Hello, I scanned my public IP with nmap from an external network it is shows 21 and 1720 open. I have no such fire wall rules set, the default WAN rules are in place.
[link] [comments]
Intelligence View
Hello, I scanned my public IP with nmap from an external network it is shows 21 and 1720 open. I have no such fire wall rules set, the default WAN rules are in place. submitted by /u/SecurityAt30 [link] [comments]
Hello, I scanned my public IP with nmap from an external network it is shows 21 and 1720 open. I have no such fire wall rules set, the default WAN rules are in place.
title: Detect Exploitation - Help! Ubiquiti Edge Router shows 21 and 1720 open when I scan from outside
id: 74cf8b48-8ca9-4d93-85d2-f0de9b52631c
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
- https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-27
logsource:
category: network_connection
product: any
detection:
selection:
CommandLine|contains:
- 'exploit'
condition: selection
falsepositives:
- Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
- attack.initial_accessrule CTI_Threat_Indicator {
meta:
author = "iShareStuff CTI Automated Detection Engine"
date = "2026-09-27"
description = "YARA Signature for "
strings:
$str = "Help! Ubiquiti Edge Router sho" ascii wide
condition:
any of them
}index=security sourcetype IN ("cisco:asa", "pan:traffic", "zeek_conn", "suricata", "WinEventLog:Security")
("Help Ubiquiti Edge Router shows 21 and 1")
| stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip, dest_ip, dest_host, signature
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
| sort - countmessage: "*Help Ubiquiti Edge Router shows 21 and 1*"CommonSecurityLog
| where Message has "Help Ubiquiti Edge Router shows 21 and 1"
| summarize EventCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by SourceIP, DestinationIP, DestinationPort, Activity
| extend DetectionRule = "iShareStuff-CTI-Compiled"
| sort by EventCount descAnalyse für identifizierte Bedrohung auf Basis von Live-CTI (ENISA EUVD): CVSS 0.0 · EPSS 0.0% · CISA KEV: nein. Handlungsableitung aus den verlinkten Hersteller-Quellen.
Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.
Ähnliche Beiträge
Thematisch verwandte Begriffe: Help, Ubiquiti, Edge, Router · 6 Treffer
Videos werden geladen ...
Beiträge werden geladen ...
Videos werden geladen ...
Beiträge werden geladen ...
Videos werden geladen ...
Beiträge werden geladen ...
Videos werden geladen ...
Beiträge werden geladen ...
Videos werden geladen ...
Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.