMTP&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;smtps&#34;&gt;SMTPS (port 465)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/smtps.png&#34; alt=&#34;SMTPS&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;imap&#34;&gt;IMAP (port 143)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/imap.png&#34; alt=&#34;IMAP&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;imaps&#34;&gt;IMAPS (port 993)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/imaps.png&#34; alt=&#34;IMAPS&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;pop3&#34;&gt;POP3 (port 110)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/pop3.png&#34; alt=&#34;POP3&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;pop3s&#34;&gt;POP3S (port 995)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/pop3s.png&#34; alt=&#34;POP3S&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;br&gt;
&lt;h2 id=&#34;tls&#34;&gt;SSL/TLS&lt;/h2&gt;
&lt;h4 id=&#34;tls13&#34;&gt;TLS 1.3 (all ports)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/tls13.png&#34; alt=&#34;HTTPS/TLS 1.3&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;tls12&#34;&gt;TLS 1.2 (all ports)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/tls12.png&#34; alt=&#34;HTTPS/TLS 1.2&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;tls11&#34;&gt;TLS 1.1 (all ports)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/tls11.png&#34; alt=&#34;HTTPS/TLS 1.1&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;tls10&#34;&gt;TLS 1.0 (all ports)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/tls10.png&#34; alt=&#34;HTTPS/TLS 1.0&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;ssl3&#34;&gt;SSL 3.0 (all ports)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/ssl3.png&#34; alt=&#34;HTTPS/SSL 3.0&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;ssl2&#34;&gt;SSL 2.0 (all ports)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/ssl2.png&#34; alt=&#34;HTTPS/SSL 2.0&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;br&gt;
&lt;h2 id=&#34;ics&#34;&gt;Industrial Control Systems&lt;/h2&gt;
&lt;h4 id=&#34;ics_all&#34;&gt;All ICS protocols&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/ics.png&#34; alt=&#34;All ICS protocols&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;modbus&#34;&gt;Modbus (port 502)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/modbus.png&#34; alt=&#34;Modbus&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;eibnet&#34;&gt;EIBnet/IP (port 3671)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/eibnet.png&#34; alt=&#34;EIBnet&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;bacnet&#34;&gt;BACnet/IP (port 47808)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q4/bacnet.png&#34; alt=&#34;BACnet&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
</content:encoded>
        <dc:creator>Jan Kopriva</dc:creator>
        <media:content url="https://untrustednetwork.netimages/ports/2021/q4/ssl2.png" medium="image"><media:title type="html">featured image</media:title></media:content>
        
        
        
          
            
              <category>SSL</category>
            
          
            
              <category>TLS</category>
            
          
            
              <category>Telnet</category>
            
          
            
              <category>DNS</category>
            
          
            
              <category>NTP</category>
            
          
            
              <category>SNMP</category>
            
          
            
              <category>SMB</category>
            
          
            
              <category>RDP</category>
            
          
            
              <category>HTTP</category>
            
          
            
              <category>HTTPS</category>
            
          
            
              <category>SMTP</category>
            
          
            
              <category>SMTPS</category>
            
          
            
              <category>IMAP</category>
            
          
            
              <category>IMAPS</category>
            
          
            
              <category>POP3</category>
            
          
            
              <category>POP3S</category>
            
          
            
              <category>ICS</category>
            
          
            
              <category>Modbus</category>
            
          
            
              <category>EIBnet</category>
            
          
            
              <category>BACnet</category>
            
          
            
              <category>Shodan</category>
            
          
        
        
          
            
              <category>News</category>
            
          
            
              <category>2022</category>
            
          
        
        
          
            
              <category>Open port statistics</category>
            
          
        
      </item>
      
      <item>
        <title>Open ports statistics for Q3 2021</title>
        <link>https://untrustednetwork.net/en/2021/10/01/open_ports_q3_2021/</link>
        <pubDate>Fri, 01 Oct 2021 15:00:00 +0200</pubDate>
        
        <atom:modified>Fri, 01 Oct 2021 15:00:00 +0200</atom:modified>
        <guid>https://untrustednetwork.net/en/2021/10/01/open_ports_q3_2021/</guid>
        <description>Only the last three months remain until the end of 2021, which means it&amp;rsquo;s time for a look at how the internet as a whole changed in the third quarter of the year.
As always, the data, on which the following charts are based, have been gathered using Shodan. Therefore bear in mind that although the charts should give us a good enough view of more significant changes, they may not be completely accurate (see the first post with quarterly statistics.</description>
        <content:encoded>&lt;p&gt;Only the last three months remain until the end of 2021, which means it&amp;rsquo;s time for a look at how the internet as a whole changed in the third quarter of the year.&lt;/p&gt;
&lt;p&gt;As always, the data, on which the following charts are based, have been gathered using &lt;a href=&#34;https://www.shodan.io/&#34;&gt;Shodan&lt;/a&gt;. Therefore bear in mind that although the charts should give us a good enough view of more significant changes, they may not be completely accurate (see the &lt;a href=&#34;https://untrustednetwork.net/en/2020/09/30/open-ports-statistics-for-q3-2020/&#34;&gt;first post with quarterly statistics&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Should you be interested in the port situation in the Czech Republic, you may find corresponding charts &lt;a href=&#34;https://untrustednetwork.net/cs/2021/10/01/open_ports_q3_2021/&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Bellow, you may find charts for the following protocols and ports:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;#ssh&#34;&gt;SSH (port 22)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#telnet&#34;&gt;Telnet (port 23)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#dns&#34;&gt;DNS (port 53)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#ntp&#34;&gt;NTP (port 123)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#snmp&#34;&gt;SNMP (port 161)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#smb&#34;&gt;SMB (port 445)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#rdp&#34;&gt;RDP (port 3389)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&#34;a-hrefwebweba&#34;&gt;&lt;a href=&#34;#web&#34;&gt;Web&lt;/a&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;#web&#34;&gt;HTTP (port 80)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#https&#34;&gt;HTTPS (port 443)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#htls13&#34;&gt;TLS 1.3 (port 443)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#htls12&#34;&gt;TLS 1.2 (port 443)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#htls11&#34;&gt;TLS 1.1 (port 443)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#htls10&#34;&gt;TLS 1.0 (port 443)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#hssl3&#34;&gt;SSL 3.0 (port 443)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#hssl2&#34;&gt;SSL 2.0 (port 443)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&#34;a-hrefemaile-maila&#34;&gt;&lt;a href=&#34;#email&#34;&gt;E-mail&lt;/a&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;#smtp&#34;&gt;SMTP (port 25)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#smtps&#34;&gt;SMTPS (port 465)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#imap&#34;&gt;IMAP (port 143)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#imaps&#34;&gt;IMAPS (port 993)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#pop3&#34;&gt;POP3 (port 110)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#pop3s&#34;&gt;POP3S (port 995)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&#34;a-hreftlsssltlsa&#34;&gt;&lt;a href=&#34;#tls&#34;&gt;SSL/TLS&lt;/a&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;#tls13&#34;&gt;TLS 1.3 (all ports)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#tls12&#34;&gt;TLS 1.2 (all ports)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#tls11&#34;&gt;TLS 1.1 (all ports)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#tls10&#34;&gt;TLS 1.0 (all ports)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#ssl3&#34;&gt;SSL 3.0 (all ports)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#ssl2&#34;&gt;SSL 2.0 (all ports)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&#34;a-hreficsindustrial-control-systems-icsa&#34;&gt;&lt;a href=&#34;#ics&#34;&gt;Industrial Control Systems (ICS)&lt;/a&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;#ics_all&#34;&gt;All ICS protocols&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#modbus&#34;&gt;Modbus (port 502)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#eibnet&#34;&gt;EIBnet/IP (port 3671)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#bacnet&#34;&gt;BACnet/IP (port 47808)&lt;br /&gt;
&lt;br&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;h4 id=&#34;ssh&#34;&gt;SSH (port 22)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/ssh.png&#34; alt=&#34;SSH&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;telnet&#34;&gt;Telnet (port 23)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/telnet.png&#34; alt=&#34;Telnet&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;dns&#34;&gt;DNS (port 53)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/dns.png&#34; alt=&#34;DNS&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;ntp&#34;&gt;NTP (port 123)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/ntp.png&#34; alt=&#34;NTP&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;snmp&#34;&gt;SNMP (port 161)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/snmp.png&#34; alt=&#34;SNMP&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;smb&#34;&gt;SMB (port 445)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/smb.png&#34; alt=&#34;SMB&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;rdp&#34;&gt;RDP (port 3389)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/rdp.png&#34; alt=&#34;RDP&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;br&gt;
&lt;h2 id=&#34;web&#34;&gt;Web&lt;/h2&gt;
&lt;h4 id=&#34;http&#34;&gt;HTTP (port 80)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/http.png&#34; alt=&#34;HTTP&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;https&#34;&gt;HTTPS (port 443)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/https.png&#34; alt=&#34;HTTPS&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;htls13&#34;&gt;TLS 1.3 (port 443)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/htls13.png&#34; alt=&#34;HTTPS/TLS 1.3&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;htls12&#34;&gt;TLS 1.2 (port 443)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/htls12.png&#34; alt=&#34;HTTPS/TLS 1.2&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;htls11&#34;&gt;TLS 1.1 (port 443)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/htls11.png&#34; alt=&#34;HTTPS/TLS 1.1&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;htls10&#34;&gt;TLS 1.0 (port 443)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/htls10.png&#34; alt=&#34;HTTPS/TLS 1.0&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;hssl3&#34;&gt;SSL 3.0 (port 443)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/hssl3.png&#34; alt=&#34;HTTPS/SSL 3.0&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;hssl2&#34;&gt;SSL 2.0 (port 443)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/hssl2.png&#34; alt=&#34;HTTPS/SSL 2.0&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;br&gt;
&lt;h2 id=&#34;email&#34;&gt;E-mail&lt;/h2&gt;
&lt;h4 id=&#34;smtp&#34;&gt;SMTP (port 25)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/smtp.png&#34; alt=&#34;SMTP&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;smtps&#34;&gt;SMTPS (port 465)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/smtps.png&#34; alt=&#34;SMTPS&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;imap&#34;&gt;IMAP (port 143)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/imap.png&#34; alt=&#34;IMAP&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;imaps&#34;&gt;IMAPS (port 993)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/imaps.png&#34; alt=&#34;IMAPS&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;pop3&#34;&gt;POP3 (port 110)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/pop3.png&#34; alt=&#34;POP3&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;pop3s&#34;&gt;POP3S (port 995)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/pop3s.png&#34; alt=&#34;POP3S&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;br&gt;
&lt;h2 id=&#34;tls&#34;&gt;SSL/TLS&lt;/h2&gt;
&lt;h4 id=&#34;tls13&#34;&gt;TLS 1.3 (all ports)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/tls13.png&#34; alt=&#34;HTTPS/TLS 1.3&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;tls12&#34;&gt;TLS 1.2 (all ports)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/tls12.png&#34; alt=&#34;HTTPS/TLS 1.2&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;tls11&#34;&gt;TLS 1.1 (all ports)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/tls11.png&#34; alt=&#34;HTTPS/TLS 1.1&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;tls10&#34;&gt;TLS 1.0 (all ports)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/tls10.png&#34; alt=&#34;HTTPS/TLS 1.0&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;ssl3&#34;&gt;SSL 3.0 (all ports)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/ssl3.png&#34; alt=&#34;HTTPS/SSL 3.0&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;ssl2&#34;&gt;SSL 2.0 (all ports)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/ssl2.png&#34; alt=&#34;HTTPS/SSL 2.0&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;br&gt;
&lt;h2 id=&#34;ics&#34;&gt;Industrial Control Systems&lt;/h2&gt;
&lt;h4 id=&#34;ics_all&#34;&gt;All ICS protocols&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/ics.png&#34; alt=&#34;All ICS protocols&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;modbus&#34;&gt;Modbus (port 502)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/modbus.png&#34; alt=&#34;Modbus&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;eibnet&#34;&gt;EIBnet/IP (port 3671)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/eibnet.png&#34; alt=&#34;EIBnet&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;bacnet&#34;&gt;BACnet/IP (port 47808)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q3/bacnet.png&#34; alt=&#34;BACnet&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
</content:encoded>
        <dc:creator>Jan Kopriva</dc:creator>
        <media:content url="https://untrustednetwork.netimages/ports/2021/q3/htls13.png" medium="image"><media:title type="html">featured image</media:title></media:content>
        
        
        
          
            
              <category>SSL</category>
            
          
            
              <category>TLS</category>
            
          
            
              <category>Telnet</category>
            
          
            
              <category>DNS</category>
            
          
            
              <category>NTP</category>
            
          
            
              <category>SNMP</category>
            
          
            
              <category>SMB</category>
            
          
            
              <category>RDP</category>
            
          
            
              <category>HTTP</category>
            
          
            
              <category>HTTPS</category>
            
          
            
              <category>SMTP</category>
            
          
            
              <category>SMTPS</category>
            
          
            
              <category>IMAP</category>
            
          
            
              <category>IMAPS</category>
            
          
            
              <category>POP3</category>
            
          
            
              <category>POP3S</category>
            
          
            
              <category>ICS</category>
            
          
            
              <category>Modbus</category>
            
          
            
              <category>EIBnet</category>
            
          
            
              <category>BACnet</category>
            
          
            
              <category>Shodan</category>
            
          
        
        
          
            
              <category>News</category>
            
          
            
              <category>2021</category>
            
          
        
        
          
            
              <category>Open port statistics</category>
            
          
        
      </item>
      
      <item>
        <title>SANS ISC Diary - TLS 1.3 and SSL - the current state of affairs</title>
        <link>https://untrustednetwork.net/en/2021/09/28/ssl_tls/</link>
        <pubDate>Tue, 28 Sep 2021 11:20:00 +0200</pubDate>
        
        <atom:modified>Tue, 28 Sep 2021 11:20:00 +0200</atom:modified>
        <guid>https://untrustednetwork.net/en/2021/09/28/ssl_tls/</guid>
        <description>A new Diary of mine was published today on the SANS Internet Storm Center website. In this one, we&amp;rsquo;ll take a look at the current state of adoption of TLS 1.3 and disposal of SSL 2.0 and 3.0&amp;hellip;</description>
        <content:encoded>&lt;p&gt;A new &lt;a href=&#34;https://isc.sans.edu/diary/27882&#34;&gt;Diary&lt;/a&gt; of mine was published today on the &lt;a href=&#34;https://isc.sans.edu/&#34;&gt;SANS Internet Storm Center&lt;/a&gt; website. In this one, we&amp;rsquo;ll take a look at the current state of adoption of TLS 1.3 and disposal of SSL 2.0 and 3.0&amp;hellip;&lt;/p&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/isc/isc-diary.jpg&#34; alt=&#34;ISC diary&#34;&gt;</content:encoded>
        <dc:creator>Jan Kopriva</dc:creator>
        <media:content url="https://untrustednetwork.netimages/isc.png" medium="image"><media:title type="html">featured image</media:title></media:content>
        
        
        
          
            
              <category>SANS</category>
            
          
            
              <category>Shodan</category>
            
          
            
              <category>TLS</category>
            
          
            
              <category>SSL</category>
            
          
        
        
          
            
              <category>News</category>
            
          
            
              <category>2021</category>
            
          
        
        
          
            
              <category>SANS ISC Diary</category>
            
          
        
      </item>
      
      <item>
        <title>Open ports statistics for Q2 2021</title>
        <link>https://untrustednetwork.net/en/2021/06/30/open_ports_q2_2021/</link>
        <pubDate>Wed, 30 Jun 2021 21:15:00 +0200</pubDate>
        
        <atom:modified>Wed, 30 Jun 2021 21:15:00 +0200</atom:modified>
        <guid>https://untrustednetwork.net/en/2021/06/30/open_ports_q2_2021/</guid>
        <description>The first half of 2020 is behind us, which means it&amp;rsquo;s time for a look at how the internet as a whole changed during the past 3 months.
As always, the data, on which the following charts are based, have been gathered using Shodan. Therefore bear in mind that although the charts should give us a good enough view of more significant changes, they may not be completely accurate (see the first post with quarterly statistics.</description>
        <content:encoded>&lt;p&gt;The first half of 2020 is behind us, which means it&amp;rsquo;s time for a look at how the internet as a whole changed during the past 3 months.&lt;/p&gt;
&lt;p&gt;As always, the data, on which the following charts are based, have been gathered using &lt;a href=&#34;https://www.shodan.io/&#34;&gt;Shodan&lt;/a&gt;. Therefore bear in mind that although the charts should give us a good enough view of more significant changes, they may not be completely accurate (see the &lt;a href=&#34;https://untrustednetwork.net/en/2020/09/30/open-ports-statistics-for-q3-2020/&#34;&gt;first post with quarterly statistics&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Should you be interested in the port situation in the Czech Republic, you may find corresponding charts &lt;a href=&#34;https://untrustednetwork.net/cs/2021/06/30/open_ports_q2_2021/&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Bellow, you may find charts for the following protocols and ports:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;#ssh&#34;&gt;SSH (port 22)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#telnet&#34;&gt;Telnet (port 23)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#dns&#34;&gt;DNS (port 53)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#ntp&#34;&gt;NTP (port 123)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#snmp&#34;&gt;SNMP (port 161)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#smb&#34;&gt;SMB (port 445)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#rdp&#34;&gt;RDP (port 3389)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&#34;a-hrefwebweba&#34;&gt;&lt;a href=&#34;#web&#34;&gt;Web&lt;/a&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;#web&#34;&gt;HTTP (port 80)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#https&#34;&gt;HTTPS (port 443)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#htls13&#34;&gt;TLS 1.3 (port 443)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#htls12&#34;&gt;TLS 1.2 (port 443)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#htls11&#34;&gt;TLS 1.1 (port 443)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#htls10&#34;&gt;TLS 1.0 (port 443)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#hssl3&#34;&gt;SSL 3.0 (port 443)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#hssl2&#34;&gt;SSL 2.0 (port 443)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&#34;a-hrefemaile-maila&#34;&gt;&lt;a href=&#34;#email&#34;&gt;E-mail&lt;/a&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;#smtp&#34;&gt;SMTP (port 25)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#smtps&#34;&gt;SMTPS (port 465)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#imap&#34;&gt;IMAP (port 143)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#imaps&#34;&gt;IMAPS (port 993)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#pop3&#34;&gt;POP3 (port 110)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#pop3s&#34;&gt;POP3S (port 995)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&#34;a-hreftlsssltlsa&#34;&gt;&lt;a href=&#34;#tls&#34;&gt;SSL/TLS&lt;/a&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;#tls13&#34;&gt;TLS 1.3 (all ports)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#tls12&#34;&gt;TLS 1.2 (all ports)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#tls11&#34;&gt;TLS 1.1 (all ports)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#tls10&#34;&gt;TLS 1.0 (all ports)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#ssl3&#34;&gt;SSL 3.0 (all ports)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#ssl2&#34;&gt;SSL 2.0 (all ports)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&#34;a-hreficsindustrial-control-systems-icsa&#34;&gt;&lt;a href=&#34;#ics&#34;&gt;Industrial Control Systems (ICS)&lt;/a&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;#ics_all&#34;&gt;All ICS protocols&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#modbus&#34;&gt;Modbus (port 502)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#eibnet&#34;&gt;EIBnet/IP (port 3671)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#bacnet&#34;&gt;BACnet/IP (port 47808)&lt;br /&gt;
&lt;br&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;h4 id=&#34;ssh&#34;&gt;SSH (port 22)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/ssh.png&#34; alt=&#34;SSH&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;telnet&#34;&gt;Telnet (port 23)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/telnet.png&#34; alt=&#34;Telnet&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;dns&#34;&gt;DNS (port 53)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/dns.png&#34; alt=&#34;DNS&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;ntp&#34;&gt;NTP (port 123)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/ntp.png&#34; alt=&#34;NTP&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;snmp&#34;&gt;SNMP (port 161)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/snmp.png&#34; alt=&#34;SNMP&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;smb&#34;&gt;SMB (port 445)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/smb.png&#34; alt=&#34;SMB&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;rdp&#34;&gt;RDP (port 3389)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/rdp.png&#34; alt=&#34;RDP&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;br&gt;
&lt;h2 id=&#34;web&#34;&gt;Web&lt;/h2&gt;
&lt;h4 id=&#34;http&#34;&gt;HTTP (port 80)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/http.png&#34; alt=&#34;HTTP&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;https&#34;&gt;HTTPS (port 443)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/https.png&#34; alt=&#34;HTTPS&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;htls13&#34;&gt;TLS 1.3 (port 443)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/htls13.png&#34; alt=&#34;HTTPS/TLS 1.3&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;htls12&#34;&gt;TLS 1.2 (port 443)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/htls12.png&#34; alt=&#34;HTTPS/TLS 1.2&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;htls11&#34;&gt;TLS 1.1 (port 443)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/htls11.png&#34; alt=&#34;HTTPS/TLS 1.1&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;htls10&#34;&gt;TLS 1.0 (port 443)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/htls10.png&#34; alt=&#34;HTTPS/TLS 1.0&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;hssl3&#34;&gt;SSL 3.0 (port 443)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/hssl3.png&#34; alt=&#34;HTTPS/SSL 3.0&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;hssl2&#34;&gt;SSL 2.0 (port 443)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/hssl2.png&#34; alt=&#34;HTTPS/SSL 2.0&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;br&gt;
&lt;h2 id=&#34;email&#34;&gt;E-mail&lt;/h2&gt;
&lt;h4 id=&#34;smtp&#34;&gt;SMTP (port 25)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/smtp.png&#34; alt=&#34;SMTP&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;smtps&#34;&gt;SMTPS (port 465)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/smtps.png&#34; alt=&#34;SMTPS&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;imap&#34;&gt;IMAP (port 143)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/imap.png&#34; alt=&#34;IMAP&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;imaps&#34;&gt;IMAPS (port 993)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/imaps.png&#34; alt=&#34;IMAPS&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;pop3&#34;&gt;POP3 (port 110)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/pop3.png&#34; alt=&#34;POP3&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;pop3s&#34;&gt;POP3S (port 995)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/pop3s.png&#34; alt=&#34;POP3S&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;br&gt;
&lt;h2 id=&#34;tls&#34;&gt;SSL/TLS&lt;/h2&gt;
&lt;h4 id=&#34;tls13&#34;&gt;TLS 1.3 (all ports)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/tls13.png&#34; alt=&#34;HTTPS/TLS 1.3&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;tls12&#34;&gt;TLS 1.2 (all ports)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/tls12.png&#34; alt=&#34;HTTPS/TLS 1.2&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;tls11&#34;&gt;TLS 1.1 (all ports)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/tls11.png&#34; alt=&#34;HTTPS/TLS 1.1&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;tls10&#34;&gt;TLS 1.0 (all ports)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/tls10.png&#34; alt=&#34;HTTPS/TLS 1.0&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;ssl3&#34;&gt;SSL 3.0 (all ports)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/ssl3.png&#34; alt=&#34;HTTPS/SSL 3.0&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;ssl2&#34;&gt;SSL 2.0 (all ports)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/ssl2.png&#34; alt=&#34;HTTPS/SSL 2.0&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;br&gt;
&lt;h2 id=&#34;ics&#34;&gt;Industrial Control Systems&lt;/h2&gt;
&lt;h4 id=&#34;ics_all&#34;&gt;All ICS protocols&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/ics.png&#34; alt=&#34;All ICS protocols&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;modbus&#34;&gt;Modbus (port 502)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/modbus.png&#34; alt=&#34;Modbus&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;eibnet&#34;&gt;EIBnet/IP (port 3671)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/eibnet.png&#34; alt=&#34;EIBnet&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;bacnet&#34;&gt;BACnet/IP (port 47808)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q2/bacnet.png&#34; alt=&#34;BACnet&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
</content:encoded>
        <dc:creator>Jan Kopriva</dc:creator>
        <media:content url="https://untrustednetwork.netimages/ports/2021/q2/hssl2.png" medium="image"><media:title type="html">featured image</media:title></media:content>
        
        
        
          
            
              <category>SSL</category>
            
          
            
              <category>TLS</category>
            
          
            
              <category>Telnet</category>
            
          
            
              <category>DNS</category>
            
          
            
              <category>NTP</category>
            
          
            
              <category>SNMP</category>
            
          
            
              <category>SMB</category>
            
          
            
              <category>RDP</category>
            
          
            
              <category>HTTP</category>
            
          
            
              <category>HTTPS</category>
            
          
            
              <category>SMTP</category>
            
          
            
              <category>SMTPS</category>
            
          
            
              <category>IMAP</category>
            
          
            
              <category>IMAPS</category>
            
          
            
              <category>POP3</category>
            
          
            
              <category>POP3S</category>
            
          
            
              <category>ICS</category>
            
          
            
              <category>Modbus</category>
            
          
            
              <category>EIBnet</category>
            
          
            
              <category>BACnet</category>
            
          
            
              <category>Shodan</category>
            
          
        
        
          
            
              <category>News</category>
            
          
            
              <category>2021</category>
            
          
        
        
          
            
              <category>Open port statistics</category>
            
          
        
      </item>
      
      <item>
        <title>Open ports statistics for Q1 2021</title>
        <link>https://untrustednetwork.net/en/2021/04/05/open_ports_q1_2021/</link>
        <pubDate>Mon, 05 Apr 2021 11:30:00 +0200</pubDate>
        
        <atom:modified>Mon, 05 Apr 2021 11:30:00 +0200</atom:modified>
        <guid>https://untrustednetwork.net/en/2021/04/05/open_ports_q1_2021/</guid>
        <description>The first quarter of 2020 is behind us, which means it&amp;rsquo;s time for another look at some of the interesting ports accessible on public IPs. This time however, we will take a look at how the internet as a whole changed during the past 3 months in terms of accessible ports, but also at specific changes related to support of different versions of SSL and TLS.
As always, the data, on which the following charts are based, have been gathered using Shodan.</description>
        <content:encoded>&lt;p&gt;The first quarter of 2020 is behind us, which means it&amp;rsquo;s time for another look at some of the interesting ports accessible on public IPs. This time however, we will take a look at how the internet as a whole changed during the past 3 months in terms of accessible ports, but also at specific changes related to support of different versions of SSL and TLS.&lt;/p&gt;
&lt;p&gt;As always, the data, on which the following charts are based, have been gathered using &lt;a href=&#34;https://www.shodan.io/&#34;&gt;Shodan&lt;/a&gt;. Therefore bear in mind that although the charts should give us a good enough view of more significant changes, they may not be completely accurate (see the &lt;a href=&#34;https://untrustednetwork.net/en/2020/09/30/open-ports-statistics-for-q3-2020/&#34;&gt;first post with quarterly statistics&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Should you be interested in the port situation in the Czech Republic, you may find corresponding charts &lt;a href=&#34;https://untrustednetwork.net/cs/2021/04/05/open_ports_q1_2021/&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Bellow, you may find charts for the following protocols and ports:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;#ssh&#34;&gt;SSH (port 22)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#telnet&#34;&gt;Telnet (port 23)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#dns&#34;&gt;DNS (port 53)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#ntp&#34;&gt;NTP (port 123)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#snmp&#34;&gt;SNMP (port 161)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#smb&#34;&gt;SMB (port 445)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#rdp&#34;&gt;RDP (port 3389)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&#34;a-hrefwebweba&#34;&gt;&lt;a href=&#34;#web&#34;&gt;Web&lt;/a&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;#web&#34;&gt;HTTP (port 80)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#https&#34;&gt;HTTPS (port 443)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#htls13&#34;&gt;TLS 1.3 (port 443)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#htls12&#34;&gt;TLS 1.2 (port 443)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#htls11&#34;&gt;TLS 1.1 (port 443)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#htls10&#34;&gt;TLS 1.0 (port 443)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#hssl3&#34;&gt;SSL 3.0 (port 443)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#hssl2&#34;&gt;SSL 2.0 (port 443)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&#34;a-hrefemaile-maila&#34;&gt;&lt;a href=&#34;#email&#34;&gt;E-mail&lt;/a&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;#smtp&#34;&gt;SMTP (port 25)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#smtps&#34;&gt;SMTPS (port 465)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#imap&#34;&gt;IMAP (port 143)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#imaps&#34;&gt;IMAPS (port 993)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#pop3&#34;&gt;POP3 (port 110)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#pop3s&#34;&gt;POP3S (port 995)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&#34;a-hreftlsssltlsa&#34;&gt;&lt;a href=&#34;#tls&#34;&gt;SSL/TLS&lt;/a&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;#tls13&#34;&gt;TLS 1.3 (all ports)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#tls12&#34;&gt;TLS 1.2 (all ports)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#tls11&#34;&gt;TLS 1.1 (all ports)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#tls10&#34;&gt;TLS 1.0 (all ports)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#ssl3&#34;&gt;SSL 3.0 (all ports)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#ssl2&#34;&gt;SSL 2.0 (all ports)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&#34;a-hreficsindustrial-control-systems-icsa&#34;&gt;&lt;a href=&#34;#ics&#34;&gt;Industrial Control Systems (ICS)&lt;/a&gt;&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;#ics_all&#34;&gt;All ICS protocols&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#modbus&#34;&gt;Modbus (port 502)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#eibnet&#34;&gt;EIBnet/IP (port 3671)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#bacnet&#34;&gt;BACnet/IP (port 47808)&lt;br /&gt;
&lt;br&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;h4 id=&#34;ssh&#34;&gt;SSH (port 22)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/ssh.png&#34; alt=&#34;SSH&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;telnet&#34;&gt;Telnet (port 23)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/telnet.png&#34; alt=&#34;Telnet&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;dns&#34;&gt;DNS (port 53)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/dns.png&#34; alt=&#34;DNS&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;ntp&#34;&gt;NTP (port 123)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/ntp.png&#34; alt=&#34;NTP&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;snmp&#34;&gt;SNMP (port 161)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/snmp.png&#34; alt=&#34;SNMP&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;smb&#34;&gt;SMB (port 445)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/smb.png&#34; alt=&#34;SMB&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;rdp&#34;&gt;RDP (port 3389)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/rdp.png&#34; alt=&#34;RDP&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;br&gt;
&lt;h2 id=&#34;web&#34;&gt;Web&lt;/h2&gt;
&lt;h4 id=&#34;http&#34;&gt;HTTP (port 80)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/http.png&#34; alt=&#34;HTTP&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;https&#34;&gt;HTTPS (port 443)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/https.png&#34; alt=&#34;HTTPS&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;htls13&#34;&gt;TLS 1.3 (port 443)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/htls13.png&#34; alt=&#34;HTTPS/TLS 1.3&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;htls12&#34;&gt;TLS 1.2 (port 443)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/htls12.png&#34; alt=&#34;HTTPS/TLS 1.2&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;htls11&#34;&gt;TLS 1.1 (port 443)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/htls11.png&#34; alt=&#34;HTTPS/TLS 1.1&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;htls10&#34;&gt;TLS 1.0 (port 443)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/htls10.png&#34; alt=&#34;HTTPS/TLS 1.0&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;hssl3&#34;&gt;SSL 3.0 (port 443)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/hssl3.png&#34; alt=&#34;HTTPS/SSL 3.0&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;hssl2&#34;&gt;SSL 2.0 (port 443)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/hssl2.png&#34; alt=&#34;HTTPS/SSL 2.0&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;br&gt;
&lt;h2 id=&#34;email&#34;&gt;E-mail&lt;/h2&gt;
&lt;h4 id=&#34;smtp&#34;&gt;SMTP (port 25)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/smtp.png&#34; alt=&#34;SMTP&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;smtps&#34;&gt;SMTPS (port 465)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/smtps.png&#34; alt=&#34;SMTPS&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;imap&#34;&gt;IMAP (port 143)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/imap.png&#34; alt=&#34;IMAP&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;imaps&#34;&gt;IMAPS (port 993)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/imaps.png&#34; alt=&#34;IMAPS&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;pop3&#34;&gt;POP3 (port 110)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/pop3.png&#34; alt=&#34;POP3&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;pop3s&#34;&gt;POP3S (port 995)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/pop3s.png&#34; alt=&#34;POP3S&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;br&gt;
&lt;h2 id=&#34;tls&#34;&gt;SSL/TLS&lt;/h2&gt;
&lt;h4 id=&#34;tls13&#34;&gt;TLS 1.3 (all ports)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/tls13.png&#34; alt=&#34;HTTPS/TLS 1.3&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;tls12&#34;&gt;TLS 1.2 (all ports)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/tls12.png&#34; alt=&#34;HTTPS/TLS 1.2&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;tls11&#34;&gt;TLS 1.1 (all ports)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/tls11.png&#34; alt=&#34;HTTPS/TLS 1.1&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;tls10&#34;&gt;TLS 1.0 (all ports)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/tls10.png&#34; alt=&#34;HTTPS/TLS 1.0&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;ssl3&#34;&gt;SSL 3.0 (all ports)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/ssl3.png&#34; alt=&#34;HTTPS/SSL 3.0&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;ssl2&#34;&gt;SSL 2.0 (all ports)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/ssl2.png&#34; alt=&#34;HTTPS/SSL 2.0&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;br&gt;
&lt;h2 id=&#34;ics&#34;&gt;Industrial Control Systems&lt;/h2&gt;
&lt;h4 id=&#34;ics_all&#34;&gt;All ICS protocols&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/ics.png&#34; alt=&#34;All ICS protocols&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;modbus&#34;&gt;Modbus (port 502)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/modbus.png&#34; alt=&#34;Modbus&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;eibnet&#34;&gt;EIBnet/IP (port 3671)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/eibnet.png&#34; alt=&#34;EIBnet&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
&lt;h4 id=&#34;bacnet&#34;&gt;BACnet/IP (port 47808)&lt;/h4&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/ports/2021/q1/bacnet.png&#34; alt=&#34;BACnet&#34; style=&#34;max-width:800px;width:100%&#34;&gt;
</content:encoded>
        <dc:creator>Jan Kopriva</dc:creator>
        <media:content url="https://untrustednetwork.netimages/ports/2021/q1/htls13.png" medium="image"><media:title type="html">featured image</media:title></media:content>
        
        
        
          
            
              <category>SSL</category>
            
          
            
              <category>TLS</category>
            
          
            
              <category>Telnet</category>
            
          
            
              <category>DNS</category>
            
          
            
              <category>NTP</category>
            
          
            
              <category>SNMP</category>
            
          
            
              <category>SMB</category>
            
          
            
              <category>RDP</category>
            
          
            
              <category>HTTP</category>
            
          
            
              <category>HTTPS</category>
            
          
            
              <category>SMTP</category>
            
          
            
              <category>SMTPS</category>
            
          
            
              <category>IMAP</category>
            
          
            
              <category>IMAPS</category>
            
          
            
              <category>POP3</category>
            
          
            
              <category>POP3S</category>
            
          
            
              <category>ICS</category>
            
          
            
              <category>Modbus</category>
            
          
            
              <category>EIBnet</category>
            
          
            
              <category>BACnet</category>
            
          
            
              <category>Shodan</category>
            
          
        
        
          
            
              <category>News</category>
            
          
            
              <category>2021</category>
            
          
        
        
          
            
              <category>Open port statistics</category>
            
          
        
      </item>
      
      <item>
        <title>SANS ISC Diary - Old TLS versions - gone, but not forgotten... well, not really &#39;gone&#39; either</title>
        <link>https://untrustednetwork.net/en/2021/03/30/tls_deprecation/</link>
        <pubDate>Tue, 30 Mar 2021 10:20:00 +0200</pubDate>
        
        <atom:modified>Tue, 30 Mar 2021 10:20:00 +0200</atom:modified>
        <guid>https://untrustednetwork.net/en/2021/03/30/tls_deprecation/</guid>
        <description>A Diary of mine was published today on the SANS Internet Storm Center website. In this one, we&amp;rsquo;ll take a look at changes in the number of web servers, which support TLS 1.0 and TLS 1.1&amp;hellip;</description>
        <content:encoded>&lt;p&gt;A &lt;a href=&#34;https://isc.sans.edu/diary/27260&#34;&gt;Diary&lt;/a&gt; of mine was published today on the &lt;a href=&#34;https://isc.sans.edu/&#34;&gt;SANS Internet Storm Center&lt;/a&gt; website. In this one, we&amp;rsquo;ll take a look at changes in the number of web servers, which support TLS 1.0 and TLS 1.1&amp;hellip;&lt;/p&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/isc/isc-diary.jpg&#34; alt=&#34;ISC diary&#34;&gt;</content:encoded>
        <dc:creator>Jan Kopriva</dc:creator>
        <media:content url="https://untrustednetwork.netimages/isc.png" medium="image"><media:title type="html">featured image</media:title></media:content>
        
        
        
          
            
              <category>SANS</category>
            
          
            
              <category>TLS</category>
            
          
            
              <category>SSL</category>
            
          
            
              <category>Shodan</category>
            
          
            
          
        
        
          
            
              <category>News</category>
            
          
            
              <category>2021</category>
            
          
        
        
          
            
              <category>SANS ISC Diary</category>
            
          
        
      </item>
      
      <item>
        <title>SANS ISC Diary - TLS 1.3 is now supported by about 1 in every 5 HTTPS servers</title>
        <link>https://untrustednetwork.net/en/2020/12/30/sans-isc-diary-tls-1.3-is-now-supported-by-about-1-in-every-5-https-servers/</link>
        <pubDate>Wed, 30 Dec 2020 12:55:00 +0100</pubDate>
        
        <atom:modified>Wed, 30 Dec 2020 12:55:00 +0100</atom:modified>
        <guid>https://untrustednetwork.net/en/2020/12/30/sans-isc-diary-tls-1.3-is-now-supported-by-about-1-in-every-5-https-servers/</guid>
        <description>A Diary of mine was published today on the SANS Internet Storm Center. In this one, we take a look at the increse in support of TLS 1.3 by HTTPS servers and the decrease in support of SSL 2.0.</description>
        <content:encoded>&lt;p&gt;A &lt;a href=&#34;https://isc.sans.edu/forums/diary/TLS+13+is+now+supported+by+about+1+in+every+5+HTTPS+servers/26936/&#34;&gt;Diary&lt;/a&gt; of mine was published today on the &lt;a href=&#34;https://isc.sans.edu/&#34;&gt;SANS Internet Storm Center&lt;/a&gt;. In this one, we take a look at the increse in support of TLS 1.3 by HTTPS servers and the decrease in support of SSL 2.0.&lt;/p&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/isc/isc-diary.jpg&#34; alt=&#34;ISC diary&#34;&gt;</content:encoded>
        <dc:creator>Jan Kopriva</dc:creator>
        <media:content url="https://untrustednetwork.netimages/isc.png" medium="image"><media:title type="html">featured image</media:title></media:content>
        
        
        
          
            
              <category>SANS</category>
            
          
            
              <category>TLS</category>
            
          
            
              <category>SSL</category>
            
          
            
              <category>HTTPS</category>
            
          
            
              <category>Shodan</category>
            
          
        
        
          
            
              <category>News</category>
            
          
            
              <category>2020</category>
            
          
        
        
          
            
              <category>SANS ISC Diary</category>
            
          
        
      </item>
      
      <item>
        <title>Open ports in the Time of Corona</title>
        <link>https://untrustednetwork.net/en/2020/04/02/open-ports-in-the-time-of-corona/</link>
        <pubDate>Thu, 02 Apr 2020 08:59:20 +0200</pubDate>
        
        <atom:modified>Thu, 02 Apr 2020 08:59:20 +0200</atom:modified>
        <guid>https://untrustednetwork.net/en/2020/04/02/open-ports-in-the-time-of-corona/</guid>
        <description>One of the side effects of social distancing and self-quarantining due to COVID-19 was a large increase in the use of VPNs (and, in some cases, different remote access protocols, such as RDP or SSH) by companies around the world, so that their employees might work from home.
I was wondering how large this increase would be when compared to the usual state of affairs. To determine this, I took a look at data I gathered from Shodan over the course of March and made couple of - hopefully interesting - charts.</description>
        <content:encoded>&lt;p&gt;One of the side effects of social distancing and self-quarantining due to COVID-19 was a large increase in the use of VPNs (and, in some cases, different remote access protocols, such as RDP or SSH) by companies around the world, so that their employees might work from home.&lt;br /&gt;
I was wondering how large this increase would be when compared to the usual state of affairs. To determine this, I took a look at data I gathered from Shodan over the course of March and made couple of - hopefully interesting - charts.&lt;/p&gt;
&lt;p&gt;Before we get to them, however, I should mention that simply looking at absolute numbers gathered from Shodan wouldn&amp;rsquo;t give us much due to the way Shodan operates (for more details, take a look at &lt;a href=&#34;https://isc.sans.edu/diary/25506&#34;&gt;my diary about patching BlueKeep&lt;/a&gt;). Therefore, while Shodan saw a significant absolute increase in open ports/detected IPs in March (almost 12% rise in detected IP addresses globally), we will take a look at both absolute and the relative values - counts as well as percentages of all IPs globally/in a specific country, which have a certain port open.&lt;/p&gt;
&lt;p&gt;If you&amp;rsquo;re interested in how the situation looked before, I&amp;rsquo;ll add that Shodan itself recently released an article with analysis of some of the trends they saw from the start of July 2019 to the end of January 2020. You may find it &lt;a href=&#34;https://blog.shodan.io/trends-in-internet-exposure/&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;One last thing I will mention before we get to &amp;ldquo;the good stuff&amp;rdquo; is that I didn&amp;rsquo;t include all the countries, for which I have data, in the charts, since that would make the post too large. If data for your country isn&amp;rsquo;t included in the charts and you would like to see how the situation changed where you live, &lt;a href=&#34;https://www.untrustednetwork.net/en/about/&#34;&gt;get in touch with me&lt;/a&gt; and if I have the data, I&amp;rsquo;ll try to add a chart for your country as well.&lt;/p&gt;
&lt;p&gt;Now, let&amp;rsquo;s take a look at the charts themselves. I picked the ports which have seen a high significant absolute increase globally - namely ports 22 (SSH), 80 (HTTP), 443 (HTTPS and many TLS-based services and VPN solutions) and 3389 (RDP). Unfortunatelly, I don&amp;rsquo;t have data for the usual VPN ports and related services (IKE, PPTP, etc.), but I assume that the jump in those was similarly significant as the one in TLS.&lt;/p&gt;
&lt;p&gt;Here is the list of countries for which charts are available:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;#global&#34;&gt;Global data&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#australia&#34;&gt;Australia&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#canada&#34;&gt;Canada&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#cz&#34;&gt;Czech Republic&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#gb&#34;&gt;Great Britain&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#germany&#34;&gt;Germany&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#china&#34;&gt;China&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#italy&#34;&gt;Italy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#netherlands&#34;&gt;Netherlands&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#romania&#34;&gt;Romania&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#russia&#34;&gt;Russia&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#slovakia&#34;&gt;Slovakia&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#spain&#34;&gt;Spain&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#usa&#34;&gt;USA&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;global&#34;&gt;Global situation&lt;/h2&gt;
&lt;p&gt;In addition to the ports mentioned above, on a global level we will take a look at SMB as well. There has been a signifficant increase in SMB open to the internet and, unfortunatelly, that was true even for SMBv1 on Windows.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/global-ssh.png&#34; alt=&#34;Global situation - SSH&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/global-http.png&#34; alt=&#34;Global situation - HTTP&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/global-https.png&#34; alt=&#34;Global situation - HTTPS&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/global-smb.png&#34; alt=&#34;Global situation - SMB&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/global-rdp.png&#34; alt=&#34;Global situation - RDP&#34; /&gt;&lt;/p&gt;
&lt;p&gt;As we may see, although there was a significant absolute increase in IPs which offer the protocols and services we were interested in, the percentage of IPs offering these protocols actually went down in cases of SSH and RDP. As the following charts demonstrate, this trend held for some countries as well, but not all of them.&lt;/p&gt;
&lt;h2 id=&#34;australia&#34;&gt;Australia&lt;/h2&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/australia-ssh.png&#34; alt=&#34;Australia - SSH&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/australia-http.png&#34; alt=&#34;Australia - HTTP&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/australia-https.png&#34; alt=&#34;Australia - HTTPS&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/australia-rdp.png&#34; alt=&#34;Australia - RDP&#34; /&gt;&lt;/p&gt;
&lt;h2 id=&#34;canada&#34;&gt;Canada&lt;/h2&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/canada-ssh.png&#34; alt=&#34;Canada - SSH&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/canada-http.png&#34; alt=&#34;Canada - HTTP&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/canada-https.png&#34; alt=&#34;Canada - HTTPS&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/canada-rdp.png&#34; alt=&#34;Canada - RDP&#34; /&gt;&lt;/p&gt;
&lt;h2 id=&#34;cz&#34;&gt;Czech Republic&lt;/h2&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/cz-ssh.png&#34; alt=&#34;Czech Republic - SSH&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/cz-http.png&#34; alt=&#34;Czech Republic - HTTP&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/cz-https.png&#34; alt=&#34;Czech Republic - HTTPS&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/cz-rdp.png&#34; alt=&#34;Czech Republic - RDP&#34; /&gt;&lt;/p&gt;
&lt;h2 id=&#34;gb&#34;&gt;Great Britain&lt;/h2&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/gb-ssh.png&#34; alt=&#34;Great Britain - SSH&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/gb-http.png&#34; alt=&#34;Great Britain - HTTP&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/gb-https.png&#34; alt=&#34;Great Britain - HTTPS&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/gb-rdp.png&#34; alt=&#34;Great Britain - RDP&#34; /&gt;&lt;/p&gt;
&lt;h2 id=&#34;germany&#34;&gt;Germany&lt;/h2&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/germany-ssh.png&#34; alt=&#34;Germany - SSH&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/germany-http.png&#34; alt=&#34;Germany - HTTP&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/germany-https.png&#34; alt=&#34;Germany - HTTPS&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/germany-rdp.png&#34; alt=&#34;Germany - RDP&#34; /&gt;&lt;/p&gt;
&lt;h2 id=&#34;china&#34;&gt;China&lt;/h2&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/china-ssh.png&#34; alt=&#34;China - SSH&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/china-http.png&#34; alt=&#34;China - HTTP&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/china-https.png&#34; alt=&#34;China - HTTPS&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/china-rdp.png&#34; alt=&#34;China - RDP&#34; /&gt;&lt;/p&gt;
&lt;h2 id=&#34;italy&#34;&gt;Italy&lt;/h2&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/italy-ssh.png&#34; alt=&#34;Italy - SSH&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/italy-http.png&#34; alt=&#34;Italy - HTTP&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/italy-https.png&#34; alt=&#34;Italy - HTTPS&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/italy-rdp.png&#34; alt=&#34;Italy - RDP&#34; /&gt;&lt;/p&gt;
&lt;h2 id=&#34;netherlands&#34;&gt;Netherlands&lt;/h2&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/netherlands-ssh.png&#34; alt=&#34;Netherlands - SSH&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/netherlands-http.png&#34; alt=&#34;Netherlands - HTTP&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/netherlands-https.png&#34; alt=&#34;Netherlands - HTTPS&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/netherlands-rdp.png&#34; alt=&#34;Netherlands - RDP&#34; /&gt;&lt;/p&gt;
&lt;h2 id=&#34;romania&#34;&gt;Romania&lt;/h2&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/romania-ssh.png&#34; alt=&#34;Romania - SSH&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/romania-http.png&#34; alt=&#34;Romania - HTTP&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/romania-https.png&#34; alt=&#34;Romania - HTTPS&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/romania-rdp.png&#34; alt=&#34;Romania - RDP&#34; /&gt;&lt;/p&gt;
&lt;h2 id=&#34;russia&#34;&gt;Russia&lt;/h2&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/russia-ssh.png&#34; alt=&#34;Russia - SSH&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/russia-http.png&#34; alt=&#34;Russia - HTTP&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/russia-https.png&#34; alt=&#34;Russia - HTTPS&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/russia-rdp.png&#34; alt=&#34;Russia - RDP&#34; /&gt;&lt;/p&gt;
&lt;h2 id=&#34;slovakia&#34;&gt;Slovakia&lt;/h2&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/slovakia-ssh.png&#34; alt=&#34;Slovakia - SSH&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/slovakia-http.png&#34; alt=&#34;Slovakia - HTTP&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/slovakia-https.png&#34; alt=&#34;Slovakia - HTTPS&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/slovakia-rdp.png&#34; alt=&#34;Slovakia - RDP&#34; /&gt;&lt;/p&gt;
&lt;h2 id=&#34;spain&#34;&gt;Spain&lt;/h2&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/spain-ssh.png&#34; alt=&#34;Spain - SSH&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/spain-http.png&#34; alt=&#34;Spain - HTTP&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/spain-https.png&#34; alt=&#34;Spain - HTTPS&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/spain-rdp.png&#34; alt=&#34;Spain - RDP&#34; /&gt;&lt;/p&gt;
&lt;h2 id=&#34;usa&#34;&gt;USA&lt;/h2&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/usa-ssh.png&#34; alt=&#34;USA - SSH&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/usa-http.png&#34; alt=&#34;USA - HTTP&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/usa-https.png&#34; alt=&#34;USA - HTTPS&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/06-corona_ports/usa-rdp.png&#34; alt=&#34;USA - RDP&#34; /&gt;&lt;/p&gt;
</content:encoded>
        <dc:creator>Jan Kopriva</dc:creator>
        <media:content url="https://untrustednetwork.netimages/icons/stats.png" medium="image"><media:title type="html">featured image</media:title></media:content>
        
        
        
          
            
              <category>SSL</category>
            
          
            
              <category>TLS</category>
            
          
            
              <category>SSH</category>
            
          
            
              <category>RDP</category>
            
          
            
              <category>HTTP</category>
            
          
            
              <category>HTTPS</category>
            
          
            
              <category>COVID-19</category>
            
          
            
              <category>Shodan</category>
            
          
        
        
          
            
              <category>News</category>
            
          
            
              <category>2020</category>
            
          
        
        
      </item>
      
      <item>
        <title>SANS ISC Diary - Secure vs. cleartext protocols – couple of interesting stats</title>
        <link>https://untrustednetwork.net/en/2020/03/02/sans-isc-diary-secure-vs.-cleartext-protocols-couple-of-interesting-stats/</link>
        <pubDate>Mon, 02 Mar 2020 06:55:00 +0100</pubDate>
        
        <atom:modified>Mon, 02 Mar 2020 06:55:00 +0100</atom:modified>
        <guid>https://untrustednetwork.net/en/2020/03/02/sans-isc-diary-secure-vs.-cleartext-protocols-couple-of-interesting-stats/</guid>
        <description>A Diary of mine was published today on the SANS Internet Storm Center. In this one, we delve into the support of HTTP and HTTPS among web servers on the internet, as well as support for Telnet and SSH, over the last six months.</description>
        <content:encoded>&lt;p&gt;A &lt;a href=&#34;https://isc.sans.edu/forums/diary/Secure+vs+cleartext+protocols+couple+of+interesting+stats/25854/&#34;&gt;Diary&lt;/a&gt; of mine was published today on the &lt;a href=&#34;https://isc.sans.edu/&#34;&gt;SANS Internet Storm Center&lt;/a&gt;. In this one, we delve into the support of HTTP and HTTPS among web servers on the internet, as well as support for Telnet and SSH, over the last six months.&lt;/p&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/isc/isc-diary.jpg&#34; alt=&#34;ISC diary&#34;&gt;
</content:encoded>
        <dc:creator>Jan Kopriva</dc:creator>
        <media:content url="https://untrustednetwork.netimages/isc.png" medium="image"><media:title type="html">featured image</media:title></media:content>
        
        
        
          
            
              <category>SANS</category>
            
          
            
              <category>TLS</category>
            
          
            
              <category>HTTP</category>
            
          
            
              <category>HTTPS</category>
            
          
            
              <category>Telnet</category>
            
          
            
              <category>SSH</category>
            
          
        
        
          
            
              <category>News</category>
            
          
            
              <category>2020</category>
            
          
        
        
          
            
              <category>SANS ISC Diary</category>
            
          
        
      </item>
      
      <item>
        <title>Most visited adult sites actually beat some e-banking portals when it comes to encryption</title>
        <link>https://untrustednetwork.net/en/2020/01/01/most-visited-adult-sites-actually-beat-some-e-banking-portals-when-it-comes-to-encryption/</link>
        <pubDate>Wed, 01 Jan 2020 12:09:20 +0100</pubDate>
        
        <atom:modified>Wed, 01 Jan 2020 12:09:20 +0100</atom:modified>
        <guid>https://untrustednetwork.net/en/2020/01/01/most-visited-adult-sites-actually-beat-some-e-banking-portals-when-it-comes-to-encryption/</guid>
        <description>After I finished the analysis of SSL/TLS configuration of almost 1400 internet banking portals (see the relevant ISC Diary, a question came to me. Internet banking portals should be among the best secured systems put online, yet not all of them made the mark when it came to encryption used to secure HTTP traffic. Would the situation be even worse for sites which are commonly assumed to lack proper security measures?</description>
        <content:encoded>&lt;p&gt;After I finished the analysis of SSL/TLS configuration of almost 1400 internet banking portals (see the relevant &lt;a href=&#34;https://untrustednetwork.net/en/2019/12/13/sans-isc-diary-internet-banking-sites-and-their-use-of-tls...-and-sslv3...-and-sslv2/&#34;&gt;ISC Diary&lt;/a&gt;, a question came to me. Internet banking portals should be among the best secured systems put online, yet not all of them made the mark when it came to encryption used to secure HTTP traffic. Would the situation be even worse for sites which are commonly assumed to lack proper security measures?&lt;/p&gt;
&lt;p&gt;Websites with adult content seemed to be the ideal starting place to determine this, so I tried to look for a list of the most popular ones. Contrary to my expectations, I wasn&amp;rsquo;t able to find any current list with more than &amp;ldquo;Top 10&amp;rdquo; or &amp;ldquo;Top 25&amp;rdquo; sites, so I turned to Alexa. Among other information, Alexa offers &amp;ldquo;Top 500 sites&amp;rdquo; lists for the following categories:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Adult&lt;/li&gt;
&lt;li&gt;Arts&lt;/li&gt;
&lt;li&gt;Business&lt;/li&gt;
&lt;li&gt;Computers&lt;/li&gt;
&lt;li&gt;Games&lt;/li&gt;
&lt;li&gt;Health&lt;/li&gt;
&lt;li&gt;Home&lt;/li&gt;
&lt;li&gt;Kids and Teens&lt;/li&gt;
&lt;li&gt;News&lt;/li&gt;
&lt;li&gt;Recreation&lt;/li&gt;
&lt;li&gt;Reference&lt;/li&gt;
&lt;li&gt;Regional&lt;/li&gt;
&lt;li&gt;Science&lt;/li&gt;
&lt;li&gt;Shopping&lt;/li&gt;
&lt;li&gt;Society&lt;/li&gt;
&lt;li&gt;Sports&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Unfortunately, without a paid account, one may only access first 50 sites of the Top 500 list for each category. Although I originally wanted our sample to be much larger, it was not to be&amp;hellip; But the limitation gave me an idea. Since one may access list of the top 50 sites in each category, why not scan all the 50 sites for each of the 16 categories? Of course, with such a small sample size, the results could not be considered anywhere near representative, but they might be interesting nonetheless.&lt;/p&gt;
&lt;p&gt;With the plan set, I put it into action on 25 December 2019. I used the same methodology as in the case of the banking portals - I conducted an Nmap scan using the &amp;ldquo;ssl-enum-ciphers&amp;rdquo; and &amp;ldquo;sslv2&amp;rdquo; scripts which enabled me to determine which SSL/TLS protocols were supported by the servers (except for TLSv1.3) as well as the weakest supported ciphersuite (once again, see the Diary for more details). In the end, the scans managed to gather information about 790 of the 800 domains (the 10 errors were mostly due to second level domains not having an A record set).&lt;/p&gt;
&lt;p&gt;In contrast to the case of internet banking portals, none of the servers in the &amp;ldquo;Top 50&amp;rdquo; lists supported SSLv2 (which 0.8% of tested internet banking servers did) or supported a ciphersuite marked with an F (as was the case with 0.29% of e-banking servers). So in this regard (and actually several others), even the 50 most visited adult sites were actually better configured than some of the internet banking portals.&lt;/p&gt;
&lt;p&gt;Apart from that, the results were a bit of a mixed bag, as you may see from the following table of results. I added the numbers for the internet banking sites as well, so you may judge the resulting grades for yourselves.&lt;br /&gt;
&lt;br&gt;&lt;br&gt;&lt;/p&gt;
&lt;table&gt;
    &lt;col width=&#34;150&#34;&gt;
    &lt;col width=&#34;80&#34;&gt;
    &lt;col width=&#34;80&#34;&gt;
    &lt;col width=&#34;80&#34;&gt;
    &lt;col width=&#34;80&#34;&gt;
    &lt;tr&gt;
        &lt;td&gt;&lt;b&gt;Category&lt;/b&gt;&lt;/td&gt;
        &lt;td&gt;&lt;b&gt;A&lt;/b&gt;&lt;/td&gt;
        &lt;td&gt;&lt;b&gt;C&lt;/b&gt;&lt;/td&gt;
        &lt;td&gt;&lt;b&gt;D&lt;/b&gt;&lt;/td&gt;
        &lt;td&gt;&lt;b&gt;F&lt;/b&gt;&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Business&lt;/td&gt;
        &lt;td&gt;78.72&lt;/td&gt;
        &lt;td&gt;17.02&lt;/td&gt;
        &lt;td&gt;4.26&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Health&lt;/td&gt;
        &lt;td&gt;75.00&lt;/td&gt;
        &lt;td&gt;25.00&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Reference&lt;/td&gt;
        &lt;td&gt;75.00&lt;/td&gt;
        &lt;td&gt;22.92&lt;/td&gt;
        &lt;td&gt;2.08&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Science&lt;/td&gt;
        &lt;td&gt;74.42&lt;/td&gt;
        &lt;td&gt;23.26&lt;/td&gt;
        &lt;td&gt;2.33&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Kids and Teens&lt;/td&gt;
        &lt;td&gt;73.91&lt;/td&gt;
        &lt;td&gt;21.74&lt;/td&gt;
        &lt;td&gt;4.35&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Regional&lt;/td&gt;
        &lt;td&gt;72.34&lt;/td&gt;
        &lt;td&gt;23.40&lt;/td&gt;
        &lt;td&gt;4.26&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Shopping&lt;/td&gt;
        &lt;td&gt;72.34&lt;/td&gt;
        &lt;td&gt;25.53&lt;/td&gt;
        &lt;td&gt;2.13&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Society&lt;/td&gt;
        &lt;td&gt;71.74&lt;/td&gt;
        &lt;td&gt;28.26&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr style=&#34;color: darkgrey;&#34;&gt;
        &lt;td&gt;Internet Banking&lt;/td&gt;
        &lt;td&gt;70.47&lt;/td&gt;
        &lt;td&gt;24.29&lt;/td&gt;
        &lt;td&gt;4.95&lt;/td&gt;
        &lt;td&gt;0.29&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Home&lt;/td&gt;
        &lt;td&gt;67.35&lt;/td&gt;
        &lt;td&gt;32.65&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;News&lt;/td&gt;
        &lt;td&gt;67.35&lt;/td&gt;
        &lt;td&gt;32.65&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Recreation&lt;/td&gt;
        &lt;td&gt;66.67&lt;/td&gt;
        &lt;td&gt;31.11&lt;/td&gt;
        &lt;td&gt;2.22&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Adult&lt;/td&gt;
        &lt;td&gt;63.27&lt;/td&gt;
        &lt;td&gt;34.69&lt;/td&gt;
        &lt;td&gt;2.04&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Games&lt;/td&gt;
        &lt;td&gt;63.04&lt;/td&gt;
        &lt;td&gt;32.61&lt;/td&gt;
        &lt;td&gt;4.35&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Arts&lt;/td&gt;
        &lt;td&gt;61.70&lt;/td&gt;
        &lt;td&gt;34.04&lt;/td&gt;
        &lt;td&gt;4.26&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Sports&lt;/td&gt;
        &lt;td&gt;61.70&lt;/td&gt;
        &lt;td&gt;31.91&lt;/td&gt;
        &lt;td&gt;6.38&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Computers&lt;/td&gt;
        &lt;td&gt;52.00&lt;/td&gt;
        &lt;td&gt;46.00&lt;/td&gt;
        &lt;td&gt;2.00&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
    &lt;/tr&gt;
&lt;/table&gt;
&lt;br&gt;
&lt;p&gt;Besides the marks for different categories, protocol support was interesting as well. As was already mentioned, none of the tested sites supported SSLv2, however one further point that should be mentioned is that on average, more internet banking sites still supported SSLv3 than servers in any of the Alexa categories and less of banking sites supported TLSv1.2 than even the sites in the Adult category. Since the sample sizes varied widely between the analyses, this should be considered more of an interesting observation than anything else, but I think it does merit at least this small remark.&lt;br /&gt;
&lt;br&gt;&lt;br&gt;&lt;/p&gt;
&lt;table&gt;
    &lt;col width=&#34;150&#34;&gt;
    &lt;col width=&#34;80&#34;&gt;
    &lt;col width=&#34;80&#34;&gt;
    &lt;col width=&#34;80&#34;&gt;
    &lt;col width=&#34;80&#34;&gt;
    &lt;tr&gt;
        &lt;td&gt;&lt;b&gt;Category&lt;/b&gt;&lt;/td&gt;
        &lt;td&gt;&lt;b&gt;SSLv3&lt;/b&gt;&lt;/td&gt;
        &lt;td&gt;&lt;b&gt;TLSv1.0&lt;/b&gt;&lt;/td&gt;
        &lt;td&gt;&lt;b&gt;TLSv1.1&lt;/b&gt;&lt;/td&gt;
        &lt;td&gt;&lt;b&gt;TLSv1.2&lt;/b&gt;&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Computers&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
        &lt;td&gt;74.00&lt;/td&gt;
        &lt;td&gt;82.00&lt;/td&gt;
        &lt;td&gt;100.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Adult&lt;/td&gt;
        &lt;td&gt;2.00&lt;/td&gt;
        &lt;td&gt;68.00&lt;/td&gt;
        &lt;td&gt;80.00&lt;/td&gt;
        &lt;td&gt;98.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;News&lt;/td&gt;
        &lt;td&gt;2.00&lt;/td&gt;
        &lt;td&gt;68.00&lt;/td&gt;
        &lt;td&gt;76.00&lt;/td&gt;
        &lt;td&gt;98.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Home&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
        &lt;td&gt;52.00&lt;/td&gt;
        &lt;td&gt;64.00&lt;/td&gt;
        &lt;td&gt;98.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Sports&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
        &lt;td&gt;68.75&lt;/td&gt;
        &lt;td&gt;85.42&lt;/td&gt;
        &lt;td&gt;97.92&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr style=&#34;color: darkgrey;&#34;&gt;
        &lt;td&gt;Internet Banking&lt;/td&gt;
        &lt;td&gt;3.49&lt;/td&gt;
        &lt;td&gt;47.64&lt;/td&gt;
        &lt;td&gt;57.75&lt;/td&gt;
        &lt;td&gt;96.65&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Reference&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
        &lt;td&gt;52.00&lt;/td&gt;
        &lt;td&gt;70.00&lt;/td&gt;
        &lt;td&gt;96.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Arts&lt;/td&gt;
        &lt;td&gt;2.04&lt;/td&gt;
        &lt;td&gt;63.27&lt;/td&gt;
        &lt;td&gt;71.43&lt;/td&gt;
        &lt;td&gt;95.92&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Society&lt;/td&gt;
        &lt;td&gt;2.08&lt;/td&gt;
        &lt;td&gt;47.92&lt;/td&gt;
        &lt;td&gt;58.33&lt;/td&gt;
        &lt;td&gt;95.83&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Health&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
        &lt;td&gt;46.94&lt;/td&gt;
        &lt;td&gt;67.35&lt;/td&gt;
        &lt;td&gt;93.88&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Shopping&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
        &lt;td&gt;36.73&lt;/td&gt;
        &lt;td&gt;63.27&lt;/td&gt;
        &lt;td&gt;93.88&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Business&lt;/td&gt;
        &lt;td&gt;2.04&lt;/td&gt;
        &lt;td&gt;36.73&lt;/td&gt;
        &lt;td&gt;53.06&lt;/td&gt;
        &lt;td&gt;93.88&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Kids and Teens&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
        &lt;td&gt;56.00&lt;/td&gt;
        &lt;td&gt;78.00&lt;/td&gt;
        &lt;td&gt;92.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Regional&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
        &lt;td&gt;56.00&lt;/td&gt;
        &lt;td&gt;78.00&lt;/td&gt;
        &lt;td&gt;92.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Recreation&lt;/td&gt;
        &lt;td&gt;2.04&lt;/td&gt;
        &lt;td&gt;42.86&lt;/td&gt;
        &lt;td&gt;63.27&lt;/td&gt;
        &lt;td&gt;91.84&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Games&lt;/td&gt;
        &lt;td&gt;2.00&lt;/td&gt;
        &lt;td&gt;66.00&lt;/td&gt;
        &lt;td&gt;82.00&lt;/td&gt;
        &lt;td&gt;90.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Science&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
        &lt;td&gt;44.90&lt;/td&gt;
        &lt;td&gt;67.35&lt;/td&gt;
        &lt;td&gt;87.76&lt;/td&gt;
    &lt;/tr&gt;
&lt;/table&gt;
&lt;br&gt;
&lt;p&gt;When it came to vulnerabilities, several servers in Society and Adult categories were found to be vulnerable to POODLE, couple in the Science category still supported the use of RC4 and quite a large number of sites in all categories supported ciphersuites vulnerable to SWEET32.&lt;br /&gt;
&lt;br&gt;&lt;br&gt;&lt;/p&gt;
&lt;table&gt;
    &lt;col width=&#34;150&#34;&gt;
    &lt;col width=&#34;80&#34;&gt;
    &lt;col width=&#34;80&#34;&gt;
    &lt;col width=&#34;80&#34;&gt;
    &lt;tr&gt;
        &lt;td&gt;&lt;b&gt;Category&lt;/b&gt;&lt;/td&gt;
        &lt;td&gt;&lt;b&gt;SWEET32&lt;/b&gt;&lt;/td&gt;
        &lt;td&gt;&lt;b&gt;RC4&lt;/b&gt;&lt;/td&gt;
        &lt;td&gt;&lt;b&gt;POODLE&lt;/b&gt;&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Society&lt;/td&gt;
        &lt;td&gt;27.08&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
        &lt;td&gt;2.08&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Adult&lt;/td&gt;
        &lt;td&gt;36.00&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
        &lt;td&gt;2.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr style=&#34;color: darkgrey;&#34;&gt;
        &lt;td&gt;Internet Banking&lt;/td&gt;
        &lt;td&gt;30.55&lt;/td&gt;
        &lt;td&gt;0.51&lt;/td&gt;
        &lt;td&gt;0.07&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Science&lt;/td&gt;
        &lt;td&gt;20.41&lt;/td&gt;
        &lt;td&gt;2.04&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Computers&lt;/td&gt;
        &lt;td&gt;48.00&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Sports&lt;/td&gt;
        &lt;td&gt;37.50&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Arts&lt;/td&gt;
        &lt;td&gt;36.73&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Games&lt;/td&gt;
        &lt;td&gt;34.00&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;News&lt;/td&gt;
        &lt;td&gt;34.00&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Home&lt;/td&gt;
        &lt;td&gt;32.00&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Recreation&lt;/td&gt;
        &lt;td&gt;30.61&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Shopping&lt;/td&gt;
        &lt;td&gt;26.53&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Regional&lt;/td&gt;
        &lt;td&gt;26.00&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Health&lt;/td&gt;
        &lt;td&gt;24.49&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Kids and Teens&lt;/td&gt;
        &lt;td&gt;24.00&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Reference&lt;/td&gt;
        &lt;td&gt;24.00&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
        &lt;td&gt;Business&lt;/td&gt;
        &lt;td&gt;20.41&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
        &lt;td&gt;0.00&lt;/td&gt;
    &lt;/tr&gt;
&lt;/table&gt;
&lt;br&gt;
&lt;p&gt;The last thing, which should be mentioned is that on average only 23.54% of the sites from the Alexa&amp;rsquo;s categories were configured in accordance with the current security best practices (i.e. they only supported TLSv1.2 and possibly TLSv1.3). Percentages for all of the categories tested may be found in the following chart.&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://untrustednetwork.net/images/2020/01-tls-ssl-alexa/tlsv12_only.png&#34;&gt;&lt;img src=&#34;https://untrustednetwork.net/images/2020/01-tls-ssl-alexa/tlsv12_only.png&#34; alt=&#34;Percentage of sites configured in accordance with current security best practices&#34; style=&#34;width:600px;&#34;&gt;&lt;/a&gt;&lt;/p&gt;
</content:encoded>
        <dc:creator>Jan Kopriva</dc:creator>
        <media:content url="https://untrustednetwork.netimages/icons/stats.png" medium="image"><media:title type="html">featured image</media:title></media:content>
        
        
        
          
            
              <category>SSL</category>
            
          
            
              <category>TLS</category>
            
          
            
              <category>Bank</category>
            
          
            
              <category>Alexa</category>
            
          
        
        
          
            
              <category>News</category>
            
          
            
              <category>2020</category>
            
          
        
        
      </item>
      
      <item>
        <title>SANS ISC Diary - Internet banking sites and their use of TLS... and SSLv3... and SSLv2?!</title>
        <link>https://untrustednetwork.net/en/2019/12/13/sans-isc-diary-internet-banking-sites-and-their-use-of-tls...-and-sslv3...-and-sslv2/</link>
        <pubDate>Fri, 13 Dec 2019 08:22:37 +0100</pubDate>
        
        <atom:modified>Fri, 13 Dec 2019 08:22:37 +0100</atom:modified>
        <guid>https://untrustednetwork.net/en/2019/12/13/sans-isc-diary-internet-banking-sites-and-their-use-of-tls...-and-sslv3...-and-sslv2/</guid>
        <description>A Diary of mine was published today on the SANS Internet Storm Center. In this one we take a look at the use of TLS (and SSL) on banking sites all over the world.</description>
        <content:encoded>&lt;p&gt;A &lt;a href=&#34;https://isc.sans.edu/forums/diary/Internet+banking+sites+and+their+use+of+TLS+and+SSLv3+and+SSLv2/25606/&#34;&gt;Diary&lt;/a&gt; of mine was published today on the &lt;a href=&#34;https://isc.sans.edu/&#34;&gt;SANS Internet Storm Center&lt;/a&gt;. In this one we take a look at the use of TLS (and SSL) on banking sites all over the world.&lt;/p&gt;
&lt;img src=&#34;https://untrustednetwork.net/images/isc/isc-diary.jpg&#34; alt=&#34;ISC diary&#34;&gt;</content:encoded>
        <dc:creator>Jan Kopriva</dc:creator>
        <media:content url="https://untrustednetwork.netimages/isc.png" medium="image"><media:title type="html">featured image</media:title></media:content>
        
        
        
          
            
              <category>SANS</category>
            
          
            
              <category>SSL</category>
            
          
            
              <category>TLS</category>
            
          
            
              <category>Bank</category>
            
          
        
        
          
            
              <category>News</category>
            
          
            
              <category>2019</category>
            
          
        
        
          
            
              <category>SANS ISC Diary</category>
            
          
        
      </item>
      
      <item>
        <title>Looking back at July 2015</title>
        <link>https://untrustednetwork.net/en/2015/08/05/looking-back-at-july-2015/</link>
        <pubDate>Wed, 05 Aug 2015 10:27:36 +0100</pubDate>
        
        <atom:modified>Wed, 05 Aug 2015 10:27:36 +0100</atom:modified>
        <guid>https://untrustednetwork.net/en/2015/08/05/looking-back-at-july-2015/</guid>
        <description>The most important IT security-related news in July has definitely been the affair surrounding a theft of data from the Hacking Team – company, which develops commercial spyware intended for use by police departments and other security agencies. More than 400 GB of stolen data were made public and afterwards analyzed by IT security specialists, leading to discovery of a large number (still growing) of zero-day vulnerabilities which were used in Hacking Team’s products.</description>
        <content:encoded>&lt;p&gt;The most important IT security-related news in July has definitely been the affair surrounding a &lt;a href=&#34;http://www.tripwire.com/state-of-security/latest-security-news/hacking-team-breach-reveals-nation-state-corporate-customers/&#34;&gt;theft&lt;/a&gt; of data from the Hacking Team – company, which develops commercial spyware intended for use by police departments and other security agencies. More than 400 GB of stolen data were made public and afterwards analyzed by IT security specialists, leading to discovery of a large number (still growing) of zero-day vulnerabilities which were used in Hacking Team’s products.&lt;br /&gt;
An interesting news appeared also in connection with vehicle security. Two researchers managed to leverage a vulnerability in a wirelessly accessible on-board entertainment system of a Jeep Cherokee which enabled them to remotely &lt;a href=&#34;http://www.wired.com/2015/07/hackers-remotely-kill-jeep-highway/&#34;&gt;control&lt;/a&gt; some of the vehicle’s functions and components, including transmission. Fiat Chrysler has responded to publication of the vulnerability by a &lt;a href=&#34;http://www.bbc.com/news/technology-33650491&#34;&gt;recall&lt;/a&gt; of 1.4 million of affected vehicles. Similar action in connection with software bugs/vulnerabilities was also taken by &lt;a href=&#34;http://www.bbc.com/news/technology-33506486&#34;&gt;Land Rover&lt;/a&gt; and &lt;a href=&#34;http://www.theregister.co.uk/2015/07/08/ford_car_software_recall_analysis/&#34;&gt;Ford&lt;/a&gt;.&lt;br /&gt;
A mention should be made of a press release by &lt;a href=&#34;https://www.europol.europa.eu/content/cybercriminal-darkode-forum-taken-down-through-global-action&#34;&gt;Europol&lt;/a&gt;, made in the middle of the month, regarding a successful operation to take down the Darkode cybercriminal forum. Although 28 users and administrators were arrested in, the forum &lt;a href=&#34;http://www.theregister.co.uk/2015/07/28/darkode_returns/&#34;&gt;resumed&lt;/a&gt; its operation only two weeks later.&lt;br /&gt;
Another vulnerability has also been discovered in OpenSSL, which enables an attacker to potentially use &lt;a href=&#34;http://www.theinquirer.net/inquirer/news/2416825/high-severity-bug-found-in-openssl-raises-fears-of-another-heartbleed&#34;&gt;invalid&lt;/a&gt; certificate as a valid one. A fix for the vulnerability was released only few days after its publication.&lt;br /&gt;
An interesting new &lt;a href=&#34;http://www.wired.com/2014/11/airhopper-hack/&#34;&gt;attack&lt;/a&gt; which could lead to extraction of data from an air-gapped system has also been made public. It is based on transmitting a radio signal generated by the computer using a video card bus as an antenna and received by a nearby mobile phone.&lt;/p&gt;
</content:encoded>
        <dc:creator>Jan Kopriva</dc:creator>
        
        
        
        
          
            
              <category>Hacking Team</category>
            
          
            
              <category>Vulnerability</category>
            
          
            
              <category>TLS/SSL</category>
            
          
        
        
          
            
              <category>2015</category>
            
          
        
        
          
            
              <category>Looking back</category>
            
          
        
      </item>
      
      <item>
        <title>Looking back at May 2015</title>
        <link>https://untrustednetwork.net/en/2015/06/05/looking-back-at-may-2015/</link>
        <pubDate>Fri, 05 Jun 2015 00:00:57 +0100</pubDate>
        
        <atom:modified>Fri, 05 Jun 2015 00:00:57 +0100</atom:modified>
        <guid>https://untrustednetwork.net/en/2015/06/05/looking-back-at-may-2015/</guid>
        <description>May has been at least as rich on cybersecurity incidents and events as any of the previous months of the year. Some of the more important are described in the following text.
The VENOM (Virtual Environment Neglected Operations Manipulation) vulnerability may be considered to be a very significant one. VENOM is a vulnerability in the code of a virtual floppy drive which is used by some of the virtualization platforms (QEMU, KVM, Xen).</description>
        <content:encoded>&lt;p&gt;May has been at least as rich on cybersecurity incidents and events as any of the previous months of the year. Some of the more important are described in the following text.&lt;br /&gt;
The &lt;a href=&#34;http://venom.crowdstrike.com/&#34;&gt;VENOM&lt;/a&gt; (Virtual Environment Neglected Operations Manipulation) vulnerability may be considered to be a very significant one. VENOM is a vulnerability in the code of a virtual floppy drive which is used by some of the virtualization platforms (QEMU, KVM, Xen). It enables the attacker to access underlying hypervisor from a virtualized OS using a buffer overflow attack. Since the vulnerability is non OS specific its impact is fairly high.&lt;br /&gt;
A mention should also be made of another of the TLS/SSL protocol implementation vulnerabilities, the so-called &lt;a href=&#34;https://weakdh.org/&#34;&gt;Logjam&lt;/a&gt;. Using Logjam, a downgrade of encryption is possible in man in the middle attacks on connections which use Diffie Hellman key exchange algorithm and support its export version.&lt;br /&gt;
Finally, it is noteworthy that the government has ratified an Action plan for National Cyber Security Strategy 2015 – 2020. Further information (in Czech) may be found &lt;a href=&#34;http://www.govcert.cz/cs/informacni-servis/akce-a-udalosti/vlada-schvalila-akcni-plan-k-narodni-strategii-kyberneticke-bezpecnosti-ceske-republiky-pro-pristich-pet-let-a-zpravu-o-stavu-kyberneticke-bezpecnosti-ceske-republiky-2014/&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;
</content:encoded>
        <dc:creator>Jan Kopriva</dc:creator>
        
        
        
        
          
            
              <category>TLS/SSL</category>
            
          
            
              <category>Virtualization</category>
            
          
            
              <category>Government</category>
            
          
            
              <category>Vulnerability</category>
            
          
        
        
          
            
              <category>2015</category>
            
          
        
        
          
            
              <category>Looking back</category>
            
          
        
      </item>
      
      <item>
        <title>FREAK - a high impact vulnerability in TLS/SSL</title>
        <link>https://untrustednetwork.net/en/2015/03/04/freak-a-high-impact-vulnerability-in-tls/ssl/</link>
        <pubDate>Wed, 04 Mar 2015 10:06:49 +0100</pubDate>
        
        <atom:modified>Wed, 04 Mar 2015 10:06:49 +0100</atom:modified>
        <guid>https://untrustednetwork.net/en/2015/03/04/freak-a-high-impact-vulnerability-in-tls/ssl/</guid>
        <description>An international research team has devised attack called FREAK (Factoring attack on RSA Export Keys) with which it is possible to lower the level of encryption used in SSL connections. Attack is based on forcing server and client to use legacy (the vulnerability has been present for a long time) weak cryptographic suites which are still supported by some of the mainstream browsers (Safari and OpenSSL-based Android browser among others) and servers.</description>
        <content:encoded>&lt;p&gt;An international research team has devised attack called &lt;a href=&#34;https://www.smacktls.com/#freak&#34;&gt;FREAK&lt;/a&gt; (Factoring attack on RSA Export Keys) with which it is possible to lower the level of encryption used in SSL connections. Attack is based on forcing server and client to use legacy (the vulnerability has been present for a long time) weak cryptographic suites which are still supported by some of the mainstream browsers (Safari and OpenSSL-based Android browser among others) and servers. After a key has been factored a man-in-the-middle attack may be launched by attacker against encrypted connection between a server and a browser. The aformentioned legacy cryptographic suites have been added to SSL implementations at a time when export regulations for cryptographic material were in effect in USA and only specific (weak) cryptographic suites were legally allowed to be exported. A link to a page containing further information about potentially vulnerable sites and a test for vulnerability on the client side may be found &lt;a href=&#34;https://freakattack.com/&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;
</content:encoded>
        <dc:creator>Jan Kopriva</dc:creator>
        
        
        
        
          
            
              <category>TLS/SSL</category>
            
          
            
              <category>Cryptography</category>
            
          
            
              <category>Vulnerability</category>
            
          
        
        
          
            
              <category>News</category>
            
          
            
              <category>2015</category>
            
          
        
        
      </item>
      

    
  </channel>
</rss>