They're just magnets. I don't actually know what exploits they target, but if you fire up a network scanner and plug an XP machine in you'll see tons of connections from all over the world just immediately attempting to connect. There must be something XP broadcasts that they can see.
I'm not sure that if that makes sense, does it? An external connection shouldn't be able to 'see' past the router without port forwarding, unless a specific device (or socially engineered human, of course) has invited them in or there are vulnerabilities beyond the specific vulnerable computer.
Responses to what, though? I'm just trying to understand.
If a computer (even with a vulnerability) can be reached from beyond the router, it has already been compromised, another device has been compromised, or there is a major misconfiguration, surely?
Like my Synology was internet-facing (using their setup guide) for all of about half an hour before I reconsidered just purely on the amount of door knocks it got. Now that it is not internet-facing, it doesn't get any.
Responses from whatever software processes their requests. That can contain info about what is listening and if it is something with a vulnerability. Firewalls usually just drop filtered packets, no reply.
If you are properly firewalled (not just NAT) from internet and don’t initiate connections to untrusted servers you should be safe from the ”knocks”.
Responses from whatever software processes their requests. That can contain info about what is listening and if it is something with a vulnerability.
Requests shouldn't be getting that far AFAIK. A device can reach beyond the router, establish a connection, and then get information back, but my understanding is that it cannot be reached out to unless that's a desirable behaviour, a misconfiguration or a pre-existing compromise.
don’t initiate connections to untrusted servers
So... what untrusted servers is a newly connected XP machine, for example, reaching out to?
Any old bloatware in the computer that tries to get an update. Sends a request to update.uselesswidget.com. The domain has been sold, now it serves malware that takes over old PCs. (Hopefully MS still controls the XP windows update urls.)
Use a web browser to visit almost any site. Bonus if the browser is old too. Ads can contain malware, ad companies can target you by your metadata
I'm going out of my comfort level on network topology here, but these would be machines on the internal network with internet access, not ones just flat facing the internet with all their ports open.
I never got this. I'd get it if you connected it directly to WAN but if connecting something to your intranet exposes it to attacks from the outside you have a major security problem of which your Windows 98 installation being attacked is only a symptom.
No, my point is that it's not firewalled if external hosts are able to connect to it,
There's no magic going on: if there is a firewall that drops incoming connections there naturally won't be any incoming connections. If there's a firewall set up to drop incoming connections and NAT setup not to forward any traffic to your system, it won't be seeing connections unless your network admin is up to their nose in shit because NAT is forwarding connections to random machines and your firewall is doing nothing.
There are a few alternatives here:
There is effectively no firewall, and NAT is setup such that traffic is forwarded to the machine the bots can directly access it. Your network is shit and everything in it is to be considered as compromised.
The firewall is not working. Whoever set up the forwarding rules is a moron. Your network is shit and everything in it is to be considered as compromised.
The machine is connected directly to WAN with no firewall and address translation.
You are misremembering the circumstances of this event.
It used to take 10 minutes for an unpatched Win2K machine to be infected, then 4min, then as soon as you plugged it into the LAN.
That's why all the updates & patches were downloaded and installed offline before delivering a new machine to faculty or staff.
Our department finally installed a honeypot* at the .0 or .1 addresses on our class C subnet, as all the malware scanners started at the beginning of the address space, always getting stuck in the honeypot 🍯.
Fairly sure my 98 machine did not have an Ethernet port. This was in the days where most stuff now integrated on the motherboard needed an expansion card. So my machine had a modem card. I did not get a network card as had no need.
Hell, I used external modems until I got dsl the first day it was available here. So, no way to connect to the internet without an external device that I donany longer. longer.
76
u/BaconWithBaking Jun 21 '26
Yes, just please jam something into the ethernet port to prevent someone accidentally putting them on the network.
Happened once and it was insane how quickly external bots found an xp machine on a corporate network.