https://reddit.com/r/netsec/comments/1tp6dz0/a_week_after_dutch_fiod_seized_800_servers_the/: A week after Dutch FIOD seized 800+ servers, the hosting network's ASN (AS209847) is still scanning at its normal daily rate
Affected Software
Frequently Asked Questions
What is the severity of AS209847 vulnerability?
The severity of the AS209847 vulnerability cannot be definitively assessed as it is related to ongoing scanning activity rather than a specific security flaw.
How do I mitigate the risks associated with AS209847?
To mitigate risks associated with AS209847, ensure that your firewall and intrusion detection systems are properly configured to block unauthorized access.
What types of systems are affected by AS209847?
Systems running MongoDB, Redis, PostgreSQL, Oracle Database, LDAP, DNP3, and EtherNet/IP may be targeted by servers associated with AS209847.
Are there known exploits for AS209847?
Currently, there are no publicly documented exploits specifically targeting AS209847, but the network's scanning indicates a potential for future attacks.
What should I do if I suspect my server is being scanned by AS209847?
If you suspect your server is being scanned by AS209847, review your server logs and ensure appropriate security measures are in place to prevent unauthorized access.