Many months after U.S. Cert issued their first warning to the public regarding exploits to the vulnerable port 445 allowing for a remote attacker to take over a vulnerable computer, many computers that are publicly exposed continue to be unpatched and shielded from attacks against port 445. First there was WannaCry that attacked Windows Computers. Now there is SambaCry, that is attacking Linux machines. Even more nasty malware that relies upon leaked U.S. Intelligence agency Cyber weapons is bound to continue to wreak havoc unless ISPs take action and block port 445.
A review today of the number of hosts within the U.S. on shodan.io reveals the following ranked list as of today:
- California 134,382
- Wyoming 40,823
- Arizona 34,273
- New York 32,406
- Texas 27,752
- Virginia 22,899
- Illinois 14,333
- Washington 11,895
- Oregon 10,834
- New Jersey 10,135
- Florida 9,241
- Georgia 6,924
- Missouri 6,438
- Colorado 6,276
- Pennsylvania 6,206
- North Carolina 5,947
- Michigan 5,560
- Nevada 4,945
- Oklahoma 4,509
- Utah 4,052
- Ohio 3,742
- Minnesota 2,667
- Iowa 2,326
- Kansas 2,322
- Idaho 2,321
- Delaware 2,287
- Massachusetts 2,097
- Indiana 1,804
- Maryland 1,691
- North Dakota 1,247
- Nebraska 1,227
- South Carolina 1,189
- Arkansas 903
- Wisconsin 822
- Kentucky 810
- Alabama 775
- Tennessee 775
- South Dakota 697
- Louisiana 687
- Montana 637
- Alaska 636
- Connecticut 596
- Mississippi 543
- New Mexico 296
- Vermont 254
- New Hampshire 229
- Maine 222
- Rhode Island 221
- Hawaii 215
- West Virginia 134
SMB Port 445 is the same port that was used to attack Sony.
When will the U.S. and State governments kick into action and start forcing ISP’s to police their vulnerable machines?
Top Cities that make up the largest vulnerable attack surface within the U.S. as of today include:
1. Los Angeles 83,613
2. Phoenix 23,841
3. Cheyenne 40,665
4. Buffalo 23,106
5. Thousand Oaks 17,205
6. Ashburn 14,803
7. Chicago 10,379
8. Dallas 10,077
9. Boardman 9,118
10. San Antonio 7,376
There remain a total of 455,023 computers within the U.S. still vulnerable to these types of SMB Port 445 attacks.
Mitigation boils down to the top 25 ISPs taking actions to stop the malware attacks by forcibly blocking Port 445.
Be the first to comment on "Top Most Vulnerable States and Cities Remain Vulnerable to Double Pulsar Samba Port 445 Exploits"