June 9, 2016 By Douglas Bonderud 2 min read

Nothing is truly safe on the internet. With enough time and effort, cybercriminals can gain access to any network, any file or any piece of data that companies want to keep hidden. Businesses and security professionals have taken steps to lower this risk by recognizing the inherent issues with protocols such as HTTP and HTTPS.

According to the new National Exposure Index (NEI) from security firm Rapid7, there are a host of other public protocols putting entire countries at risk. Here’s a look at the most hackable protocols and nations worldwide.

Behind the Scenes of the NEI

As noted in Rapid7’s blog post, while efforts such as CAIDA and Shodan take aim at general data analytics and new IoT networks, there are no services designed to “gauge the general deployment of services of public networks.” So Rapid7 leveraged Project Sonar to compile a list of the most commonly used internet protocols, their relative risk and the overall risk to specific countries.

The results are telling: For example, while secure shell (SSH) is the third most popular protocol (behind HTTP and HTTPS, respectively), unencrypted Telnet services come in at No. 7. Rapid7 found 15 million nodes using the protocol, with more than 11 million offering direct access to relational databases and 4.5 million providing access to printer services.

The National Exposure Index also examined services exposed via a specific port. According to Network World, 5.4 million unencrypted Microsoft Remote Procedure Call services are exposed on port 135, while 4.5 million Universal Plug and Play services were vulnerable at port 5000. Another 4.5 million printer services were at risk on port 9100.

Per-Country Compromise

Rapid7’s work also examined which countries had the most devices listening on all 30 ports and which were at the highest risk of compromise. On the listening end, there are no surprises: The U.S. tops the list with more than 43 million devices, while China comes in a distant second wth 11.3 million. Interestingly, the number of listening ports did not necessarily increase overall risk.

As noted by The Guardian, it’s neither the U.S. nor China that claims the No. 1 spot for most hackable, but rather Belgium, followed by Tajikistan, Samoa and Australia; China ranks fifth, and the U.S. slides in at No. 14. It’s possible that countries with lower device numbers are simply looking for ways to rapidly improve access. Unmonitored, unencrypted protocols certainly achieve that aim.

Ultimately, the security firm argued that “these results speak to a fundamental failure in modern internet engineering.” The data supports this claim — encryption isn’t compulsory, wide-open Telnet protocols “just work” and there’s little impetus to standardize (or even reliably detect) all protocols in use.

Large-scale breaches at the hands of legacy protocols such as 2014’s Heartbleed epidemic demonstrate the risk for countries and companies alike. It won’t be easy, it won’t be fast and it won’t be simple, but the NEI makes it clear: Until safety trumps speed, the internet remains inherently insecure.

More from

Cyberattack on American Water: A warning to critical infrastructure

3 min read - American Water, the largest publicly traded United States water and wastewater utility, recently experienced a cybersecurity incident that forced the company to disconnect key systems, including its customer billing platform. As the company’s investigation continues, there are growing concerns about the vulnerabilities that persist in the water sector, which has increasingly become a target for cyberattacks. The breach is a stark reminder of the critical infrastructure risks that have long plagued the industry. While the water utility has confirmed that…

What’s behind unchecked CVE proliferation, and what to do about it

4 min read - The volume of Common Vulnerabilities and Exposures (CVEs) has reached staggering levels, placing immense pressure on organizations' cyber defenses. According to SecurityScorecard, there were 29,000 vulnerabilities recorded in 2023, and by mid-2024, nearly 27,500 had already been identified.Meanwhile, Coalition's 2024 Cyber Threat Index forecasts that the total number of CVEs for 2024 will hit 34,888—a 25% increase compared to the previous year. This upward trend presents a significant challenge for organizations trying to manage vulnerabilities and mitigate potential exploits.What’s behind…

Quishing: A growing threat hiding in plain sight

4 min read - Our mobile devices go everywhere we go, and we can use them for almost anything. For businesses, the accessibility of mobile devices has also made it easier to create more interactive ways to introduce new products and services while improving user experiences across different industries. Quick-response (QR) codes are a good example of this in action and help mobile devices quickly navigate to web pages or install new software by simply scanning an image.However, legitimate organizations aren’t the only ones…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today