>From their e-mail list: 

We do support an option along the lines of what you are asking. 

We have an interface up to pull the .csv-files from 
https://dl.shadowserver.org/reports/ (down at the moment, planned maintenance - 
should be up again tonight ) 

In order to be able to log in to that interface, you need to change your 
mailman password globally, by logging in to your account using the url listed 
in the monthly mail.shadowserver.org mailing list memberships reminder, hit log 
in, and check the 'change globally' button in the 'change password' field. An 
hour or so after updating the mailinglist password you should be able to log in 
to https://dl.shadowserver.org/reports/ . 

You can either script up pulling down the csvs, or I can ship you a script for 
pull down the csv on a linux host that one of our report recipients wrote and 
shared with us. 

Thanks, 
- -- Kjell Chr 




----- 
Mike Hammett 
Intelligent Computing Solutions 
http://www.ics-il.com 

----- Original Message -----

From: "That One Guy /sarcasm" <[email protected]> 
To: [email protected] 
Sent: Monday, May 18, 2015 11:55:28 AM 
Subject: Re: [AFMUG] how much to worry about SSDP vulnerable customers 


I keep meaning to address all the shadowserver reports, we get like 5 different 
ones each day I think now. 
I wonder if you could write some sort of email parser to pull in the reports 
and take the data from the attachments to automatically generate rules 


On Mon, May 18, 2015 at 11:28 AM, Cassidy B. Larson < [email protected] > 
wrote: 


If you don’t block it, or they don’t fix it, they’ll more than likely 
participate in a DDOS. Plus, it could impact their service and they think it’s 
your fault :) 
I’ve seen a few of those types of DDOS this year. 

-c 



> On May 18, 2015, at 10:18 AM, Ken Hohhof < [email protected] > wrote: 
> 
> I finally started getting ShadowServer reports which are nice. 
> 
> One thing I notice is that about 5% of customers still have routers with SSDP 
> (the discovery protocol for UPnP) exposed on the WAN side. This despite the 
> fact that I scanned the network earlier this year and sent notices to every 
> single customer with this vulnerability. It tells me very few did anything 
> about it. Most of these are DLink DIR-615 routers, and except for the very 
> last version of that router, there is no FW update, their only solution is to 
> disable UPnP in the menus. Apparently that's too difficult for customers. 
> 
> My question: is this serious enough to worry about? Should I just wait for 
> those DLink routers (or their owners) to die? 
> 
> I guess another solution would be to block ports 1900/2049/5783 but these 
> might be legitimately in use as ephemeral ports and I don't like blocking 
> high numbered ports. 
> 







-- 




If you only see yourself as part of the team but you don't see your team as 
part of yourself you have already failed as part of the team. 

Reply via email to